Jul 21 12:36:40.172702 kernel: Booting Linux on physical CPU 0x0000000000 [0x410fd083] Jul 21 12:36:40.172804 kernel: Linux version 6.12.95-flatcar (build@pony-truck.infra.kinvolk.io) (aarch64-cros-linux-gnu-gcc (Gentoo Hardened 15.3.0 p8) 15.3.0, GNU ld (Gentoo 2.46.0 p1) 2.46.0) #1 SMP PREEMPT Tue Jul 21 11:07:37 -00 2026 Jul 21 12:36:40.172913 kernel: KASLR disabled due to lack of seed Jul 21 12:36:40.172946 kernel: efi: EFI v2.7 by EDK II Jul 21 12:36:40.172972 kernel: efi: SMBIOS=0x7bed0000 SMBIOS 3.0=0x7beb0000 ACPI=0x786e0000 ACPI 2.0=0x786e0014 MEMATTR=0x7a73ca98 MEMRESERVE=0x78551b98 Jul 21 12:36:40.172995 kernel: secureboot: Secure boot disabled Jul 21 12:36:40.173013 kernel: ACPI: Early table checksum verification disabled Jul 21 12:36:40.173030 kernel: ACPI: RSDP 0x00000000786E0014 000024 (v02 AMAZON) Jul 21 12:36:40.173055 kernel: ACPI: XSDT 0x00000000786D00E8 000064 (v01 AMAZON AMZNFACP 00000001 01000013) Jul 21 12:36:40.173078 kernel: ACPI: FACP 0x00000000786B0000 000114 (v06 AMAZON AMZNFACP 00000001 AMZN 00000001) Jul 21 12:36:40.173104 kernel: ACPI: DSDT 0x0000000078640000 0013D2 (v02 AMAZON AMZNDSDT 00000001 AMZN 00000001) Jul 21 12:36:40.173119 kernel: ACPI: FACS 0x0000000078630000 000040 Jul 21 12:36:40.173135 kernel: ACPI: APIC 0x00000000786C0000 000108 (v04 AMAZON AMZNAPIC 00000001 AMZN 00000001) Jul 21 12:36:40.173162 kernel: ACPI: SPCR 0x00000000786A0000 000050 (v02 AMAZON AMZNSPCR 00000001 AMZN 00000001) Jul 21 12:36:40.173189 kernel: ACPI: GTDT 0x0000000078690000 000060 (v02 AMAZON AMZNGTDT 00000001 AMZN 00000001) Jul 21 12:36:40.173214 kernel: ACPI: MCFG 0x0000000078680000 00003C (v02 AMAZON AMZNMCFG 00000001 AMZN 00000001) Jul 21 12:36:40.173230 kernel: ACPI: SLIT 0x0000000078670000 00002D (v01 AMAZON AMZNSLIT 00000001 AMZN 00000001) Jul 21 12:36:40.173256 kernel: ACPI: IORT 0x0000000078660000 000078 (v01 AMAZON AMZNIORT 00000001 AMZN 00000001) Jul 21 12:36:40.173272 kernel: ACPI: PPTT 0x0000000078650000 0000EC (v01 AMAZON AMZNPPTT 00000001 AMZN 00000001) Jul 21 12:36:40.173297 kernel: ACPI: SPCR: console: uart,mmio,0x90a0000,115200 Jul 21 12:36:40.173321 kernel: earlycon: uart0 at MMIO 0x00000000090a0000 (options '115200') Jul 21 12:36:40.173371 kernel: printk: legacy bootconsole [uart0] enabled Jul 21 12:36:40.173389 kernel: ACPI: Use ACPI SPCR as default console: Yes Jul 21 12:36:40.173415 kernel: NUMA: Faking a node at [mem 0x0000000040000000-0x00000004b5ffffff] Jul 21 12:36:40.173432 kernel: NODE_DATA(0) allocated [mem 0x4b584ea00-0x4b5855fff] Jul 21 12:36:40.173448 kernel: Zone ranges: Jul 21 12:36:40.173472 kernel: DMA [mem 0x0000000040000000-0x00000000ffffffff] Jul 21 12:36:40.173499 kernel: DMA32 empty Jul 21 12:36:40.173528 kernel: Normal [mem 0x0000000100000000-0x00000004b5ffffff] Jul 21 12:36:40.173552 kernel: Device empty Jul 21 12:36:40.173576 kernel: Movable zone start for each node Jul 21 12:36:40.173593 kernel: Early memory node ranges Jul 21 12:36:40.173617 kernel: node 0: [mem 0x0000000040000000-0x000000007862ffff] Jul 21 12:36:40.173633 kernel: node 0: [mem 0x0000000078630000-0x000000007863ffff] Jul 21 12:36:40.173649 kernel: node 0: [mem 0x0000000078640000-0x00000000786effff] Jul 21 12:36:40.173673 kernel: node 0: [mem 0x00000000786f0000-0x000000007872ffff] Jul 21 12:36:40.173699 kernel: node 0: [mem 0x0000000078730000-0x000000007bbfffff] Jul 21 12:36:40.173725 kernel: node 0: [mem 0x000000007bc00000-0x000000007bfdffff] Jul 21 12:36:40.173742 kernel: node 0: [mem 0x000000007bfe0000-0x000000007fffffff] Jul 21 12:36:40.173772 kernel: node 0: [mem 0x0000000400000000-0x00000004b5ffffff] Jul 21 12:36:40.173803 kernel: Initmem setup node 0 [mem 0x0000000040000000-0x00000004b5ffffff] Jul 21 12:36:40.173821 kernel: On node 0, zone Normal: 8192 pages in unavailable ranges Jul 21 12:36:40.173883 kernel: cma: Reserved 16 MiB at 0x000000007f000000 on node -1 Jul 21 12:36:40.173921 kernel: psci: probing for conduit method from ACPI. Jul 21 12:36:40.173938 kernel: psci: PSCIv1.0 detected in firmware. Jul 21 12:36:40.173965 kernel: psci: Using standard PSCI v0.2 function IDs Jul 21 12:36:40.173983 kernel: psci: Trusted OS migration not required Jul 21 12:36:40.174000 kernel: psci: SMC Calling Convention v1.1 Jul 21 12:36:40.174026 kernel: smccc: KVM: hypervisor services detected (0x00000000 0x00000000 0x00000000 0x00000001) Jul 21 12:36:40.174045 kernel: percpu: Embedded 34 pages/cpu s98904 r8192 d32168 u139264 Jul 21 12:36:40.174072 kernel: pcpu-alloc: s98904 r8192 d32168 u139264 alloc=34*4096 Jul 21 12:36:40.174099 kernel: pcpu-alloc: [0] 0 [0] 1 Jul 21 12:36:40.174116 kernel: Detected PIPT I-cache on CPU0 Jul 21 12:36:40.174145 kernel: CPU features: detected: GIC system register CPU interface Jul 21 12:36:40.174163 kernel: CPU features: detected: Spectre-v2 Jul 21 12:36:40.174190 kernel: CPU features: detected: Spectre-v3a Jul 21 12:36:40.174209 kernel: CPU features: detected: Spectre-BHB Jul 21 12:36:40.174226 kernel: CPU features: detected: ARM erratum 1742098 Jul 21 12:36:40.174245 kernel: CPU features: detected: ARM errata 1165522, 1319367, or 1530923 Jul 21 12:36:40.174273 kernel: alternatives: applying boot alternatives Jul 21 12:36:40.174294 kernel: Kernel command line: BOOT_IMAGE=/flatcar/vmlinuz-a mount.usr=/dev/mapper/usr verity.usr=PARTUUID=7130c94a-213a-4e5a-8e26-6cce9662f132 rootflags=rw mount.usrflags=ro consoleblank=0 root=LABEL=ROOT console=tty1 console=ttyS0,115200n8 earlycon flatcar.first_boot=detected acpi=force flatcar.oem.id=ec2 modprobe.blacklist=xen_fbfront net.ifnames=0 nvme_core.io_timeout=4294967295 verity.usrhash=cb29b7dea5ff1999f54ff2f6f0bb741cbce2cca2dddad9dcc68a162e4f647860 Jul 21 12:36:40.174313 kernel: Dentry cache hash table entries: 524288 (order: 10, 4194304 bytes, linear) Jul 21 12:36:40.174334 kernel: Inode-cache hash table entries: 262144 (order: 9, 2097152 bytes, linear) Jul 21 12:36:40.174360 kernel: Fallback order for Node 0: 0 Jul 21 12:36:40.174379 kernel: Built 1 zonelists, mobility grouping on. Total pages: 1007616 Jul 21 12:36:40.174410 kernel: Policy zone: Normal Jul 21 12:36:40.174428 kernel: mem auto-init: stack:off, heap alloc:off, heap free:off Jul 21 12:36:40.174445 kernel: software IO TLB: area num 2. Jul 21 12:36:40.174462 kernel: software IO TLB: mapped [mem 0x0000000074530000-0x0000000078530000] (64MB) Jul 21 12:36:40.174479 kernel: SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1 Jul 21 12:36:40.174496 kernel: ftrace: allocating 41315 entries in 162 pages Jul 21 12:36:40.174524 kernel: ftrace: allocated 162 pages with 3 groups Jul 21 12:36:40.174542 kernel: rcu: Preemptible hierarchical RCU implementation. Jul 21 12:36:40.174571 kernel: rcu: RCU event tracing is enabled. Jul 21 12:36:40.174598 kernel: rcu: RCU restricting CPUs from NR_CPUS=512 to nr_cpu_ids=2. Jul 21 12:36:40.174616 kernel: Trampoline variant of Tasks RCU enabled. Jul 21 12:36:40.174634 kernel: Rude variant of Tasks RCU enabled. Jul 21 12:36:40.174652 kernel: Tracing variant of Tasks RCU enabled. Jul 21 12:36:40.174670 kernel: rcu: RCU calculated value of scheduler-enlistment delay is 100 jiffies. Jul 21 12:36:40.174688 kernel: rcu: Adjusting geometry for rcu_fanout_leaf=16, nr_cpu_ids=2 Jul 21 12:36:40.174706 kernel: RCU Tasks: Setting shift to 1 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=2. Jul 21 12:36:40.174723 kernel: RCU Tasks Rude: Setting shift to 1 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=2. Jul 21 12:36:40.174741 kernel: RCU Tasks Trace: Setting shift to 1 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=2. Jul 21 12:36:40.174770 kernel: NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0 Jul 21 12:36:40.174788 kernel: GICv3: 96 SPIs implemented Jul 21 12:36:40.174811 kernel: GICv3: 0 Extended SPIs implemented Jul 21 12:36:40.174829 kernel: Root IRQ handler: gic_handle_irq Jul 21 12:36:40.176266 kernel: GICv3: GICv3 features: 16 PPIs Jul 21 12:36:40.176288 kernel: GICv3: GICD_CTRL.DS=1, SCR_EL3.FIQ=0 Jul 21 12:36:40.176306 kernel: GICv3: CPU0: found redistributor 0 region 0:0x0000000010200000 Jul 21 12:36:40.176323 kernel: ITS [mem 0x10080000-0x1009ffff] Jul 21 12:36:40.176341 kernel: ITS@0x0000000010080000: allocated 8192 Devices @400190000 (indirect, esz 8, psz 64K, shr 1) Jul 21 12:36:40.176359 kernel: ITS@0x0000000010080000: allocated 8192 Interrupt Collections @4001a0000 (flat, esz 8, psz 64K, shr 1) Jul 21 12:36:40.176377 kernel: GICv3: using LPI property table @0x00000004001b0000 Jul 21 12:36:40.176393 kernel: ITS: Using hypervisor restricted LPI range [128] Jul 21 12:36:40.176425 kernel: GICv3: CPU0: using allocated LPI pending table @0x00000004001d0000 Jul 21 12:36:40.176452 kernel: rcu: srcu_init: Setting srcu_struct sizes based on contention. Jul 21 12:36:40.176477 kernel: arch_timer: cp15 timer(s) running at 83.33MHz (virt). Jul 21 12:36:40.176495 kernel: clocksource: arch_sys_counter: mask: 0x1ffffffffffffff max_cycles: 0x13381ebeec, max_idle_ns: 440795203145 ns Jul 21 12:36:40.176512 kernel: sched_clock: 57 bits at 83MHz, resolution 12ns, wraps every 4398046511100ns Jul 21 12:36:40.176540 kernel: Console: colour dummy device 80x25 Jul 21 12:36:40.176562 kernel: printk: legacy console [tty1] enabled Jul 21 12:36:40.176580 kernel: ACPI: Core revision 20240827 Jul 21 12:36:40.176607 kernel: Calibrating delay loop (skipped), value calculated using timer frequency.. 166.66 BogoMIPS (lpj=83333) Jul 21 12:36:40.176633 kernel: pid_max: default: 32768 minimum: 301 Jul 21 12:36:40.176662 kernel: LSM: initializing lsm=lockdown,capability,landlock,selinux,ima Jul 21 12:36:40.176690 kernel: landlock: Up and running. Jul 21 12:36:40.176716 kernel: SELinux: Initializing. Jul 21 12:36:40.176734 kernel: Mount-cache hash table entries: 8192 (order: 4, 65536 bytes, linear) Jul 21 12:36:40.176752 kernel: Mountpoint-cache hash table entries: 8192 (order: 4, 65536 bytes, linear) Jul 21 12:36:40.176779 kernel: rcu: Hierarchical SRCU implementation. Jul 21 12:36:40.176798 kernel: rcu: Max phase no-delay instances is 400. Jul 21 12:36:40.176820 kernel: Timer migration: 1 hierarchy levels; 8 children per group; 1 crossnode level Jul 21 12:36:40.178993 kernel: Remapping and enabling EFI services. Jul 21 12:36:40.179018 kernel: smp: Bringing up secondary CPUs ... Jul 21 12:36:40.179051 kernel: Detected PIPT I-cache on CPU1 Jul 21 12:36:40.179071 kernel: GICv3: CPU1: found redistributor 1 region 0:0x0000000010220000 Jul 21 12:36:40.179090 kernel: GICv3: CPU1: using allocated LPI pending table @0x00000004001e0000 Jul 21 12:36:40.179126 kernel: CPU1: Booted secondary processor 0x0000000001 [0x410fd083] Jul 21 12:36:40.179146 kernel: smp: Brought up 1 node, 2 CPUs Jul 21 12:36:40.179165 kernel: SMP: Total of 2 processors activated. Jul 21 12:36:40.179185 kernel: CPU: All CPU(s) started at EL1 Jul 21 12:36:40.179211 kernel: CPU features: detected: 32-bit EL0 Support Jul 21 12:36:40.179232 kernel: CPU features: detected: 32-bit EL1 Support Jul 21 12:36:40.179251 kernel: CPU features: detected: CRC32 instructions Jul 21 12:36:40.179270 kernel: alternatives: applying system-wide alternatives Jul 21 12:36:40.179297 kernel: Memory: 3819892K/4030464K available (12480K kernel code, 2492K rwdata, 9560K rodata, 13376K init, 1043K bss, 188472K reserved, 16384K cma-reserved) Jul 21 12:36:40.179328 kernel: devtmpfs: initialized Jul 21 12:36:40.179346 kernel: clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 1911260446275000 ns Jul 21 12:36:40.179365 kernel: futex hash table entries: 512 (order: 3, 32768 bytes, linear) Jul 21 12:36:40.179385 kernel: 22960 pages in range for non-PLT usage Jul 21 12:36:40.179403 kernel: 514480 pages in range for PLT usage Jul 21 12:36:40.179431 kernel: pinctrl core: initialized pinctrl subsystem Jul 21 12:36:40.179456 kernel: SMBIOS 3.0.0 present. Jul 21 12:36:40.179474 kernel: DMI: Amazon EC2 a1.large/, BIOS 1.0 11/1/2018 Jul 21 12:36:40.179493 kernel: DMI: Memory slots populated: 0/0 Jul 21 12:36:40.179511 kernel: NET: Registered PF_NETLINK/PF_ROUTE protocol family Jul 21 12:36:40.179530 kernel: DMA: preallocated 512 KiB GFP_KERNEL pool for atomic allocations Jul 21 12:36:40.179549 kernel: DMA: preallocated 512 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations Jul 21 12:36:40.179570 kernel: DMA: preallocated 512 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations Jul 21 12:36:40.179596 kernel: audit: initializing netlink subsys (disabled) Jul 21 12:36:40.179614 kernel: audit: type=2000 audit(0.239:1): state=initialized audit_enabled=0 res=1 Jul 21 12:36:40.179633 kernel: thermal_sys: Registered thermal governor 'step_wise' Jul 21 12:36:40.179652 kernel: cpuidle: using governor menu Jul 21 12:36:40.179670 kernel: hw-breakpoint: found 6 breakpoint and 4 watchpoint registers. Jul 21 12:36:40.179689 kernel: ASID allocator initialised with 65536 entries Jul 21 12:36:40.179708 kernel: acpiphp: ACPI Hot Plug PCI Controller Driver version: 0.5 Jul 21 12:36:40.179731 kernel: Serial: AMBA PL011 UART driver Jul 21 12:36:40.179750 kernel: HugeTLB: registered 1.00 GiB page size, pre-allocated 0 pages Jul 21 12:36:40.179768 kernel: HugeTLB: 0 KiB vmemmap can be freed for a 1.00 GiB page Jul 21 12:36:40.179787 kernel: HugeTLB: registered 32.0 MiB page size, pre-allocated 0 pages Jul 21 12:36:40.179805 kernel: HugeTLB: 0 KiB vmemmap can be freed for a 32.0 MiB page Jul 21 12:36:40.179824 kernel: HugeTLB: registered 2.00 MiB page size, pre-allocated 0 pages Jul 21 12:36:40.180941 kernel: HugeTLB: 0 KiB vmemmap can be freed for a 2.00 MiB page Jul 21 12:36:40.180978 kernel: HugeTLB: registered 64.0 KiB page size, pre-allocated 0 pages Jul 21 12:36:40.180998 kernel: HugeTLB: 0 KiB vmemmap can be freed for a 64.0 KiB page Jul 21 12:36:40.181017 kernel: ACPI: Added _OSI(Module Device) Jul 21 12:36:40.181037 kernel: ACPI: Added _OSI(Processor Device) Jul 21 12:36:40.181058 kernel: ACPI: Added _OSI(Processor Aggregator Device) Jul 21 12:36:40.181076 kernel: ACPI: 1 ACPI AML tables successfully acquired and loaded Jul 21 12:36:40.181096 kernel: ACPI: Interpreter enabled Jul 21 12:36:40.181120 kernel: ACPI: Using GIC for interrupt routing Jul 21 12:36:40.181140 kernel: ACPI: MCFG table detected, 1 entries Jul 21 12:36:40.181159 kernel: ACPI: CPU0 has been hot-added Jul 21 12:36:40.181178 kernel: ACPI: CPU1 has been hot-added Jul 21 12:36:40.181197 kernel: ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00]) Jul 21 12:36:40.186048 kernel: acpi PNP0A08:00: _OSC: OS supports [ExtendedConfig ASPM ClockPM Segments MSI HPX-Type3] Jul 21 12:36:40.186507 kernel: acpi PNP0A08:00: _OSC: platform does not support [LTR] Jul 21 12:36:40.187259 kernel: acpi PNP0A08:00: _OSC: OS now controls [PCIeHotplug PME AER PCIeCapability] Jul 21 12:36:40.187702 kernel: acpi PNP0A08:00: ECAM area [mem 0x20000000-0x200fffff] reserved by PNP0C02:00 Jul 21 12:36:40.188202 kernel: acpi PNP0A08:00: ECAM at [mem 0x20000000-0x200fffff] for [bus 00] Jul 21 12:36:40.188247 kernel: ACPI: Remapped I/O 0x000000001fff0000 to [io 0x0000-0xffff window] Jul 21 12:36:40.188267 kernel: acpiphp: Slot [1] registered Jul 21 12:36:40.188287 kernel: acpiphp: Slot [2] registered Jul 21 12:36:40.188320 kernel: acpiphp: Slot [3] registered Jul 21 12:36:40.188339 kernel: acpiphp: Slot [4] registered Jul 21 12:36:40.188359 kernel: acpiphp: Slot [5] registered Jul 21 12:36:40.188378 kernel: acpiphp: Slot [6] registered Jul 21 12:36:40.188397 kernel: acpiphp: Slot [7] registered Jul 21 12:36:40.188415 kernel: acpiphp: Slot [8] registered Jul 21 12:36:40.188434 kernel: acpiphp: Slot [9] registered Jul 21 12:36:40.188459 kernel: acpiphp: Slot [10] registered Jul 21 12:36:40.188481 kernel: acpiphp: Slot [11] registered Jul 21 12:36:40.188500 kernel: acpiphp: Slot [12] registered Jul 21 12:36:40.188518 kernel: acpiphp: Slot [13] registered Jul 21 12:36:40.188537 kernel: acpiphp: Slot [14] registered Jul 21 12:36:40.188556 kernel: acpiphp: Slot [15] registered Jul 21 12:36:40.188574 kernel: acpiphp: Slot [16] registered Jul 21 12:36:40.188592 kernel: acpiphp: Slot [17] registered Jul 21 12:36:40.188617 kernel: acpiphp: Slot [18] registered Jul 21 12:36:40.188635 kernel: acpiphp: Slot [19] registered Jul 21 12:36:40.188653 kernel: acpiphp: Slot [20] registered Jul 21 12:36:40.188671 kernel: acpiphp: Slot [21] registered Jul 21 12:36:40.188689 kernel: acpiphp: Slot [22] registered Jul 21 12:36:40.188708 kernel: acpiphp: Slot [23] registered Jul 21 12:36:40.188726 kernel: acpiphp: Slot [24] registered Jul 21 12:36:40.188750 kernel: acpiphp: Slot [25] registered Jul 21 12:36:40.188770 kernel: acpiphp: Slot [26] registered Jul 21 12:36:40.188789 kernel: acpiphp: Slot [27] registered Jul 21 12:36:40.188807 kernel: acpiphp: Slot [28] registered Jul 21 12:36:40.188825 kernel: acpiphp: Slot [29] registered Jul 21 12:36:40.189867 kernel: acpiphp: Slot [30] registered Jul 21 12:36:40.189897 kernel: acpiphp: Slot [31] registered Jul 21 12:36:40.189916 kernel: PCI host bridge to bus 0000:00 Jul 21 12:36:40.190398 kernel: pci_bus 0000:00: root bus resource [mem 0x80000000-0xffffffff window] Jul 21 12:36:40.190886 kernel: pci_bus 0000:00: root bus resource [io 0x0000-0xffff window] Jul 21 12:36:40.191294 kernel: pci_bus 0000:00: root bus resource [mem 0x400000000000-0x407fffffffff window] Jul 21 12:36:40.191727 kernel: pci_bus 0000:00: root bus resource [bus 00] Jul 21 12:36:40.192297 kernel: pci 0000:00:00.0: [1d0f:0200] type 00 class 0x060000 conventional PCI endpoint Jul 21 12:36:40.198429 kernel: pci 0000:00:01.0: [1d0f:8250] type 00 class 0x070003 conventional PCI endpoint Jul 21 12:36:40.198910 kernel: pci 0000:00:01.0: BAR 0 [mem 0x80118000-0x80118fff] Jul 21 12:36:40.199357 kernel: pci 0000:00:04.0: [1d0f:8061] type 00 class 0x010802 PCIe Root Complex Integrated Endpoint Jul 21 12:36:40.205394 kernel: pci 0000:00:04.0: BAR 0 [mem 0x80114000-0x80117fff] Jul 21 12:36:40.205925 kernel: pci 0000:00:04.0: PME# supported from D0 D1 D2 D3hot D3cold Jul 21 12:36:40.206386 kernel: pci 0000:00:05.0: [1d0f:ec20] type 00 class 0x020000 PCIe Root Complex Integrated Endpoint Jul 21 12:36:40.206785 kernel: pci 0000:00:05.0: BAR 0 [mem 0x80110000-0x80113fff] Jul 21 12:36:40.207221 kernel: pci 0000:00:05.0: BAR 2 [mem 0x80000000-0x800fffff pref] Jul 21 12:36:40.207615 kernel: pci 0000:00:05.0: BAR 4 [mem 0x80100000-0x8010ffff] Jul 21 12:36:40.208051 kernel: pci 0000:00:05.0: PME# supported from D0 D1 D2 D3hot D3cold Jul 21 12:36:40.208427 kernel: pci_bus 0000:00: resource 4 [mem 0x80000000-0xffffffff window] Jul 21 12:36:40.208811 kernel: pci_bus 0000:00: resource 5 [io 0x0000-0xffff window] Jul 21 12:36:40.209224 kernel: pci_bus 0000:00: resource 6 [mem 0x400000000000-0x407fffffffff window] Jul 21 12:36:40.209263 kernel: ACPI: PCI: Interrupt link GSI0 configured for IRQ 35 Jul 21 12:36:40.209283 kernel: ACPI: PCI: Interrupt link GSI1 configured for IRQ 36 Jul 21 12:36:40.209303 kernel: ACPI: PCI: Interrupt link GSI2 configured for IRQ 37 Jul 21 12:36:40.209365 kernel: ACPI: PCI: Interrupt link GSI3 configured for IRQ 38 Jul 21 12:36:40.209391 kernel: iommu: Default domain type: Translated Jul 21 12:36:40.209420 kernel: iommu: DMA domain TLB invalidation policy: strict mode Jul 21 12:36:40.209440 kernel: efivars: Registered efivars operations Jul 21 12:36:40.209458 kernel: vgaarb: loaded Jul 21 12:36:40.209477 kernel: clocksource: Switched to clocksource arch_sys_counter Jul 21 12:36:40.209495 kernel: VFS: Disk quotas dquot_6.6.0 Jul 21 12:36:40.209514 kernel: VFS: Dquot-cache hash table entries: 512 (order 0, 4096 bytes) Jul 21 12:36:40.209532 kernel: pnp: PnP ACPI init Jul 21 12:36:40.210131 kernel: system 00:00: [mem 0x20000000-0x2fffffff] could not be reserved Jul 21 12:36:40.210182 kernel: pnp: PnP ACPI: found 1 devices Jul 21 12:36:40.210203 kernel: NET: Registered PF_INET protocol family Jul 21 12:36:40.210222 kernel: IP idents hash table entries: 65536 (order: 7, 524288 bytes, linear) Jul 21 12:36:40.210242 kernel: tcp_listen_portaddr_hash hash table entries: 2048 (order: 3, 32768 bytes, linear) Jul 21 12:36:40.210260 kernel: Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear) Jul 21 12:36:40.210293 kernel: TCP established hash table entries: 32768 (order: 6, 262144 bytes, linear) Jul 21 12:36:40.210314 kernel: TCP bind hash table entries: 32768 (order: 8, 1048576 bytes, linear) Jul 21 12:36:40.210332 kernel: TCP: Hash tables configured (established 32768 bind 32768) Jul 21 12:36:40.210350 kernel: UDP hash table entries: 2048 (order: 4, 65536 bytes, linear) Jul 21 12:36:40.210369 kernel: UDP-Lite hash table entries: 2048 (order: 4, 65536 bytes, linear) Jul 21 12:36:40.210388 kernel: NET: Registered PF_UNIX/PF_LOCAL protocol family Jul 21 12:36:40.210406 kernel: PCI: CLS 0 bytes, default 64 Jul 21 12:36:40.210425 kernel: kvm [1]: HYP mode not available Jul 21 12:36:40.210452 kernel: Initialise system trusted keyrings Jul 21 12:36:40.210471 kernel: workingset: timestamp_bits=39 max_order=20 bucket_order=0 Jul 21 12:36:40.210491 kernel: Key type asymmetric registered Jul 21 12:36:40.210510 kernel: Asymmetric key parser 'x509' registered Jul 21 12:36:40.210532 kernel: Block layer SCSI generic (bsg) driver version 0.4 loaded (major 249) Jul 21 12:36:40.210552 kernel: io scheduler mq-deadline registered Jul 21 12:36:40.210570 kernel: io scheduler kyber registered Jul 21 12:36:40.210596 kernel: io scheduler bfq registered Jul 21 12:36:40.211106 kernel: pl061_gpio ARMH0061:00: PL061 GPIO chip registered Jul 21 12:36:40.211151 kernel: input: Power Button as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0C:00/input/input0 Jul 21 12:36:40.211171 kernel: ACPI: button: Power Button [PWRB] Jul 21 12:36:40.211191 kernel: input: Sleep Button as /devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0E:00/input/input1 Jul 21 12:36:40.211209 kernel: ACPI: button: Sleep Button [SLPB] Jul 21 12:36:40.211238 kernel: Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled Jul 21 12:36:40.211259 kernel: ACPI: \_SB_.PCI0.GSI2: Enabled at IRQ 37 Jul 21 12:36:40.211680 kernel: serial 0000:00:01.0: enabling device (0010 -> 0012) Jul 21 12:36:40.211719 kernel: printk: legacy console [ttyS0] disabled Jul 21 12:36:40.211739 kernel: 0000:00:01.0: ttyS0 at MMIO 0x80118000 (irq = 14, base_baud = 115200) is a 16550A Jul 21 12:36:40.211758 kernel: printk: legacy console [ttyS0] enabled Jul 21 12:36:40.211777 kernel: printk: legacy bootconsole [uart0] disabled Jul 21 12:36:40.211814 kernel: ACPI: bus type drm_connector registered Jul 21 12:36:40.211884 kernel: thunder_xcv, ver 1.0 Jul 21 12:36:40.211909 kernel: thunder_bgx, ver 1.0 Jul 21 12:36:40.211928 kernel: nicpf, ver 1.0 Jul 21 12:36:40.211947 kernel: nicvf, ver 1.0 Jul 21 12:36:40.212467 kernel: rtc-efi rtc-efi.0: registered as rtc0 Jul 21 12:36:40.215631 kernel: rtc-efi rtc-efi.0: setting system clock to 2026-07-21T12:36:35 UTC (1784637395) Jul 21 12:36:40.215703 kernel: hid: raw HID events driver (C) Jiri Kosina Jul 21 12:36:40.215724 kernel: hw perfevents: enabled with armv8_pmuv3_0 PMU driver, 3 (0,80000003) counters available Jul 21 12:36:40.215745 kernel: watchdog: NMI not fully supported Jul 21 12:36:40.215767 kernel: NET: Registered PF_INET6 protocol family Jul 21 12:36:40.215786 kernel: watchdog: Hard watchdog permanently disabled Jul 21 12:36:40.215804 kernel: Segment Routing with IPv6 Jul 21 12:36:40.215822 kernel: In-situ OAM (IOAM) with IPv6 Jul 21 12:36:40.215908 kernel: NET: Registered PF_PACKET protocol family Jul 21 12:36:40.215928 kernel: Key type dns_resolver registered Jul 21 12:36:40.215949 kernel: registered taskstats version 1 Jul 21 12:36:40.215967 kernel: Loading compiled-in X.509 certificates Jul 21 12:36:40.215987 kernel: Loaded X.509 cert 'Kinvolk GmbH: Module signing key for 6.12.95-flatcar: 906bd54d032a8a3902b88d6f6aa9201f425d8d9b' Jul 21 12:36:40.216028 kernel: Demotion targets for Node 0: null Jul 21 12:36:40.216048 kernel: Key type .fscrypt registered Jul 21 12:36:40.216077 kernel: Key type fscrypt-provisioning registered Jul 21 12:36:40.216098 kernel: ima: No TPM chip found, activating TPM-bypass! Jul 21 12:36:40.216117 kernel: ima: Allocated hash algorithm: sha1 Jul 21 12:36:40.216136 kernel: ima: No architecture policies found Jul 21 12:36:40.216154 kernel: alg: No test for fips(ansi_cprng) (fips_ansi_cprng) Jul 21 12:36:40.216173 kernel: clk: Disabling unused clocks Jul 21 12:36:40.216191 kernel: PM: genpd: Disabling unused power domains Jul 21 12:36:40.216216 kernel: Freeing unused kernel memory: 13376K Jul 21 12:36:40.216237 kernel: Run /init as init process Jul 21 12:36:40.216256 kernel: with arguments: Jul 21 12:36:40.216274 kernel: /init Jul 21 12:36:40.216293 kernel: with environment: Jul 21 12:36:40.216311 kernel: HOME=/ Jul 21 12:36:40.216329 kernel: TERM=linux Jul 21 12:36:40.216348 kernel: ACPI: \_SB_.PCI0.GSI0: Enabled at IRQ 35 Jul 21 12:36:40.216731 kernel: nvme nvme0: pci function 0000:00:04.0 Jul 21 12:36:40.221685 kernel: nvme nvme0: 2/0/0 default/read/poll queues Jul 21 12:36:40.221736 kernel: GPT:Primary header thinks Alt. header is not at the end of the disk. Jul 21 12:36:40.221756 kernel: GPT:25804799 != 33554431 Jul 21 12:36:40.221776 kernel: GPT:Alternate GPT header not at the end of the disk. Jul 21 12:36:40.221794 kernel: GPT:25804799 != 33554431 Jul 21 12:36:40.221828 kernel: GPT: Use GNU Parted to correct GPT errors. Jul 21 12:36:40.221889 kernel: nvme0n1: p1 p2 p3 p4 p6 p7 p9 Jul 21 12:36:40.221909 kernel: SCSI subsystem initialized Jul 21 12:36:40.221930 kernel: device-mapper: core: CONFIG_IMA_DISABLE_HTABLE is disabled. Duplicate IMA measurements will not be recorded in the IMA log. Jul 21 12:36:40.221950 kernel: device-mapper: uevent: version 1.0.3 Jul 21 12:36:40.221969 kernel: device-mapper: ioctl: 4.48.0-ioctl (2023-03-01) initialised: dm-devel@lists.linux.dev Jul 21 12:36:40.221988 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:40.222016 kernel: raid6: neonx8 gen() 6550 MB/s Jul 21 12:36:40.222034 kernel: raid6: neonx4 gen() 6423 MB/s Jul 21 12:36:40.222053 kernel: raid6: neonx2 gen() 5434 MB/s Jul 21 12:36:40.222071 kernel: raid6: neonx1 gen() 3953 MB/s Jul 21 12:36:40.222089 kernel: raid6: int64x8 gen() 3188 MB/s Jul 21 12:36:40.222108 kernel: raid6: int64x4 gen() 3670 MB/s Jul 21 12:36:40.222126 kernel: raid6: int64x2 gen() 3609 MB/s Jul 21 12:36:40.222152 kernel: raid6: int64x1 gen() 2753 MB/s Jul 21 12:36:40.222171 kernel: raid6: using algorithm neonx8 gen() 6550 MB/s Jul 21 12:36:40.222190 kernel: raid6: .... xor() 4531 MB/s, rmw enabled Jul 21 12:36:40.222208 kernel: raid6: using neon recovery algorithm Jul 21 12:36:40.222226 kernel: xor: measuring software checksum speed Jul 21 12:36:40.222244 kernel: 8regs : 10466 MB/sec Jul 21 12:36:40.222263 kernel: 32regs : 11056 MB/sec Jul 21 12:36:40.222286 kernel: arm64_neon : 8964 MB/sec Jul 21 12:36:40.222305 kernel: xor: using function: 32regs (11056 MB/sec) Jul 21 12:36:40.222323 kernel: Btrfs loaded, zoned=no, fsverity=no Jul 21 12:36:40.222342 kernel: BTRFS: device fsid 4befe9c1-d619-4fef-8f96-43063af51751 devid 1 transid 40 /dev/mapper/usr (254:0) scanned by mount (222) Jul 21 12:36:40.222361 kernel: BTRFS info (device dm-0): first mount of filesystem 4befe9c1-d619-4fef-8f96-43063af51751 Jul 21 12:36:40.222380 kernel: BTRFS info (device dm-0): using crc32c (crc32c-generic) checksum algorithm Jul 21 12:36:40.222398 kernel: BTRFS info (device dm-0 state E): enabling ssd optimizations Jul 21 12:36:40.222424 kernel: BTRFS info (device dm-0 state E): disabling log replay at mount time Jul 21 12:36:40.222444 kernel: BTRFS info (device dm-0 state E): enabling free space tree Jul 21 12:36:40.222463 kernel: loop: module loaded Jul 21 12:36:40.222482 kernel: loop0: detected capacity change from 0 to 100016 Jul 21 12:36:40.222500 kernel: squashfs: version 4.0 (2009/01/31) Phillip Lougher Jul 21 12:36:40.222523 systemd[1]: Successfully made /usr/ read-only. Jul 21 12:36:40.222550 systemd[1]: systemd 260.1 running in system mode (+PAM +AUDIT +SELINUX -APPARMOR +IMA +IPE +SMACK +SECCOMP -GCRYPT -GNUTLS +OPENSSL -ACL +BLKID +CURL +ELFUTILS -FIDO2 +IDN2 +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 -PWQUALITY -P11KIT -QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD -BPF_FRAMEWORK -BTF -XKBCOMMON +UTMP +LIBARCHIVE) Jul 21 12:36:40.222578 systemd[1]: Detected virtualization amazon. Jul 21 12:36:40.222598 systemd[1]: Detected architecture arm64. Jul 21 12:36:40.222617 systemd[1]: Running in initrd. Jul 21 12:36:40.222636 systemd[1]: Initializing machine ID from SMBIOS/DMI UUID. Jul 21 12:36:40.222657 systemd[1]: No hostname configured, using default hostname. Jul 21 12:36:40.222677 systemd[1]: Hostname set to . Jul 21 12:36:40.222705 (gene[258]: '/usr/lib/systemd/system-generators/dracut-crypt-generator' failed with exit status 2. Jul 21 12:36:40.222743 systemd[1]: Queued start job for default target initrd.target. Jul 21 12:36:40.222769 systemd[1]: Started clevis-luks-askpass.path - Forward Password Requests to Clevis Directory Watch. Jul 21 12:36:40.222790 systemd[1]: Started systemd-ask-password-console.path - Dispatch Password Requests to Console Directory Watch. Jul 21 12:36:40.222816 systemd[1]: Expecting device dev-disk-by\x2dlabel-EFI\x2dSYSTEM.device - /dev/disk/by-label/EFI-SYSTEM... Jul 21 12:36:40.222880 systemd[1]: Expecting device dev-disk-by\x2dlabel-OEM.device - /dev/disk/by-label/OEM... Jul 21 12:36:40.222907 systemd[1]: Expecting device dev-disk-by\x2dlabel-ROOT.device - /dev/disk/by-label/ROOT... Jul 21 12:36:40.222929 systemd[1]: Expecting device dev-disk-by\x2dpartlabel-USR\x2dA.device - /dev/disk/by-partlabel/USR-A... Jul 21 12:36:40.222950 systemd[1]: Expecting device dev-mapper-usr.device - /dev/mapper/usr... Jul 21 12:36:40.222970 systemd[1]: Reached target cryptsetup-pre.target - Local Encrypted Volumes (Pre). Jul 21 12:36:40.223001 systemd[1]: Reached target cryptsetup.target - Local Encrypted Volumes. Jul 21 12:36:40.223022 systemd[1]: Reached target initrd-usr-fs.target - Initrd /usr File System. Jul 21 12:36:40.223043 systemd[1]: Reached target paths.target - Path Units. Jul 21 12:36:40.223063 systemd[1]: Reached target slices.target - Slice Units. Jul 21 12:36:40.223084 systemd[1]: Reached target swap.target - Swaps. Jul 21 12:36:40.223104 systemd[1]: Reached target timers.target - Timer Units. Jul 21 12:36:40.223124 systemd[1]: Listening on iscsid.socket - Open-iSCSI iscsid Socket. Jul 21 12:36:40.223151 systemd[1]: Listening on iscsiuio.socket - Open-iSCSI iscsiuio Socket. Jul 21 12:36:40.223172 systemd[1]: Listening on systemd-coredump.socket - Process Core Dump Socket. Jul 21 12:36:40.223194 systemd[1]: Listening on systemd-journald-audit.socket - Journal Audit Socket. Jul 21 12:36:40.223214 systemd[1]: Listening on systemd-journald-dev-log.socket - Journal Socket (/dev/log). Jul 21 12:36:40.223235 systemd[1]: Listening on systemd-journald.socket - Journal Sockets. Jul 21 12:36:40.223255 systemd[1]: Listening on systemd-networkd-resolve-hook.socket - Network Management Resolve Hook Socket. Jul 21 12:36:40.223283 systemd[1]: Listening on systemd-networkd.socket - Network Management Netlink Socket. Jul 21 12:36:40.223305 systemd[1]: Listening on systemd-udevd-control.socket - udev Control Socket. Jul 21 12:36:40.223326 systemd[1]: Listening on systemd-udevd-kernel.socket - udev Kernel Socket. Jul 21 12:36:40.223347 systemd[1]: Reached target sockets.target - Socket Units. Jul 21 12:36:40.223370 systemd[1]: afterburn-network-kargs.service - Afterburn Initrd Setup Network Kernel Arguments skipped, no trigger condition checks were met. Jul 21 12:36:40.223392 systemd[1]: Starting ignition-setup-pre.service - Ignition env setup... Jul 21 12:36:40.223414 systemd[1]: Starting kmod-static-nodes.service - Create List of Static Device Nodes... Jul 21 12:36:40.223445 systemd[1]: Finished network-cleanup.service - Network Cleanup. Jul 21 12:36:40.223469 systemd[1]: systemd-battery-check.service - Early Battery Level Check skipped, unmet condition check ConditionDirectoryNotEmpty=/sys/class/power_supply Jul 21 12:36:40.223493 systemd[1]: Starting systemd-journald.service - Journal Service... Jul 21 12:36:40.223521 systemd[1]: Starting systemd-modules-load.service - Load Kernel Modules... Jul 21 12:36:40.223546 systemd[1]: Starting systemd-vconsole-setup.service - Virtual Console Setup... Jul 21 12:36:40.223570 systemd[1]: Finished ignition-setup-pre.service - Ignition env setup. Jul 21 12:36:40.223592 systemd[1]: Finished kmod-static-nodes.service - Create List of Static Device Nodes. Jul 21 12:36:40.223614 systemd[1]: Starting systemd-tmpfiles-setup-dev-early.service - Create Static Device Nodes in /dev gracefully... Jul 21 12:36:40.223717 systemd-journald[416]: Collecting audit messages is enabled. Jul 21 12:36:40.223769 kernel: bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this. Jul 21 12:36:40.223794 systemd[1]: Finished systemd-vconsole-setup.service - Virtual Console Setup. Jul 21 12:36:40.223821 kernel: Bridge firewalling registered Jul 21 12:36:40.223919 kernel: audit: type=1130 audit(1784637400.190:2): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.223948 systemd[1]: Finished systemd-modules-load.service - Load Kernel Modules. Jul 21 12:36:40.223971 kernel: audit: type=1130 audit(1784637400.201:3): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-modules-load comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.223993 systemd[1]: Finished systemd-tmpfiles-setup-dev-early.service - Create Static Device Nodes in /dev gracefully. Jul 21 12:36:40.224015 kernel: audit: type=1130 audit(1784637400.214:4): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev-early comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.224049 systemd[1]: Starting dracut-cmdline-ask.service - dracut ask for additional cmdline parameters... Jul 21 12:36:40.224079 systemd-journald[416]: Journal started Jul 21 12:36:40.224119 systemd-journald[416]: Runtime Journal (/run/log/journal/ec2c0ef6f39eee0a06e5e3b661241913) is 8M, max 75.3M, 67.3M free. Jul 21 12:36:40.190000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.201000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-modules-load comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.214000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev-early comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.063481 systemd-modules-load[418]: Using 2 probe threads Jul 21 12:36:40.168971 systemd-vconsole-setup[421]: Configuration of first virtual console was skipped, ignoring remaining ones. Jul 21 12:36:40.188994 systemd-modules-load[418]: Inserted module 'br_netfilter' Jul 21 12:36:40.243875 systemd[1]: Starting systemd-sysctl.service - Apply Kernel Variables... Jul 21 12:36:40.264880 systemd[1]: Starting systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev... Jul 21 12:36:40.277573 systemd[1]: Started systemd-journald.service - Journal Service. Jul 21 12:36:40.276000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-journald comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.287604 systemd[1]: Starting systemd-tmpfiles-setup.service - Create System Files and Directories... Jul 21 12:36:40.295892 kernel: audit: type=1130 audit(1784637400.276:5): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-journald comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.299385 systemd[1]: systemd-sysctl.service: Deactivated successfully. Jul 21 12:36:40.309134 systemd[1]: Finished systemd-sysctl.service - Apply Kernel Variables. Jul 21 12:36:40.311000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.312000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.320869 kernel: audit: type=1130 audit(1784637400.311:6): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.328951 kernel: audit: type=1131 audit(1784637400.312:7): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.336038 systemd[1]: Finished systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev. Jul 21 12:36:40.342000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.346591 systemd-tmpfiles[462]: /usr/lib/tmpfiles.d/systemd.conf:30: Duplicate line for path "/var/lib/systemd", ignoring. Jul 21 12:36:40.347340 systemd-tmpfiles[462]: /usr/lib/tmpfiles.d/var.conf:14: Duplicate line for path "/var/log", ignoring. Jul 21 12:36:40.358953 systemd[1]: Finished dracut-cmdline-ask.service - dracut ask for additional cmdline parameters. Jul 21 12:36:40.365533 kernel: audit: type=1130 audit(1784637400.342:8): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.363000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-cmdline-ask comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.370415 kernel: audit: type=1130 audit(1784637400.363:9): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-cmdline-ask comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.371638 systemd[1]: Starting dracut-cmdline.service - dracut cmdline hook... Jul 21 12:36:40.375000 audit: BPF prog-id=5 op=LOAD Jul 21 12:36:40.380829 systemd[1]: Starting systemd-resolved.service - Network Name Resolution... Jul 21 12:36:40.384022 kernel: audit: type=1334 audit(1784637400.375:10): prog-id=5 op=LOAD Jul 21 12:36:40.395448 systemd[1]: Finished systemd-tmpfiles-setup.service - Create System Files and Directories. Jul 21 12:36:40.396000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.410917 kernel: audit: type=1130 audit(1784637400.396:11): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.433953 dracut-cmdline[479]: dracut-111 Jul 21 12:36:40.445064 dracut-cmdline[479]: Using kernel command line parameters: SYSTEMD_SULOGIN_FORCE=1 BOOT_IMAGE=/flatcar/vmlinuz-a mount.usr=/dev/mapper/usr verity.usr=PARTUUID=7130c94a-213a-4e5a-8e26-6cce9662f132 rootflags=rw mount.usrflags=ro consoleblank=0 root=LABEL=ROOT console=tty1 console=ttyS0,115200n8 earlycon flatcar.first_boot=detected acpi=force flatcar.oem.id=ec2 modprobe.blacklist=xen_fbfront net.ifnames=0 nvme_core.io_timeout=4294967295 verity.usrhash=cb29b7dea5ff1999f54ff2f6f0bb741cbce2cca2dddad9dcc68a162e4f647860 Jul 21 12:36:40.570936 systemd-resolved[481]: Positive Trust Anchors: Jul 21 12:36:40.577431 systemd-resolved[481]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d Jul 21 12:36:40.577446 systemd-resolved[481]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 Jul 21 12:36:40.577513 systemd-resolved[481]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test Jul 21 12:36:40.757873 kernel: Loading iSCSI transport class v2.0-870. Jul 21 12:36:40.816890 kernel: iscsi: registered transport (tcp) Jul 21 12:36:40.882890 kernel: iscsi: registered transport (qla4xxx) Jul 21 12:36:40.882980 kernel: QLogic iSCSI HBA Driver Jul 21 12:36:40.910888 kernel: random: crng init done Jul 21 12:36:40.917861 systemd-resolved[481]: Defaulting to hostname 'linux'. Jul 21 12:36:40.926000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-resolved comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.925169 systemd[1]: Started systemd-resolved.service - Network Name Resolution. Jul 21 12:36:40.934087 systemd[1]: Reached target nss-lookup.target - Host and Network Name Lookups. Jul 21 12:36:40.946134 systemd[1]: Starting systemd-network-generator.service - Generate Network Units from Kernel Command Line... Jul 21 12:36:40.976111 systemd[1]: Finished systemd-network-generator.service - Generate Network Units from Kernel Command Line. Jul 21 12:36:40.981000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-network-generator comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:40.986248 systemd[1]: Reached target network-pre.target - Preparation for Network. Jul 21 12:36:41.090965 systemd[1]: Finished dracut-cmdline.service - dracut cmdline hook. Jul 21 12:36:41.089000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-cmdline comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:41.094988 systemd[1]: Starting dracut-pre-udev.service - dracut pre-udev hook... Jul 21 12:36:41.116305 systemd[1]: Starting parse-ip-for-networkd.service - Write systemd-networkd units from cmdline... Jul 21 12:36:41.165970 systemd[1]: Finished dracut-pre-udev.service - dracut pre-udev hook. Jul 21 12:36:41.174000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-udev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:41.176000 audit: BPF prog-id=6 op=LOAD Jul 21 12:36:41.177000 audit: BPF prog-id=7 op=LOAD Jul 21 12:36:41.182558 systemd[1]: Starting systemd-udevd.service - Rule-based Manager for Device Events and Files... Jul 21 12:36:41.299572 systemd-udevd[720]: Using default interface naming scheme 'v260'. Jul 21 12:36:41.329952 systemd[1]: Finished parse-ip-for-networkd.service - Write systemd-networkd units from cmdline. Jul 21 12:36:41.335000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=parse-ip-for-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:41.354268 systemd[1]: Started systemd-udevd.service - Rule-based Manager for Device Events and Files. Jul 21 12:36:41.363000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-udevd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:41.367917 systemd[1]: Starting dracut-pre-trigger.service - dracut pre-trigger hook... Jul 21 12:36:41.373000 audit: BPF prog-id=8 op=LOAD Jul 21 12:36:41.385983 systemd[1]: Starting systemd-networkd.service - Network Management... Jul 21 12:36:41.435864 dracut-pre-trigger[827]: rd.md=0: removing MD RAID activation Jul 21 12:36:41.494598 systemd-networkd[837]: Failed to open nftables netlink socket. IPMasquerade= and NFTSet= settings will not be applied. Ignoring: Protocol not supported Jul 21 12:36:41.513971 systemd[1]: Finished dracut-pre-trigger.service - dracut pre-trigger hook. Jul 21 12:36:41.520000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:41.526075 systemd[1]: Starting systemd-udev-trigger.service - Coldplug All udev Devices... Jul 21 12:36:41.526510 systemd-networkd[837]: lo: Link UP Jul 21 12:36:41.526517 systemd-networkd[837]: lo: Gained carrier Jul 21 12:36:41.536000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:41.531688 systemd[1]: Started systemd-networkd.service - Network Management. Jul 21 12:36:41.539873 systemd[1]: Reached target network.target - Network. Jul 21 12:36:41.807934 systemd[1]: Finished systemd-udev-trigger.service - Coldplug All udev Devices. Jul 21 12:36:41.806000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-udev-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:41.815490 systemd[1]: Starting dracut-initqueue.service - dracut initqueue hook... Jul 21 12:36:42.230791 systemd[1]: systemd-vconsole-setup.service: Deactivated successfully. Jul 21 12:36:42.232000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:42.231105 systemd[1]: Stopped systemd-vconsole-setup.service - Virtual Console Setup. Jul 21 12:36:42.253160 systemd[1]: Stopping systemd-vconsole-setup.service - Virtual Console Setup... Jul 21 12:36:42.268051 systemd[1]: Starting systemd-vconsole-setup.service - Virtual Console Setup... Jul 21 12:36:42.280417 kernel: ACPI: \_SB_.PCI0.GSI1: Enabled at IRQ 36 Jul 21 12:36:42.280529 kernel: ena 0000:00:05.0: enabling device (0010 -> 0012) Jul 21 12:36:42.288910 kernel: ena 0000:00:05.0: ENA device version: 0.10 Jul 21 12:36:42.289560 kernel: nvme nvme0: using unchecked data buffer Jul 21 12:36:42.291347 kernel: ena 0000:00:05.0: ENA controller version: 0.0.1 implementation version 1 Jul 21 12:36:42.299888 kernel: ena 0000:00:05.0: Elastic Network Adapter (ENA) found at mem 80110000, mac addr 06:71:38:23:cb:53 Jul 21 12:36:42.320187 (udev-worker)[919]: Network interface NamePolicy= disabled on kernel command line. Jul 21 12:36:42.342380 systemd-vconsole-setup[933]: Configuration of first virtual console was skipped, ignoring remaining ones. Jul 21 12:36:42.352999 systemd[1]: Finished systemd-vconsole-setup.service - Virtual Console Setup. Jul 21 12:36:42.355000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:42.358363 systemd-networkd[837]: eth0: Found matching .network file, based on potentially unpredictable interface name: /usr/lib/systemd/network/zz-default.network Jul 21 12:36:42.358381 systemd-networkd[837]: eth0: Configuring with /usr/lib/systemd/network/zz-default.network. Jul 21 12:36:42.374477 systemd-networkd[837]: eth0: Link UP Jul 21 12:36:42.378151 systemd-networkd[837]: eth0: Gained carrier Jul 21 12:36:42.378194 systemd-networkd[837]: eth0: Found matching .network file, based on potentially unpredictable interface name: /usr/lib/systemd/network/zz-default.network Jul 21 12:36:42.399971 systemd-networkd[837]: eth0: DHCPv4 address 172.31.16.165/20, gateway 172.31.16.1 acquired from 172.31.16.1 Jul 21 12:36:42.484157 systemd[1]: Found device dev-disk-by\x2dpartlabel-USR\x2dA.device - Amazon Elastic Block Store USR-A. Jul 21 12:36:42.539759 systemd[1]: Starting disk-uuid.service - Generate new UUID for disk GPT if necessary... Jul 21 12:36:42.586061 disk-uuid[998]: Primary Header is updated. Jul 21 12:36:42.586061 disk-uuid[998]: Secondary Entries is updated. Jul 21 12:36:42.586061 disk-uuid[998]: Secondary Header is updated. Jul 21 12:36:42.659199 systemd[1]: Found device dev-disk-by\x2dlabel-OEM.device - Amazon Elastic Block Store OEM. Jul 21 12:36:42.715891 systemd[1]: Found device dev-disk-by\x2dlabel-EFI\x2dSYSTEM.device - Amazon Elastic Block Store EFI-SYSTEM. Jul 21 12:36:42.757869 systemd[1]: Found device dev-disk-by\x2dlabel-ROOT.device - Amazon Elastic Block Store ROOT. Jul 21 12:36:42.790099 systemd[1]: Mounting oem.mount - /oem... Jul 21 12:36:42.834925 kernel: BTRFS: device label OEM devid 1 transid 11 /dev/nvme0n1p6 (259:5) scanned by mount (1036) Jul 21 12:36:42.839898 kernel: BTRFS info (device nvme0n1p6): first mount of filesystem c5d600df-e377-4112-9764-9143f7b9b469 Jul 21 12:36:42.841069 kernel: BTRFS info (device nvme0n1p6): using crc32c (crc32c-generic) checksum algorithm Jul 21 12:36:42.898154 kernel: BTRFS info (device nvme0n1p6): enabling ssd optimizations Jul 21 12:36:42.898234 kernel: BTRFS info (device nvme0n1p6): enabling free space tree Jul 21 12:36:42.901720 systemd[1]: Mounted oem.mount - /oem. Jul 21 12:36:42.909889 systemd[1]: Starting ignition-fetch-offline.service - Ignition (fetch-offline)... Jul 21 12:36:43.238112 systemd[1]: Finished dracut-initqueue.service - dracut initqueue hook. Jul 21 12:36:43.243000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-initqueue comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:43.246322 systemd[1]: Reached target remote-fs-pre.target - Preparation for Remote File Systems. Jul 21 12:36:43.252152 systemd[1]: Reached target remote-cryptsetup.target - Remote Encrypted Volumes. Jul 21 12:36:43.256803 systemd[1]: Reached target remote-fs.target - Remote File Systems. Jul 21 12:36:43.269718 systemd[1]: Starting dracut-pre-mount.service - dracut pre-mount hook... Jul 21 12:36:43.315708 systemd[1]: Finished dracut-pre-mount.service - dracut pre-mount hook. Jul 21 12:36:43.317000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:43.675719 disk-uuid[1001]: Warning: The kernel is still using the old partition table. Jul 21 12:36:43.675719 disk-uuid[1001]: The new table will be used at the next reboot or after you Jul 21 12:36:43.675719 disk-uuid[1001]: run partprobe(8) or kpartx(8) Jul 21 12:36:43.675719 disk-uuid[1001]: The operation has completed successfully. Jul 21 12:36:43.692771 systemd[1]: disk-uuid.service: Deactivated successfully. Jul 21 12:36:43.696891 systemd[1]: Finished disk-uuid.service - Generate new UUID for disk GPT if necessary. Jul 21 12:36:43.700000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=disk-uuid comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:43.700000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=disk-uuid comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:43.709716 systemd[1]: Mounting boot.mount - Boot partition... Jul 21 12:36:43.832675 systemd[1]: Mounted boot.mount - Boot partition. Jul 21 12:36:44.392080 systemd-networkd[837]: eth0: Gained IPv6LL Jul 21 12:36:44.637056 ignition[1125]: Ignition 2.24.0 Jul 21 12:36:44.637082 ignition[1125]: Stage: fetch-offline Jul 21 12:36:44.641958 ignition[1125]: no config dir at "/usr/lib/ignition/base.d" Jul 21 12:36:44.641996 ignition[1125]: no config dir at "/usr/lib/ignition/base.platform.d/aws" Jul 21 12:36:44.642990 ignition[1125]: Ignition finished successfully Jul 21 12:36:44.653652 systemd[1]: Finished ignition-fetch-offline.service - Ignition (fetch-offline). Jul 21 12:36:44.655000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-fetch-offline comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:44.660482 systemd[1]: Starting ignition-fetch.service - Ignition (fetch)... Jul 21 12:36:44.701747 ignition[1252]: Ignition 2.24.0 Jul 21 12:36:44.701777 ignition[1252]: Stage: fetch Jul 21 12:36:44.702127 ignition[1252]: no config dir at "/usr/lib/ignition/base.d" Jul 21 12:36:44.702148 ignition[1252]: no config dir at "/usr/lib/ignition/base.platform.d/aws" Jul 21 12:36:44.702278 ignition[1252]: PUT http://169.254.169.254/latest/api/token: attempt #1 Jul 21 12:36:44.720053 ignition[1252]: PUT result: OK Jul 21 12:36:44.723200 ignition[1252]: parsed url from cmdline: "" Jul 21 12:36:44.723223 ignition[1252]: no config URL provided Jul 21 12:36:44.723239 ignition[1252]: reading system config file "/usr/lib/ignition/user.ign" Jul 21 12:36:44.723318 ignition[1252]: no config at "/usr/lib/ignition/user.ign" Jul 21 12:36:44.723377 ignition[1252]: PUT http://169.254.169.254/latest/api/token: attempt #1 Jul 21 12:36:44.731873 ignition[1252]: PUT result: OK Jul 21 12:36:44.731978 ignition[1252]: GET http://169.254.169.254/2019-10-01/user-data: attempt #1 Jul 21 12:36:44.737892 ignition[1252]: GET result: OK Jul 21 12:36:44.738044 ignition[1252]: parsing config with SHA512: 06a9cc4c1f7b26496d14d65302a3683b79118d1449ecdc495e378713dbcdcf4627a86bafaea328071a26106407e59f589d8a78781ed863f09dc0dc89ac0bcc82 Jul 21 12:36:44.753168 unknown[1252]: fetched base config from "system" Jul 21 12:36:44.753198 unknown[1252]: fetched base config from "system" Jul 21 12:36:44.753933 ignition[1252]: fetch: fetch complete Jul 21 12:36:44.753213 unknown[1252]: fetched user config from "aws" Jul 21 12:36:44.753945 ignition[1252]: fetch: fetch passed Jul 21 12:36:44.754050 ignition[1252]: Ignition finished successfully Jul 21 12:36:44.768208 systemd[1]: Finished ignition-fetch.service - Ignition (fetch). Jul 21 12:36:44.771000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-fetch comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:44.777184 systemd[1]: Starting ignition-kargs.service - Ignition (kargs)... Jul 21 12:36:44.820661 ignition[1261]: Ignition 2.24.0 Jul 21 12:36:44.820695 ignition[1261]: Stage: kargs Jul 21 12:36:44.821083 ignition[1261]: no config dir at "/usr/lib/ignition/base.d" Jul 21 12:36:44.821107 ignition[1261]: no config dir at "/usr/lib/ignition/base.platform.d/aws" Jul 21 12:36:44.821256 ignition[1261]: PUT http://169.254.169.254/latest/api/token: attempt #1 Jul 21 12:36:44.825027 ignition[1261]: PUT result: OK Jul 21 12:36:44.834697 ignition[1261]: kargs: kargs passed Jul 21 12:36:44.834801 ignition[1261]: Ignition finished successfully Jul 21 12:36:44.843934 systemd[1]: Finished ignition-kargs.service - Ignition (kargs). Jul 21 12:36:44.842000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-kargs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:44.850125 systemd[1]: Starting ignition-disks.service - Ignition (disks)... Jul 21 12:36:44.892098 systemd[1]: ignition-kargs.service: Deactivated successfully. Jul 21 12:36:44.892859 systemd[1]: Stopped ignition-kargs.service - Ignition (kargs). Jul 21 12:36:44.897000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-kargs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:44.905098 systemd[1]: ignition-fetch.service: Deactivated successfully. Jul 21 12:36:44.905660 systemd[1]: Stopped ignition-fetch.service - Ignition (fetch). Jul 21 12:36:44.910000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-fetch comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:44.917035 systemd[1]: ignition-fetch-offline.service: Deactivated successfully. Jul 21 12:36:44.917603 systemd[1]: Stopped ignition-fetch-offline.service - Ignition (fetch-offline). Jul 21 12:36:44.923000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-fetch-offline comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:44.929625 systemd[1]: Unmounting oem.mount - /oem... Jul 21 12:36:44.956891 kernel: BTRFS info (device nvme0n1p6): last unmount of filesystem c5d600df-e377-4112-9764-9143f7b9b469 Jul 21 12:36:44.959205 systemd[1]: oem.mount: Deactivated successfully. Jul 21 12:36:44.963555 systemd[1]: Unmounted oem.mount - /oem. Jul 21 12:36:45.012787 ignition[1283]: Ignition 2.24.0 Jul 21 12:36:45.012819 ignition[1283]: Stage: disks Jul 21 12:36:45.013190 ignition[1283]: no config dir at "/usr/lib/ignition/base.d" Jul 21 12:36:45.013212 ignition[1283]: no config dir at "/usr/lib/ignition/base.platform.d/aws" Jul 21 12:36:45.013358 ignition[1283]: PUT http://169.254.169.254/latest/api/token: attempt #1 Jul 21 12:36:45.018287 ignition[1283]: PUT result: OK Jul 21 12:36:45.029231 ignition[1283]: disks: disks passed Jul 21 12:36:45.034672 ignition[1283]: Ignition finished successfully Jul 21 12:36:45.041323 systemd[1]: Finished ignition-disks.service - Ignition (disks). Jul 21 12:36:45.043000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-disks comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:45.046759 systemd[1]: Reached target initrd-root-device.target - Initrd Root Device. Jul 21 12:36:45.052904 systemd[1]: Reached target local-fs-pre.target - Preparation for Local File Systems. Jul 21 12:36:45.055970 systemd[1]: Reached target local-fs.target - Local File Systems. Jul 21 12:36:45.063287 systemd[1]: Reached target sysinit.target - System Initialization. Jul 21 12:36:45.067872 systemd[1]: Reached target basic.target - Basic System. Jul 21 12:36:45.074900 systemd[1]: Starting systemd-fsck-root.service - File System Check on /dev/disk/by-label/ROOT... Jul 21 12:36:45.203161 systemd-fsck[1295]: ROOT: clean, 15/1631200 files, 112378/1617920 blocks Jul 21 12:36:45.209504 systemd[1]: Finished systemd-fsck-root.service - File System Check on /dev/disk/by-label/ROOT. Jul 21 12:36:45.210000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-fsck-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:45.220424 kernel: kauditd_printk_skb: 25 callbacks suppressed Jul 21 12:36:45.220463 kernel: audit: type=1130 audit(1784637405.210:37): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-fsck-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:45.223591 systemd[1]: Mounting sysroot.mount - /sysroot... Jul 21 12:36:45.444874 kernel: EXT4-fs (nvme0n1p9): mounted filesystem ffc116b5-0c8c-464a-921c-36a2b93bcaff r/w with ordered data mode. Quota mode: none. Jul 21 12:36:45.446828 systemd[1]: Mounted sysroot.mount - /sysroot. Jul 21 12:36:45.448491 systemd[1]: Reached target initrd-root-fs.target - Initrd Root File System. Jul 21 12:36:45.482981 systemd[1]: Mounting sysroot-usr.mount - /sysroot/usr... Jul 21 12:36:45.485692 systemd[1]: flatcar-metadata-hostname.service - Flatcar Metadata Hostname Agent skipped, no trigger condition checks were met. Jul 21 12:36:45.485771 systemd[1]: ignition-remount-sysroot.service - Remount /sysroot read-write for Ignition skipped, unmet condition check ConditionPathIsReadWrite=!/sysroot Jul 21 12:36:45.485876 systemd[1]: Reached target ignition-diskful.target - Ignition Boot Disk Setup. Jul 21 12:36:45.521665 systemd[1]: Mounted sysroot-usr.mount - /sysroot/usr. Jul 21 12:36:45.528579 systemd[1]: Starting initrd-setup-root.service - Root filesystem setup... Jul 21 12:36:45.957108 systemd-tmpfiles[1337]: /sysroot/usr/lib/tmpfiles.d/base_image_var.conf:1: Duplicate line for path "/sysroot/var", ignoring. Jul 21 12:36:45.957198 systemd-tmpfiles[1337]: /sysroot/usr/lib/tmpfiles.d/base_image_var.conf:7: Duplicate line for path "/sysroot/var/empty", ignoring. Jul 21 12:36:45.957427 systemd-tmpfiles[1337]: /sysroot/usr/lib/tmpfiles.d/base_image_var.conf:28: Duplicate line for path "/sysroot/var/log", ignoring. Jul 21 12:36:47.060877 kernel: loop1: detected capacity change from 0 to 44256 Jul 21 12:36:47.108575 kernel: loop1: p1 p2 p3 Jul 21 12:36:47.491853 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:47.491924 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:36:47.491953 kernel: device-mapper: table: 254:1: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:36:47.494877 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:36:47.494879 systemd-confext[1391]: device-mapper: reload ioctl on loop1p1-12-verity (254:1) failed: Invalid argument Jul 21 12:36:47.511886 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:47.571897 kernel: erofs: (device dm-1): mounted with root inode @ nid 40. Jul 21 12:36:47.598886 kernel: loop2: detected capacity change from 0 to 44256 Jul 21 12:36:47.600877 kernel: loop2: p1 p2 p3 Jul 21 12:36:47.612915 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:47.612987 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:36:47.615527 kernel: device-mapper: table: 254:1: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:36:47.618867 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:36:47.618259 (sd-merge)[1402]: device-mapper: reload ioctl on loop2p1-16-verity (254:1) failed: Invalid argument Jul 21 12:36:47.631942 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:47.669797 (sd-merge)[1402]: Using extensions '00-flatcar-default.raw'. Jul 21 12:36:47.671973 kernel: erofs: (device dm-1): mounted with root inode @ nid 40. Jul 21 12:36:47.673980 (sd-merge)[1402]: Merged extensions into '/sysroot/etc'. Jul 21 12:36:47.686433 initrd-setup-root[1409]: /etc 00-flatcar-default Tue 2026-07-21 12:36:40 UTC Jul 21 12:36:47.694954 systemd[1]: Finished initrd-setup-root.service - Root filesystem setup. Jul 21 12:36:47.693000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:47.708893 kernel: audit: type=1130 audit(1784637407.693:38): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:47.709591 systemd[1]: Starting ignition-mount.service - Ignition (mount)... Jul 21 12:36:47.793996 ignition[1416]: INFO : Ignition 2.24.0 Jul 21 12:36:47.793996 ignition[1416]: INFO : Stage: mount Jul 21 12:36:47.798369 ignition[1416]: INFO : no config dir at "/usr/lib/ignition/base.d" Jul 21 12:36:47.798369 ignition[1416]: INFO : no config dir at "/usr/lib/ignition/base.platform.d/aws" Jul 21 12:36:47.798369 ignition[1416]: INFO : PUT http://169.254.169.254/latest/api/token: attempt #1 Jul 21 12:36:47.798369 ignition[1416]: INFO : PUT result: OK Jul 21 12:36:47.814895 ignition[1416]: INFO : mount: mount passed Jul 21 12:36:47.814895 ignition[1416]: INFO : Ignition finished successfully Jul 21 12:36:47.824021 systemd[1]: Finished ignition-mount.service - Ignition (mount). Jul 21 12:36:47.825000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:47.836725 kernel: audit: type=1130 audit(1784637407.825:39): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:47.831861 systemd[1]: Starting ignition-files.service - Ignition (files)... Jul 21 12:36:47.871016 systemd[1]: Mounting oem.mount - /oem... Jul 21 12:36:47.900890 kernel: BTRFS: device label OEM devid 1 transid 11 /dev/nvme0n1p6 (259:5) scanned by mount (1427) Jul 21 12:36:47.905918 kernel: BTRFS info (device nvme0n1p6): first mount of filesystem c5d600df-e377-4112-9764-9143f7b9b469 Jul 21 12:36:47.906157 kernel: BTRFS info (device nvme0n1p6): using crc32c (crc32c-generic) checksum algorithm Jul 21 12:36:47.917019 kernel: BTRFS info (device nvme0n1p6): enabling ssd optimizations Jul 21 12:36:47.917099 kernel: BTRFS info (device nvme0n1p6): enabling free space tree Jul 21 12:36:47.922205 systemd[1]: Mounted oem.mount - /oem. Jul 21 12:36:47.931562 systemd[1]: Mounting sysroot-oem.mount - /sysroot/oem... Jul 21 12:36:47.959753 systemd[1]: Mounted sysroot-oem.mount - /sysroot/oem. Jul 21 12:36:48.006497 ignition[1447]: INFO : Ignition 2.24.0 Jul 21 12:36:48.006497 ignition[1447]: INFO : Stage: files Jul 21 12:36:48.011184 ignition[1447]: INFO : no config dir at "/usr/lib/ignition/base.d" Jul 21 12:36:48.011184 ignition[1447]: INFO : no config dir at "/usr/lib/ignition/base.platform.d/aws" Jul 21 12:36:48.011184 ignition[1447]: INFO : PUT http://169.254.169.254/latest/api/token: attempt #1 Jul 21 12:36:48.019993 ignition[1447]: INFO : PUT result: OK Jul 21 12:36:48.027870 ignition[1447]: DEBUG : files: compiled without relabeling support, skipping Jul 21 12:36:48.061194 ignition[1447]: INFO : files: ensureUsers: op(1): [started] creating or modifying user "core" Jul 21 12:36:48.061194 ignition[1447]: DEBUG : files: ensureUsers: op(1): executing: "usermod" "--root" "/sysroot" "core" Jul 21 12:36:48.072693 ignition[1447]: INFO : files: ensureUsers: op(1): [finished] creating or modifying user "core" Jul 21 12:36:48.077618 ignition[1447]: INFO : files: ensureUsers: op(2): [started] adding ssh keys to user "core" Jul 21 12:36:48.081992 unknown[1447]: wrote ssh authorized keys file for user: core Jul 21 12:36:48.085768 ignition[1447]: INFO : files: ensureUsers: op(2): [finished] adding ssh keys to user "core" Jul 21 12:36:48.089901 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(3): [started] writing file "/sysroot/opt/helm-v3.17.3-linux-arm64.tar.gz" Jul 21 12:36:48.094323 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(3): GET https://get.helm.sh/helm-v3.17.3-linux-arm64.tar.gz: attempt #1 Jul 21 12:36:48.183770 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(3): GET result: OK Jul 21 12:36:48.459855 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(3): [finished] writing file "/sysroot/opt/helm-v3.17.3-linux-arm64.tar.gz" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(4): [started] writing file "/sysroot/home/core/install.sh" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(4): [finished] writing file "/sysroot/home/core/install.sh" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(5): [started] writing file "/sysroot/home/core/nginx.yaml" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(5): [finished] writing file "/sysroot/home/core/nginx.yaml" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(6): [started] writing file "/sysroot/home/core/nfs-pod.yaml" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(6): [finished] writing file "/sysroot/home/core/nfs-pod.yaml" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(7): [started] writing file "/sysroot/home/core/nfs-pvc.yaml" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(7): [finished] writing file "/sysroot/home/core/nfs-pvc.yaml" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(8): [started] writing file "/sysroot/etc/flatcar/update.conf" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(8): [finished] writing file "/sysroot/etc/flatcar/update.conf" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(9): [started] writing link "/sysroot/etc/extensions/kubernetes.raw" -> "/opt/extensions/kubernetes/kubernetes-v1.34.4-arm64.raw" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(9): [finished] writing link "/sysroot/etc/extensions/kubernetes.raw" -> "/opt/extensions/kubernetes/kubernetes-v1.34.4-arm64.raw" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(a): [started] writing file "/sysroot/opt/extensions/kubernetes/kubernetes-v1.34.4-arm64.raw" Jul 21 12:36:48.465588 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(a): GET https://extensions.flatcar.org/extensions/kubernetes-v1.34.4-arm64.raw: attempt #1 Jul 21 12:36:48.926294 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(a): GET result: OK Jul 21 12:36:49.361982 ignition[1447]: INFO : files: createFilesystemsFiles: createFiles: op(a): [finished] writing file "/sysroot/opt/extensions/kubernetes/kubernetes-v1.34.4-arm64.raw" Jul 21 12:36:49.367576 ignition[1447]: INFO : files: op(b): [started] processing unit "prepare-helm.service" Jul 21 12:36:49.398887 ignition[1447]: INFO : files: op(b): op(c): [started] writing unit "prepare-helm.service" at "/sysroot/etc/systemd/system/prepare-helm.service" Jul 21 12:36:49.403711 ignition[1447]: INFO : files: op(b): op(c): [finished] writing unit "prepare-helm.service" at "/sysroot/etc/systemd/system/prepare-helm.service" Jul 21 12:36:49.403711 ignition[1447]: INFO : files: op(b): [finished] processing unit "prepare-helm.service" Jul 21 12:36:49.403711 ignition[1447]: INFO : files: op(d): [started] setting preset to enabled for "prepare-helm.service" Jul 21 12:36:49.403711 ignition[1447]: INFO : files: op(d): [finished] setting preset to enabled for "prepare-helm.service" Jul 21 12:36:49.403711 ignition[1447]: INFO : files: createResultFile: createFiles: op(e): [started] writing file "/sysroot/etc/.ignition-result.json" Jul 21 12:36:49.403711 ignition[1447]: INFO : files: createResultFile: createFiles: op(e): [finished] writing file "/sysroot/etc/.ignition-result.json" Jul 21 12:36:49.403711 ignition[1447]: INFO : files: files passed Jul 21 12:36:49.403711 ignition[1447]: INFO : Ignition finished successfully Jul 21 12:36:49.423467 systemd[1]: Finished ignition-files.service - Ignition (files). Jul 21 12:36:49.430000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-files comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:49.440689 systemd[1]: Starting ignition-quench.service - Ignition (record completion)... Jul 21 12:36:49.447680 kernel: audit: type=1130 audit(1784637409.430:40): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-files comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:49.455072 systemd[1]: Starting initrd-setup-root-after-ignition.service - Root filesystem completion... Jul 21 12:36:49.478792 systemd[1]: ignition-quench.service: Deactivated successfully. Jul 21 12:36:49.484981 systemd[1]: Finished ignition-quench.service - Ignition (record completion). Jul 21 12:36:49.489000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-quench comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:49.489000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-quench comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:49.502881 kernel: audit: type=1130 audit(1784637409.489:41): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-quench comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:49.502973 kernel: audit: type=1131 audit(1784637409.489:42): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-quench comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:49.554193 initrd-setup-root-after-ignition[1487]: grep: /sysroot/etc/flatcar/enabled-sysext.conf: No such file or directory Jul 21 12:36:49.558466 initrd-setup-root-after-ignition[1487]: grep: /sysroot/usr/share/flatcar/enabled-sysext.conf: No such file or directory Jul 21 12:36:49.562714 initrd-setup-root-after-ignition[1490]: grep: /sysroot/etc/flatcar/enabled-sysext.conf: No such file or directory Jul 21 12:36:49.576887 kernel: loop3: detected capacity change from 0 to 44256 Jul 21 12:36:49.581887 kernel: loop3: p1 p2 p3 Jul 21 12:36:49.599537 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:49.599608 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:36:49.599637 kernel: device-mapper: table: 254:2: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:36:49.600940 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:36:49.602507 systemd-confext[1493]: device-mapper: reload ioctl on loop3p1-19-verity (254:2) failed: Invalid argument Jul 21 12:36:49.621961 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:49.668891 kernel: erofs: (device dm-2): mounted with root inode @ nid 40. Jul 21 12:36:49.700909 kernel: loop4: detected capacity change from 0 to 44256 Jul 21 12:36:49.703908 kernel: loop4: p1 p2 p3 Jul 21 12:36:49.715964 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:49.716071 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:36:49.717905 kernel: device-mapper: table: 254:2: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:36:49.719306 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:36:49.719458 (sd-merge)[1502]: device-mapper: reload ioctl on loop4p1-23-verity (254:2) failed: Invalid argument Jul 21 12:36:49.729898 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:49.768877 kernel: erofs: (device dm-2): mounted with root inode @ nid 40. Jul 21 12:36:49.768996 (sd-merge)[1502]: Skipping extension refresh because no change was found, use --always-refresh=yes to always do a refresh. Jul 21 12:36:49.797894 kernel: loop4: detected capacity change from 0 to 200864 Jul 21 12:36:49.865896 kernel: loop5: detected capacity change from 0 to 379472 Jul 21 12:36:49.901145 kernel: loop5: p1 p2 p3 Jul 21 12:36:50.252233 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:50.252299 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:36:50.254115 kernel: device-mapper: table: 254:2: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:36:50.255284 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:36:50.255380 systemd-sysext[1510]: device-mapper: reload ioctl on loop5p1-29-verity (254:2) failed: Invalid argument Jul 21 12:36:50.268889 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:50.405884 kernel: erofs: (device dm-2): mounted with root inode @ nid 39. Jul 21 12:36:50.505879 kernel: loop6: detected capacity change from 0 to 172472 Jul 21 12:36:50.552888 kernel: loop6: p1 p2 p3 Jul 21 12:36:50.874857 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:50.874921 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:36:50.876860 kernel: device-mapper: table: 254:2: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:36:50.878292 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:36:50.878383 systemd-sysext[1510]: device-mapper: reload ioctl on loop6p1-33-verity (254:2) failed: Invalid argument Jul 21 12:36:50.888881 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:51.011878 kernel: erofs: (device dm-2): mounted with root inode @ nid 39. Jul 21 12:36:51.086122 kernel: loop7: detected capacity change from 0 to 281976 Jul 21 12:36:51.119901 kernel: loop7: p1 p2 p3 Jul 21 12:36:51.438820 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:51.438925 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:36:51.438956 kernel: device-mapper: table: 254:2: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:36:51.440506 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:36:51.441781 systemd-sysext[1510]: device-mapper: reload ioctl on loop7p1-37-verity (254:2) failed: Invalid argument Jul 21 12:36:51.447944 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:51.567889 kernel: erofs: (device dm-2): mounted with root inode @ nid 39. Jul 21 12:36:51.596898 kernel: loop1: detected capacity change from 0 to 200864 Jul 21 12:36:51.621897 kernel: loop3: detected capacity change from 0 to 379472 Jul 21 12:36:51.625879 kernel: loop3: p1 p2 p3 Jul 21 12:36:51.651546 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:51.651616 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:36:51.654875 kernel: device-mapper: table: 254:2: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:36:51.656086 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:36:51.656922 (sd-merge)[1535]: device-mapper: reload ioctl on loop3p1-44-verity (254:2) failed: Invalid argument Jul 21 12:36:51.664876 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:51.765893 kernel: erofs: (device dm-2): mounted with root inode @ nid 39. Jul 21 12:36:51.773899 kernel: loop4: p1 p2 p3 Jul 21 12:36:51.793760 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:51.793854 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:36:51.793889 kernel: device-mapper: table: 254:3: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:36:51.797077 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:36:51.797109 (sd-merge)[1535]: device-mapper: reload ioctl on loop4p1-48-verity (254:3) failed: Invalid argument Jul 21 12:36:51.803859 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:51.902876 kernel: erofs: (device dm-3): mounted with root inode @ nid 39. Jul 21 12:36:51.909878 kernel: loop5: p1 p2 p3 Jul 21 12:36:51.929370 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:51.929450 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:36:51.931571 kernel: device-mapper: table: 254:4: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:36:51.933105 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:36:51.933227 (sd-merge)[1535]: device-mapper: reload ioctl on loop5p1-52-verity (254:4) failed: Invalid argument Jul 21 12:36:51.941157 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:36:52.039916 kernel: erofs: (device dm-4): mounted with root inode @ nid 39. Jul 21 12:36:52.040824 (sd-merge)[1535]: Using extensions 'containerd-flatcar.raw', 'docker-flatcar.raw', 'kubernetes-v1.34.4-arm64.raw', 'oem-ami-9999.0.102+package-updates-2026-07-06.raw'. Jul 21 12:36:52.047686 (sd-merge)[1535]: Merged extensions into '/sysroot/usr'. Jul 21 12:36:52.062930 systemd[1]: Finished initrd-setup-root-after-ignition.service - Root filesystem completion. Jul 21 12:36:52.064000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root-after-ignition comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.074357 kernel: audit: type=1130 audit(1784637412.064:43): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root-after-ignition comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.076647 systemd[1]: Starting initrd-parse-etc.service - Mountpoints Configured in the Real Root... Jul 21 12:36:52.117714 systemd[1]: initrd-parse-etc.service: Deactivated successfully. Jul 21 12:36:52.122050 systemd[1]: Finished initrd-parse-etc.service - Mountpoints Configured in the Real Root. Jul 21 12:36:52.123000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-parse-etc comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.125438 systemd[1]: initrd-parse-etc.service: Triggering OnSuccess= dependencies. Jul 21 12:36:52.123000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-parse-etc comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.136030 systemd[1]: Reached target initrd-fs.target - Initrd File Systems. Jul 21 12:36:52.142760 kernel: audit: type=1130 audit(1784637412.123:44): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-parse-etc comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.142799 kernel: audit: type=1131 audit(1784637412.123:45): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-parse-etc comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.145536 systemd[1]: Starting dracut-mount.service - dracut mount hook... Jul 21 12:36:52.513761 systemd[1]: Finished dracut-mount.service - dracut mount hook. Jul 21 12:36:52.514000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.524912 kernel: audit: type=1130 audit(1784637412.514:46): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.524968 systemd[1]: Starting dracut-pre-pivot.service - dracut pre-pivot and cleanup hook... Jul 21 12:36:52.581327 systemd[1]: Finished dracut-pre-pivot.service - dracut pre-pivot and cleanup hook. Jul 21 12:36:52.579000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-pivot comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.590152 systemd[1]: Starting initrd-cleanup.service - Cleaning Up and Shutting Down Daemons... Jul 21 12:36:52.599301 kernel: audit: type=1130 audit(1784637412.579:47): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-pivot comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.633778 systemd[1]: Stopped target basic.target - Basic System. Jul 21 12:36:52.635036 systemd[1]: Stopped target ignition-diskful.target - Ignition Boot Disk Setup. Jul 21 12:36:52.642904 systemd[1]: Stopped target initrd-root-device.target - Initrd Root Device. Jul 21 12:36:52.648772 systemd[1]: Stopped target initrd-usr-fs.target - Initrd /usr File System. Jul 21 12:36:52.654260 systemd[1]: Stopped target nss-lookup.target - Host and Network Name Lookups. Jul 21 12:36:52.659616 systemd[1]: Stopped target paths.target - Path Units. Jul 21 12:36:52.665360 systemd[1]: Stopped target remote-cryptsetup.target - Remote Encrypted Volumes. Jul 21 12:36:52.673794 systemd[1]: Stopped target slices.target - Slice Units. Jul 21 12:36:52.701000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-pivot comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.706000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.712000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.722000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-initqueue comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.735000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root-after-ignition comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.746000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-files comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.772307 kernel: audit: type=1131 audit(1784637412.701:48): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-pivot comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.674274 systemd[1]: Stopped target sockets.target - Socket Units. Jul 21 12:36:52.783000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-modules-load comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.788666 kernel: audit: type=1131 audit(1784637412.706:49): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.675195 systemd[1]: Stopped target sysinit.target - System Initialization. Jul 21 12:36:52.791810 kernel: audit: type=1131 audit(1784637412.712:50): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.676016 systemd[1]: Stopped target local-fs.target - Local File Systems. Jul 21 12:36:52.797480 kernel: audit: type=1131 audit(1784637412.722:51): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-initqueue comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.676785 systemd[1]: Stopped target local-fs-pre.target - Preparation for Local File Systems. Jul 21 12:36:52.800723 kernel: audit: type=1131 audit(1784637412.735:52): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root-after-ignition comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.677650 systemd[1]: Stopped target swap.target - Swaps. Jul 21 12:36:52.678531 systemd[1]: Stopped target timers.target - Timer Units. Jul 21 12:36:52.679373 systemd[1]: iscsid.socket: Deactivated successfully. Jul 21 12:36:52.679666 systemd[1]: Closed iscsid.socket - Open-iSCSI iscsid Socket. Jul 21 12:36:52.685554 systemd[1]: iscsiuio.socket: Deactivated successfully. Jul 21 12:36:52.685819 systemd[1]: Closed iscsiuio.socket - Open-iSCSI iscsiuio Socket. Jul 21 12:36:52.692561 systemd[1]: systemd-coredump.socket: Deactivated successfully. Jul 21 12:36:52.692795 systemd[1]: Closed systemd-coredump.socket - Process Core Dump Socket. Jul 21 12:36:52.697601 systemd[1]: systemd-journald-audit.socket: Deactivated successfully. Jul 21 12:36:52.697933 systemd[1]: Closed systemd-journald-audit.socket - Journal Audit Socket. Jul 21 12:36:52.701972 systemd[1]: dracut-pre-pivot.service: Deactivated successfully. Jul 21 12:36:52.702231 systemd[1]: Stopped dracut-pre-pivot.service - dracut pre-pivot and cleanup hook. Jul 21 12:36:52.706698 systemd[1]: Stopped target remote-fs.target - Remote File Systems. Jul 21 12:36:52.707694 systemd[1]: Stopped target remote-fs-pre.target - Preparation for Remote File Systems. Jul 21 12:36:52.708075 systemd[1]: dracut-mount.service: Deactivated successfully. Jul 21 12:36:52.708280 systemd[1]: Stopped dracut-mount.service - dracut mount hook. Jul 21 12:36:52.712620 systemd[1]: dracut-pre-mount.service: Deactivated successfully. Jul 21 12:36:52.898000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.902174 ignition[1608]: INFO : Ignition 2.24.0 Jul 21 12:36:52.902174 ignition[1608]: INFO : Stage: umount Jul 21 12:36:52.902174 ignition[1608]: INFO : no config dir at "/usr/lib/ignition/base.d" Jul 21 12:36:52.902174 ignition[1608]: INFO : no config dir at "/usr/lib/ignition/base.platform.d/aws" Jul 21 12:36:52.902174 ignition[1608]: INFO : PUT http://169.254.169.254/latest/api/token: attempt #1 Jul 21 12:36:52.902174 ignition[1608]: INFO : PUT result: OK Jul 21 12:36:52.902174 ignition[1608]: INFO : umount: umount passed Jul 21 12:36:52.902174 ignition[1608]: INFO : Ignition finished successfully Jul 21 12:36:52.713007 systemd[1]: Stopped dracut-pre-mount.service - dracut pre-mount hook. Jul 21 12:36:52.717886 systemd[1]: Stopped target cryptsetup.target - Local Encrypted Volumes. Jul 21 12:36:52.718311 systemd[1]: systemd-ask-password-console.path: Deactivated successfully. Jul 21 12:36:52.718979 systemd[1]: Stopped systemd-ask-password-console.path - Dispatch Password Requests to Console Directory Watch. Jul 21 12:36:52.720920 systemd[1]: Stopped target cryptsetup-pre.target - Local Encrypted Volumes (Pre). Jul 21 12:36:52.721605 systemd[1]: clevis-luks-askpass.path: Deactivated successfully. Jul 21 12:36:52.931000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-udev-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.722265 systemd[1]: Stopped clevis-luks-askpass.path - Forward Password Requests to Clevis Directory Watch. Jul 21 12:36:52.723451 systemd[1]: dracut-initqueue.service: Deactivated successfully. Jul 21 12:36:52.723881 systemd[1]: Stopped dracut-initqueue.service - dracut initqueue hook. Jul 21 12:36:52.735659 systemd[1]: initrd-setup-root-after-ignition.service: Deactivated successfully. Jul 21 12:36:52.736084 systemd[1]: Stopped initrd-setup-root-after-ignition.service - Root filesystem completion. Jul 21 12:36:52.747513 systemd[1]: ignition-files.service: Deactivated successfully. Jul 21 12:36:52.747962 systemd[1]: Stopped ignition-files.service - Ignition (files). Jul 21 12:36:52.770583 systemd[1]: Stopping ignition-mount.service - Ignition (mount)... Jul 21 12:36:52.780186 systemd[1]: systemd-modules-load.service: Deactivated successfully. Jul 21 12:36:52.780511 systemd[1]: Stopped systemd-modules-load.service - Load Kernel Modules. Jul 21 12:36:52.975000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:52.858937 systemd[1]: systemd-tmpfiles-setup.service: Deactivated successfully. Jul 21 12:36:52.859240 systemd[1]: Stopped systemd-tmpfiles-setup.service - Create System Files and Directories. Jul 21 12:36:52.930082 systemd[1]: systemd-udev-trigger.service: Deactivated successfully. Jul 21 12:36:52.930815 systemd[1]: Stopped systemd-udev-trigger.service - Coldplug All udev Devices. Jul 21 12:36:52.969022 systemd[1]: dracut-pre-trigger.service: Deactivated successfully. Jul 21 12:36:52.969373 systemd[1]: Stopped dracut-pre-trigger.service - dracut pre-trigger hook. Jul 21 12:36:53.008016 systemd[1]: ignition-mount.service: Deactivated successfully. Jul 21 12:36:53.013202 systemd[1]: Stopped ignition-mount.service - Ignition (mount). Jul 21 12:36:53.015000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.032194 systemd[1]: initrd-cleanup.service: Deactivated successfully. Jul 21 12:36:53.037939 systemd[1]: Finished initrd-cleanup.service - Cleaning Up and Shutting Down Daemons. Jul 21 12:36:53.043000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-cleanup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.043000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-cleanup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.073913 systemd[1]: Stopped target network.target - Network. Jul 21 12:36:53.078759 systemd[1]: ignition-disks.service: Deactivated successfully. Jul 21 12:36:53.079000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-disks comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.078917 systemd[1]: Stopped ignition-disks.service - Ignition (disks). Jul 21 12:36:53.090281 systemd[1]: ignition-setup-pre.service: Deactivated successfully. Jul 21 12:36:53.091000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-setup-pre comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.090402 systemd[1]: Stopped ignition-setup-pre.service - Ignition env setup. Jul 21 12:36:53.102091 systemd[1]: initrd-setup-root.service: Deactivated successfully. Jul 21 12:36:53.103000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.102195 systemd[1]: Stopped initrd-setup-root.service - Root filesystem setup. Jul 21 12:36:53.114407 systemd[1]: Stopping systemd-networkd.service - Network Management... Jul 21 12:36:53.117210 systemd[1]: Stopping systemd-resolved.service - Network Name Resolution... Jul 21 12:36:53.129960 systemd[1]: systemd-networkd.service: Deactivated successfully. Jul 21 12:36:53.136817 systemd[1]: Stopped systemd-networkd.service - Network Management. Jul 21 12:36:53.141000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.151443 systemd[1]: systemd-resolved.service: Deactivated successfully. Jul 21 12:36:53.156430 systemd[1]: Stopped systemd-resolved.service - Network Name Resolution. Jul 21 12:36:53.158000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-resolved comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.168000 audit: BPF prog-id=8 op=UNLOAD Jul 21 12:36:53.169000 audit: BPF prog-id=5 op=UNLOAD Jul 21 12:36:53.171780 systemd[1]: Stopped target network-pre.target - Preparation for Network. Jul 21 12:36:53.178047 systemd[1]: systemd-networkd-resolve-hook.socket: Deactivated successfully. Jul 21 12:36:53.178210 systemd[1]: Closed systemd-networkd-resolve-hook.socket - Network Management Resolve Hook Socket. Jul 21 12:36:53.192582 systemd[1]: systemd-networkd.socket: Deactivated successfully. Jul 21 12:36:53.192722 systemd[1]: Closed systemd-networkd.socket - Network Management Netlink Socket. Jul 21 12:36:53.206549 systemd[1]: Stopping network-cleanup.service - Network Cleanup... Jul 21 12:36:53.208928 systemd[1]: parse-ip-for-networkd.service: Deactivated successfully. Jul 21 12:36:53.214000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=parse-ip-for-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.209032 systemd[1]: Stopped parse-ip-for-networkd.service - Write systemd-networkd units from cmdline. Jul 21 12:36:53.229052 systemd[1]: Stopping systemd-udevd.service - Rule-based Manager for Device Events and Files... Jul 21 12:36:53.266188 systemd[1]: systemd-udevd.service: Deactivated successfully. Jul 21 12:36:53.272954 systemd[1]: Stopped systemd-udevd.service - Rule-based Manager for Device Events and Files. Jul 21 12:36:53.279573 systemd[1]: systemd-udevd.service: Consumed 2.786s CPU time over 12.083s wall clock time. Jul 21 12:36:53.277000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-udevd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.288717 systemd[1]: network-cleanup.service: Deactivated successfully. Jul 21 12:36:53.292460 systemd[1]: Stopped network-cleanup.service - Network Cleanup. Jul 21 12:36:53.296000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=network-cleanup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.303739 systemd[1]: systemd-udevd-control.socket: Deactivated successfully. Jul 21 12:36:53.303995 systemd[1]: Closed systemd-udevd-control.socket - udev Control Socket. Jul 21 12:36:53.316538 systemd[1]: dracut-pre-udev.service: Deactivated successfully. Jul 21 12:36:53.317000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-udev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.316675 systemd[1]: Stopped dracut-pre-udev.service - dracut pre-udev hook. Jul 21 12:36:53.329028 systemd[1]: dracut-cmdline.service: Deactivated successfully. Jul 21 12:36:53.330000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-cmdline comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.329150 systemd[1]: Stopped dracut-cmdline.service - dracut cmdline hook. Jul 21 12:36:53.338798 systemd[1]: dracut-cmdline-ask.service: Deactivated successfully. Jul 21 12:36:53.341000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-cmdline-ask comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.338963 systemd[1]: Stopped dracut-cmdline-ask.service - dracut ask for additional cmdline parameters. Jul 21 12:36:53.358810 systemd[1]: Starting initrd-udevadm-cleanup-db.service - Cleanup udev Database... Jul 21 12:36:53.368187 systemd[1]: systemd-network-generator.service: Deactivated successfully. Jul 21 12:36:53.368330 systemd[1]: Stopped systemd-network-generator.service - Generate Network Units from Kernel Command Line. Jul 21 12:36:53.366000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-network-generator comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.381324 systemd[1]: systemd-tmpfiles-setup-dev.service: Deactivated successfully. Jul 21 12:36:53.381474 systemd[1]: Stopped systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev. Jul 21 12:36:53.387000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.398037 systemd[1]: systemd-tmpfiles-setup-dev-early.service: Deactivated successfully. Jul 21 12:36:53.398404 systemd[1]: Stopped systemd-tmpfiles-setup-dev-early.service - Create Static Device Nodes in /dev gracefully. Jul 21 12:36:53.408000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev-early comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.415898 systemd[1]: kmod-static-nodes.service: Deactivated successfully. Jul 21 12:36:53.418000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=kmod-static-nodes comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.416013 systemd[1]: Stopped kmod-static-nodes.service - Create List of Static Device Nodes. Jul 21 12:36:53.428877 systemd[1]: systemd-vconsole-setup.service: Deactivated successfully. Jul 21 12:36:53.430000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.429000 systemd[1]: Stopped systemd-vconsole-setup.service - Virtual Console Setup. Jul 21 12:36:53.447825 systemd[1]: initrd-udevadm-cleanup-db.service: Deactivated successfully. Jul 21 12:36:53.453970 systemd[1]: Finished initrd-udevadm-cleanup-db.service - Cleanup udev Database. Jul 21 12:36:53.455000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-udevadm-cleanup-db comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.455000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-udevadm-cleanup-db comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:53.465362 systemd[1]: Reached target initrd-switch-root.target - Switch Root. Jul 21 12:36:53.474016 systemd[1]: Starting initrd-switch-root.service - Switch Root... Jul 21 12:36:53.508640 systemd[1]: Switching root. Jul 21 12:36:53.951866 systemd-journald[416]: Received SIGTERM from PID 1 (systemd). Jul 21 12:36:53.951965 systemd-journald[416]: Journal stopped Jul 21 12:36:59.490386 kernel: SELinux: policy capability network_peer_controls=1 Jul 21 12:36:59.490536 kernel: SELinux: policy capability open_perms=1 Jul 21 12:36:59.490580 kernel: SELinux: policy capability extended_socket_class=1 Jul 21 12:36:59.490619 kernel: SELinux: policy capability always_check_network=0 Jul 21 12:36:59.490651 kernel: SELinux: policy capability cgroup_seclabel=1 Jul 21 12:36:59.490693 kernel: SELinux: policy capability nnp_nosuid_transition=1 Jul 21 12:36:59.490742 kernel: SELinux: policy capability genfs_seclabel_symlinks=0 Jul 21 12:36:59.490775 kernel: SELinux: policy capability ioctl_skip_cloexec=0 Jul 21 12:36:59.490816 kernel: SELinux: policy capability userspace_initial_context=0 Jul 21 12:36:59.496015 systemd[1]: Successfully loaded SELinux policy in 238.909ms. Jul 21 12:36:59.496090 systemd[1]: Relabeled /dev/, /dev/shm/, /run/ in 24.852ms. Jul 21 12:36:59.496129 systemd[1]: systemd 260.1 running in system mode (+PAM +AUDIT +SELINUX -APPARMOR +IMA +IPE +SMACK +SECCOMP -GCRYPT -GNUTLS +OPENSSL -ACL +BLKID +CURL +ELFUTILS -FIDO2 +IDN2 +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 -PWQUALITY -P11KIT -QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD -BPF_FRAMEWORK -BTF -XKBCOMMON +UTMP +LIBARCHIVE) Jul 21 12:36:59.496165 systemd[1]: Detected virtualization amazon. Jul 21 12:36:59.496196 systemd[1]: Detected architecture arm64. Jul 21 12:36:59.496230 systemd[1]: Detected first boot. Jul 21 12:36:59.496271 systemd[1]: Initializing machine ID from SMBIOS/DMI UUID. Jul 21 12:36:59.496303 zram_generator::config[1896]: No configuration found. Jul 21 12:36:59.496341 kernel: NET: Registered PF_VSOCK protocol family Jul 21 12:36:59.496372 systemd[1]: Applying preset policy. Jul 21 12:36:59.496407 systemd[1]: Created symlink '/etc/systemd/system/multi-user.target.wants/prepare-helm.service' → '/etc/systemd/system/prepare-helm.service'. Jul 21 12:36:59.496441 systemd[1]: Populated /etc with preset unit settings. Jul 21 12:36:59.496471 kernel: kauditd_printk_skb: 32 callbacks suppressed Jul 21 12:36:59.496504 kernel: audit: type=1334 audit(1784637418.669:85): prog-id=10 op=LOAD Jul 21 12:36:59.496531 kernel: audit: type=1334 audit(1784637418.669:86): prog-id=2 op=UNLOAD Jul 21 12:36:59.496563 kernel: audit: type=1334 audit(1784637418.669:87): prog-id=11 op=LOAD Jul 21 12:36:59.496591 kernel: audit: type=1334 audit(1784637418.669:88): prog-id=12 op=LOAD Jul 21 12:36:59.496625 kernel: audit: type=1334 audit(1784637418.669:89): prog-id=3 op=UNLOAD Jul 21 12:36:59.496657 kernel: audit: type=1334 audit(1784637418.669:90): prog-id=4 op=UNLOAD Jul 21 12:36:59.496689 kernel: audit: type=1334 audit(1784637418.679:91): prog-id=13 op=LOAD Jul 21 12:36:59.496725 kernel: audit: type=1334 audit(1784637418.679:92): prog-id=10 op=UNLOAD Jul 21 12:36:59.496757 kernel: audit: type=1334 audit(1784637418.681:93): prog-id=14 op=LOAD Jul 21 12:36:59.496788 kernel: audit: type=1334 audit(1784637418.682:94): prog-id=15 op=LOAD Jul 21 12:36:59.496821 systemd[1]: initrd-switch-root.service: Deactivated successfully. Jul 21 12:36:59.496901 systemd[1]: Stopped initrd-switch-root.service - Switch Root. Jul 21 12:36:59.496940 systemd[1]: systemd-journald.service: Scheduled restart job, restart counter is at 1. Jul 21 12:36:59.496971 systemd[1]: Created slice system-addon\x2dconfig.slice - Slice /system/addon-config. Jul 21 12:36:59.497012 systemd[1]: Created slice system-addon\x2drun.slice - Slice /system/addon-run. Jul 21 12:36:59.497057 systemd[1]: Created slice system-getty.slice - Slice /system/getty. Jul 21 12:36:59.497089 systemd[1]: Created slice system-modprobe.slice - Slice /system/modprobe. Jul 21 12:36:59.497120 systemd[1]: Created slice system-serial\x2dgetty.slice - Slice /system/serial-getty. Jul 21 12:36:59.497156 systemd[1]: Created slice system-system\x2dcloudinit.slice - Slice /system/system-cloudinit. Jul 21 12:36:59.497188 systemd[1]: Created slice system-systemd\x2dfsck.slice - Slice /system/systemd-fsck. Jul 21 12:36:59.497251 systemd[1]: Created slice user.slice - User and Session Slice. Jul 21 12:36:59.497283 systemd[1]: Started clevis-luks-askpass.path - Forward Password Requests to Clevis Directory Watch. Jul 21 12:36:59.497317 systemd[1]: Started systemd-ask-password-console.path - Dispatch Password Requests to Console Directory Watch. Jul 21 12:36:59.497347 systemd[1]: Started systemd-ask-password-wall.path - Forward Password Requests to Wall Directory Watch. Jul 21 12:36:59.497378 systemd[1]: Set up automount boot.automount - Boot partition Automount Point. Jul 21 12:36:59.497410 systemd[1]: Set up automount proc-sys-fs-binfmt_misc.automount - Arbitrary Executable File Formats File System Automount Point. Jul 21 12:36:59.497441 systemd[1]: Expecting device dev-disk-by\x2dlabel-OEM.device - /dev/disk/by-label/OEM... Jul 21 12:36:59.497490 systemd[1]: Expecting device dev-ttyS0.device - /dev/ttyS0... Jul 21 12:36:59.497522 systemd[1]: Reached target cryptsetup-pre.target - Local Encrypted Volumes (Pre). Jul 21 12:36:59.497555 systemd[1]: Reached target cryptsetup.target - Local Encrypted Volumes. Jul 21 12:36:59.497585 systemd[1]: Reached target imports.target - Image Downloads. Jul 21 12:36:59.497617 systemd[1]: Stopped target initrd-switch-root.target - Switch Root. Jul 21 12:36:59.497650 systemd[1]: Stopped target initrd-fs.target - Initrd File Systems. Jul 21 12:36:59.497680 systemd[1]: Stopped target initrd-root-fs.target - Initrd Root File System. Jul 21 12:36:59.497716 systemd[1]: Reached target integritysetup.target - Local Integrity Protected Volumes. Jul 21 12:36:59.497747 systemd[1]: Reached target remote-cryptsetup.target - Remote Encrypted Volumes. Jul 21 12:36:59.497783 systemd[1]: Reached target remote-fs.target - Remote File Systems. Jul 21 12:36:59.497822 systemd[1]: Reached target remote-integritysetup.target - Remote Integrity Protected Volumes. Jul 21 12:36:59.505364 systemd[1]: Reached target remote-veritysetup.target - Remote Verity Protected Volumes. Jul 21 12:36:59.505416 systemd[1]: Reached target slices.target - Slice Units. Jul 21 12:36:59.505456 systemd[1]: Reached target swap.target - Swaps. Jul 21 12:36:59.505500 systemd[1]: Reached target veritysetup.target - Local Verity Protected Volumes. Jul 21 12:36:59.505533 systemd[1]: Listening on systemd-ask-password.socket - Query the User Interactively for a Password. Jul 21 12:36:59.505569 systemd[1]: Listening on systemd-coredump.socket - Process Core Dump Socket. Jul 21 12:36:59.505604 systemd[1]: Listening on systemd-creds.socket - Credential Encryption/Decryption. Jul 21 12:36:59.505635 systemd[1]: Listening on systemd-factory-reset.socket - Factory Reset Management. Jul 21 12:36:59.505684 systemd[1]: Listening on systemd-journald-audit.socket - Journal Audit Socket. Jul 21 12:36:59.505728 systemd[1]: Listening on systemd-mountfsd.socket - DDI File System Mounter Socket. Jul 21 12:36:59.505771 systemd[1]: Listening on systemd-mute-console.socket - Console Output Muting Service Socket. Jul 21 12:36:59.505808 systemd[1]: Listening on systemd-networkd-resolve-hook.socket - Network Management Resolve Hook Socket. Jul 21 12:36:59.505899 systemd[1]: Listening on systemd-networkd-varlink-metrics.socket - Network Management Metrics Varlink Socket. Jul 21 12:36:59.505941 systemd[1]: Listening on systemd-networkd-varlink.socket - Network Management Varlink Socket. Jul 21 12:36:59.505978 systemd[1]: Listening on systemd-networkd.socket - Network Management Netlink Socket. Jul 21 12:36:59.506015 systemd[1]: Listening on systemd-nsresourced.socket - Namespace Resource Manager Socket. Jul 21 12:36:59.506045 systemd[1]: Listening on systemd-oomd.socket - Userspace Out-Of-Memory (OOM) Killer Socket. Jul 21 12:36:59.506079 systemd[1]: Listening on systemd-repart.socket - Disk Repartitioning Service Socket. Jul 21 12:36:59.506111 systemd[1]: Listening on systemd-resolved-monitor.socket - Resolve Monitor Varlink Socket. Jul 21 12:36:59.506141 systemd[1]: Listening on systemd-resolved-varlink.socket - Resolve Service Varlink Socket. Jul 21 12:36:59.506173 systemd[1]: Listening on systemd-udevd-control.socket - udev Control Socket. Jul 21 12:36:59.506209 systemd[1]: Listening on systemd-udevd-varlink.socket - udev Varlink Socket. Jul 21 12:36:59.506243 systemd[1]: Listening on systemd-userdbd.socket - User Database Manager Socket. Jul 21 12:36:59.506274 systemd[1]: Mounting dev-hugepages.mount - Huge Pages File System... Jul 21 12:36:59.506309 systemd[1]: Mounting dev-mqueue.mount - POSIX Message Queue File System... Jul 21 12:36:59.506339 systemd[1]: Mounting media.mount - External Media Directory... Jul 21 12:36:59.506370 systemd[1]: Mounting sys-kernel-debug.mount - Kernel Debug File System... Jul 21 12:36:59.506400 systemd[1]: Mounting sys-kernel-tracing.mount - Kernel Trace File System... Jul 21 12:36:59.506438 systemd[1]: tmp.mount: x-systemd.graceful-option=usrquota specified, but option is not available, suppressing. Jul 21 12:36:59.506470 systemd[1]: Mounting tmp.mount - Temporary Directory /tmp... Jul 21 12:36:59.506502 systemd[1]: Starting flatcar-tmpfiles.service - Create missing system files... Jul 21 12:36:59.506540 systemd[1]: ignition-delete-config.service - Ignition (delete config) skipped, no trigger condition checks were met. Jul 21 12:36:59.506572 systemd[1]: Starting kmod-static-nodes.service - Create List of Static Device Nodes... Jul 21 12:36:59.506609 systemd[1]: Starting modprobe@configfs.service - Load Kernel Module configfs... Jul 21 12:36:59.506641 systemd[1]: modprobe@drm.service - Load Kernel Module drm skipped, unmet condition check ConditionKernelModuleLoaded=!drm Jul 21 12:36:59.506675 systemd[1]: Starting modprobe@efi_pstore.service - Load Kernel Module efi_pstore... Jul 21 12:36:59.506711 systemd[1]: Starting modprobe@fuse.service - Load Kernel Module fuse... Jul 21 12:36:59.506744 systemd[1]: setup-nsswitch.service - Create /etc/nsswitch.conf skipped, unmet condition check ConditionPathExists=!/etc/nsswitch.conf Jul 21 12:36:59.506786 systemd[1]: systemd-fsck-root.service: Deactivated successfully. Jul 21 12:36:59.506816 systemd[1]: Stopped systemd-fsck-root.service - File System Check on Root Device. Jul 21 12:36:59.509922 systemd[1]: systemd-hibernate-clear.service - Clear Stale Hibernate Storage Info skipped, unmet condition check ConditionPathExists=/sys/firmware/efi/efivars/HibernateLocation-8cf2644b-4b0b-428f-9387-6d876050dc67 Jul 21 12:36:59.509995 systemd[1]: Starting systemd-journald.service - Journal Service... Jul 21 12:36:59.510031 systemd[1]: Starting systemd-modules-load.service - Load Kernel Modules... Jul 21 12:36:59.510065 systemd[1]: Starting systemd-network-generator.service - Generate Network Units from Kernel Command Line... Jul 21 12:36:59.510103 systemd[1]: Reached target time-set.target - System Time Set. Jul 21 12:36:59.510147 systemd[1]: Starting systemd-remount-fs.service - Remount Root and Kernel File Systems... Jul 21 12:36:59.510183 systemd[1]: Starting systemd-udev-load-credentials.service - Load udev Rules from Credentials... Jul 21 12:36:59.510220 systemd[1]: Starting systemd-udev-trigger.service - Coldplug All udev Devices... Jul 21 12:36:59.510257 systemd[1]: Mounted dev-hugepages.mount - Huge Pages File System. Jul 21 12:36:59.510289 systemd[1]: Mounted dev-mqueue.mount - POSIX Message Queue File System. Jul 21 12:36:59.510327 systemd[1]: Mounted media.mount - External Media Directory. Jul 21 12:36:59.510363 systemd[1]: Mounted sys-kernel-debug.mount - Kernel Debug File System. Jul 21 12:36:59.512209 systemd[1]: Mounted sys-kernel-tracing.mount - Kernel Trace File System. Jul 21 12:36:59.512248 systemd[1]: Mounted tmp.mount - Temporary Directory /tmp. Jul 21 12:36:59.512280 systemd[1]: Finished kmod-static-nodes.service - Create List of Static Device Nodes. Jul 21 12:36:59.512314 systemd[1]: modprobe@efi_pstore.service: Deactivated successfully. Jul 21 12:36:59.512357 systemd[1]: Finished modprobe@efi_pstore.service - Load Kernel Module efi_pstore. Jul 21 12:36:59.512393 systemd[1]: Finished systemd-network-generator.service - Generate Network Units from Kernel Command Line. Jul 21 12:36:59.512430 systemd[1]: Reached target network-pre.target - Preparation for Network. Jul 21 12:36:59.512465 systemd[1]: Starting systemd-tmpfiles-setup-dev-early.service - Create Static Device Nodes in /dev gracefully... Jul 21 12:36:59.512504 systemd[1]: Finished systemd-modules-load.service - Load Kernel Modules. Jul 21 12:36:59.512542 systemd[1]: modprobe@configfs.service: Deactivated successfully. Jul 21 12:36:59.512574 systemd[1]: Finished modprobe@configfs.service - Load Kernel Module configfs. Jul 21 12:36:59.512606 systemd[1]: Finished systemd-remount-fs.service - Remount Root and Kernel File Systems. Jul 21 12:36:59.512638 systemd[1]: Finished systemd-udev-load-credentials.service - Load udev Rules from Credentials. Jul 21 12:36:59.512677 kernel: fuse: init (API version 7.41) Jul 21 12:36:59.512710 systemd[1]: modprobe@fuse.service: Deactivated successfully. Jul 21 12:36:59.512752 systemd[1]: Finished modprobe@fuse.service - Load Kernel Module fuse. Jul 21 12:36:59.512785 systemd[1]: remount-root.service - Remount Root File System skipped, unmet condition check ConditionPathIsReadWrite=!/ Jul 21 12:36:59.512819 systemd[1]: Starting systemd-hwdb-update.service - Rebuild Hardware Database... Jul 21 12:36:59.512972 systemd-journald[1969]: Collecting audit messages is enabled. Jul 21 12:36:59.513043 systemd[1]: systemd-pstore.service - Platform Persistent Storage Archival skipped, unmet condition check ConditionDirectoryNotEmpty=/sys/fs/pstore Jul 21 12:36:59.513089 systemd[1]: Starting systemd-random-seed.service - Load/Save OS Random Seed... Jul 21 12:36:59.513122 systemd[1]: Starting systemd-sysctl.service - Apply Kernel Variables... Jul 21 12:36:59.513160 systemd-journald[1969]: Journal started Jul 21 12:36:59.513227 systemd-journald[1969]: Runtime Journal (/run/log/journal/ec2c0ef6f39eee0a06e5e3b661241913) is 8M, max 75.3M, 67.3M free. Jul 21 12:36:58.896000 audit[1]: EVENT_LISTENER pid=1 uid=0 auid=4294967295 tty=(none) ses=4294967295 subj=system_u:system_r:kernel_t:s0 comm="systemd" exe="/usr/lib/systemd/systemd" nl-mcgrp=1 op=connect res=1 Jul 21 12:36:59.160000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-fsck-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.168000 audit: BPF prog-id=15 op=UNLOAD Jul 21 12:36:59.168000 audit: BPF prog-id=14 op=UNLOAD Jul 21 12:36:59.170000 audit: BPF prog-id=16 op=LOAD Jul 21 12:36:59.170000 audit: BPF prog-id=17 op=LOAD Jul 21 12:36:59.171000 audit: BPF prog-id=18 op=LOAD Jul 21 12:36:59.311000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kmod-static-nodes comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.328000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@efi_pstore comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.328000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@efi_pstore comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.339000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-network-generator comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.379000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-modules-load comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.402000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@configfs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.402000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@configfs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.416000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-remount-fs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.426000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-udev-load-credentials comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.438000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@fuse comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.438000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@fuse comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.470000 audit: CONFIG_CHANGE op=set audit_enabled=1 old=1 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 res=1 Jul 21 12:36:59.470000 audit[1969]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=60 a0=4 a1=ffffffa658b0 a2=4000 a3=0 items=0 ppid=1 pid=1969 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-journal" exe="/usr/lib/systemd/systemd-journald" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:36:59.470000 audit: PROCTITLE proctitle="/usr/lib/systemd/systemd-journald" Jul 21 12:36:59.519000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-journald comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:58.582891 systemd[1]: Queued start job for default target multi-user.target. Jul 21 12:36:59.538997 systemd[1]: Started systemd-journald.service - Journal Service. Jul 21 12:36:58.686444 systemd[1]: Unnecessary job was removed for dev-nvme0n1p6.device - /dev/nvme0n1p6. Jul 21 12:36:58.690066 systemd[1]: systemd-journald.service: Deactivated successfully. Jul 21 12:36:59.316039 systemd-modules-load[1970]: Using 2 probe threads Jul 21 12:36:59.527415 systemd[1]: Starting systemd-journal-flush.service - Flush Journal to Persistent Storage... Jul 21 12:36:59.564034 systemd-tmpfiles[1980]: ACLs are not supported, ignoring. Jul 21 12:36:59.564083 systemd-tmpfiles[1980]: ACLs are not supported, ignoring. Jul 21 12:36:59.597000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-tmpfiles-setup-dev-early comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.596105 systemd[1]: Finished systemd-tmpfiles-setup-dev-early.service - Create Static Device Nodes in /dev gracefully. Jul 21 12:36:59.610623 systemd[1]: Finished systemd-random-seed.service - Load/Save OS Random Seed. Jul 21 12:36:59.615000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-random-seed comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.618634 systemd[1]: Reached target first-boot-complete.target - First Boot Complete. Jul 21 12:36:59.636069 systemd-journald[1969]: Time spent on flushing to /var/log/journal/ec2c0ef6f39eee0a06e5e3b661241913 is 133.864ms for 1153 entries. Jul 21 12:36:59.636069 systemd-journald[1969]: System Journal (/var/log/journal/ec2c0ef6f39eee0a06e5e3b661241913) is 8M, max 588.1M, 580.1M free. Jul 21 12:36:59.685000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.797013 systemd-journald[1969]: Received client request to flush runtime journal. Jul 21 12:36:59.684196 systemd[1]: Finished systemd-sysctl.service - Apply Kernel Variables. Jul 21 12:36:59.713676 systemd[1]: Mounting sys-fs-fuse-connections.mount - FUSE Control File System... Jul 21 12:36:59.803000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-journal-flush comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:36:59.725371 systemd[1]: Mounting sys-kernel-config.mount - Kernel Configuration File System... Jul 21 12:36:59.750010 systemd[1]: Mounted sys-fs-fuse-connections.mount - FUSE Control File System. Jul 21 12:36:59.772640 systemd[1]: Mounted sys-kernel-config.mount - Kernel Configuration File System. Jul 21 12:36:59.802816 systemd[1]: Finished systemd-journal-flush.service - Flush Journal to Persistent Storage. Jul 21 12:36:59.965608 systemd[1]: Finished systemd-udev-trigger.service - Coldplug All udev Devices. Jul 21 12:36:59.967000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-udev-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.007153 systemd[1]: Finished flatcar-tmpfiles.service - Create missing system files. Jul 21 12:37:00.009000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=flatcar-tmpfiles comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.014497 systemd[1]: Starting systemd-sysusers.service - Create System Users... Jul 21 12:37:00.084232 systemd[1]: Finished systemd-sysusers.service - Create System Users. Jul 21 12:37:00.087000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-sysusers comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.098126 systemd[1]: Starting systemd-journalctl.socket - Journal Log Access Socket... Jul 21 12:37:00.108000 audit: BPF prog-id=19 op=LOAD Jul 21 12:37:00.109000 audit: BPF prog-id=20 op=LOAD Jul 21 12:37:00.109000 audit: BPF prog-id=21 op=LOAD Jul 21 12:37:00.120000 audit: BPF prog-id=22 op=LOAD Jul 21 12:37:00.114178 systemd[1]: Starting systemd-oomd.service - Userspace Out-Of-Memory (OOM) Killer... Jul 21 12:37:00.126383 systemd[1]: Starting systemd-resolved.service - Network Name Resolution... Jul 21 12:37:00.138225 systemd[1]: Starting systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev... Jul 21 12:37:00.148271 systemd[1]: Listening on systemd-journalctl.socket - Journal Log Access Socket. Jul 21 12:37:00.156000 audit: BPF prog-id=23 op=LOAD Jul 21 12:37:00.156000 audit: BPF prog-id=24 op=LOAD Jul 21 12:37:00.156000 audit: BPF prog-id=25 op=LOAD Jul 21 12:37:00.161376 systemd[1]: Starting systemd-userdbd.service - User Database Manager... Jul 21 12:37:00.177435 systemd[1]: Starting modprobe@tun.service - Load Kernel Module tun... Jul 21 12:37:00.240348 systemd[1]: proc-sys-fs-binfmt_misc.automount: Got automount request for /proc/sys/fs/binfmt_misc, triggered by 2040 ((systemd-userd)) Jul 21 12:37:00.248748 systemd-tmpfiles[2039]: ACLs are not supported, ignoring. Jul 21 12:37:00.248802 systemd-tmpfiles[2039]: ACLs are not supported, ignoring. Jul 21 12:37:00.258274 systemd[1]: Finished systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev. Jul 21 12:37:00.264000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-tmpfiles-setup-dev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.266523 systemd[1]: Reached target local-fs-pre.target - Preparation for Local File Systems. Jul 21 12:37:00.273162 systemd[1]: systemd-repart.service - Repartition Root Disk skipped, no trigger condition checks were met. Jul 21 12:37:00.316882 kernel: tun: Universal TUN/TAP device driver, 1.6 Jul 21 12:37:00.317438 systemd[1]: modprobe@tun.service: Deactivated successfully. Jul 21 12:37:00.318958 systemd[1]: Finished modprobe@tun.service - Load Kernel Module tun. Jul 21 12:37:00.323000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@tun comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.323000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@tun comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.328000 audit: BPF prog-id=26 op=LOAD Jul 21 12:37:00.328000 audit: BPF prog-id=27 op=LOAD Jul 21 12:37:00.328000 audit: BPF prog-id=28 op=LOAD Jul 21 12:37:00.332205 systemd[1]: Starting systemd-nsresourced.service - Namespace Resource Manager... Jul 21 12:37:00.674890 systemd[1]: Finished systemd-hwdb-update.service - Rebuild Hardware Database. Jul 21 12:37:00.676000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-hwdb-update comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.677000 audit: BPF prog-id=7 op=UNLOAD Jul 21 12:37:00.677000 audit: BPF prog-id=6 op=UNLOAD Jul 21 12:37:00.677000 audit: BPF prog-id=29 op=LOAD Jul 21 12:37:00.678000 audit: BPF prog-id=30 op=LOAD Jul 21 12:37:00.681371 systemd[1]: Starting systemd-udevd.service - Rule-based Manager for Device Events and Files... Jul 21 12:37:00.705893 systemd[1]: Mounting proc-sys-fs-binfmt_misc.mount - Arbitrary Executable File Formats File System... Jul 21 12:37:00.709460 systemd[1]: var-lib-machines.mount - Virtual Machine and Container Storage (Compatibility) skipped, unmet condition check ConditionPathExists=/var/lib/machines.raw Jul 21 12:37:00.709565 systemd[1]: Reached target local-fs.target - Local File Systems. Jul 21 12:37:00.712023 systemd[1]: Reached target machines.target - Virtual Machines and Containers. Jul 21 12:37:00.718938 systemd[1]: Listening on systemd-importd.socket - Disk Image Download Service Socket. Jul 21 12:37:00.728169 systemd[1]: Listening on systemd-sysext.socket - System Extension Image Management. Jul 21 12:37:00.738582 systemd[1]: Starting systemd-confext.service - Merge System Configuration Images into /etc/... Jul 21 12:37:00.745209 systemd[1]: Starting systemd-machine-id-commit.service - Save Transient machine-id to Disk... Jul 21 12:37:00.757227 systemd[1]: Starting systemd-userdb-load-credentials.service - Load JSON user/group Records from Credentials... Jul 21 12:37:00.780540 systemd[1]: Mounted proc-sys-fs-binfmt_misc.mount - Arbitrary Executable File Formats File System. Jul 21 12:37:00.784815 systemd[1]: systemd-binfmt.service - Set Up Additional Binary Formats skipped, no trigger condition checks were met. Jul 21 12:37:00.785898 systemd[1]: proc-sys-fs-binfmt_misc.automount: Got automount request for /proc/sys/fs/binfmt_misc, triggered by 2044 ((systemd-nsres)) Jul 21 12:37:00.786344 systemd[1]: proc-sys-fs-binfmt_misc.automount: Automount point already active? Jul 21 12:37:00.837602 systemd[1]: etc-machine\x2did.mount: Deactivated successfully. Jul 21 12:37:00.841167 systemd[1]: Finished systemd-machine-id-commit.service - Save Transient machine-id to Disk. Jul 21 12:37:00.844000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-machine-id-commit comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.848147 systemd[1]: Finished systemd-userdb-load-credentials.service - Load JSON user/group Records from Credentials. Jul 21 12:37:00.849000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-userdb-load-credentials comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.883992 systemd[1]: Started systemd-userdbd.service - User Database Manager. Jul 21 12:37:00.887000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-userdbd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.890587 systemd-udevd[2046]: Using default interface naming scheme 'v260'. Jul 21 12:37:00.914111 systemd-nsresourced[2044]: Not setting up BPF subsystem, as functionality has been disabled at compile time. Jul 21 12:37:00.920625 systemd[1]: Started systemd-nsresourced.service - Namespace Resource Manager. Jul 21 12:37:00.922000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-nsresourced comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:00.960549 kernel: set_capacity_and_notify: 2 callbacks suppressed Jul 21 12:37:00.960708 kernel: loop6: detected capacity change from 0 to 44256 Jul 21 12:37:00.972887 kernel: loop6: p1 p2 p3 Jul 21 12:37:01.051878 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:01.052017 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:37:01.052074 kernel: device-mapper: table: 254:5: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:37:01.055128 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:37:01.054990 systemd-confext[2055]: device-mapper: reload ioctl on loop6p1-56-verity (254:5) failed: Invalid argument Jul 21 12:37:01.072871 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:01.073142 systemd-oomd[2037]: No swap; memory pressure usage will be degraded Jul 21 12:37:01.076194 systemd[1]: Started systemd-oomd.service - Userspace Out-Of-Memory (OOM) Killer. Jul 21 12:37:01.078000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-oomd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:01.105930 systemd-resolved[2038]: Positive Trust Anchors: Jul 21 12:37:01.105953 systemd-resolved[2038]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d Jul 21 12:37:01.105963 systemd-resolved[2038]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 Jul 21 12:37:01.106024 systemd-resolved[2038]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test Jul 21 12:37:01.115352 systemd-resolved[2038]: Defaulting to hostname 'linux'. Jul 21 12:37:01.118099 systemd[1]: Started systemd-resolved.service - Network Name Resolution. Jul 21 12:37:01.119000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-resolved comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:01.120921 systemd[1]: Reached target nss-lookup.target - Host and Network Name Lookups. Jul 21 12:37:01.159453 systemd[1]: Started systemd-udevd.service - Rule-based Manager for Device Events and Files. Jul 21 12:37:01.161000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-udevd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:01.163000 audit: BPF prog-id=31 op=LOAD Jul 21 12:37:01.166236 systemd[1]: Starting systemd-networkd.service - Network Management... Jul 21 12:37:01.331152 systemd-networkd[2075]: lo: Link UP Jul 21 12:37:01.331180 systemd-networkd[2075]: lo: Gained carrier Jul 21 12:37:01.334000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:01.333050 systemd[1]: Started systemd-networkd.service - Network Management. Jul 21 12:37:01.335747 systemd[1]: Reached target network.target - Network. Jul 21 12:37:01.343695 systemd[1]: Starting systemd-networkd-persistent-storage.service - Enable Persistent Storage in systemd-networkd... Jul 21 12:37:01.355080 systemd[1]: Starting systemd-networkd-wait-online.service - Wait for Network to be Online... Jul 21 12:37:01.487078 systemd[1]: Finished systemd-networkd-persistent-storage.service - Enable Persistent Storage in systemd-networkd. Jul 21 12:37:01.491000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-networkd-persistent-storage comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:01.499938 systemd[1]: Condition check resulted in dev-ttyS0.device - /dev/ttyS0 being skipped. Jul 21 12:37:01.514821 (udev-worker)[2089]: Network interface NamePolicy= disabled on kernel command line. Jul 21 12:37:01.605444 systemd-networkd[2075]: eth0: Found matching .network file, based on potentially unpredictable interface name: /usr/lib/systemd/network/zz-default.network Jul 21 12:37:01.605888 systemd-networkd[2075]: eth0: Configuring with /usr/lib/systemd/network/zz-default.network. Jul 21 12:37:01.619602 systemd-networkd[2075]: eth0: Link UP Jul 21 12:37:01.621262 systemd-networkd[2075]: eth0: Gained carrier Jul 21 12:37:01.621671 systemd-networkd[2075]: eth0: Found matching .network file, based on potentially unpredictable interface name: /usr/lib/systemd/network/zz-default.network Jul 21 12:37:01.636993 systemd-networkd[2075]: eth0: DHCPv4 address 172.31.16.165/20, gateway 172.31.16.1 acquired from 172.31.16.1 Jul 21 12:37:01.930185 systemd[1]: Starting systemd-vconsole-setup.service - Virtual Console Setup... Jul 21 12:37:02.160910 kernel: erofs: (device dm-5): mounted with root inode @ nid 40. Jul 21 12:37:02.261939 kernel: loop6: detected capacity change from 0 to 44256 Jul 21 12:37:02.264901 kernel: loop6: p1 p2 p3 Jul 21 12:37:02.278990 systemd-vconsole-setup[2131]: Configuration of first virtual console was skipped, ignoring remaining ones. Jul 21 12:37:02.284414 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:02.283473 systemd[1]: Finished systemd-vconsole-setup.service - Virtual Console Setup. Jul 21 12:37:02.284616 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:37:02.287272 kernel: device-mapper: table: 254:5: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:37:02.288000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:02.291043 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:37:02.295969 (sd-merge)[2215]: device-mapper: reload ioctl on loop6p1-61-verity (254:5) failed: Invalid argument Jul 21 12:37:02.302928 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:02.368869 kernel: erofs: (device dm-5): mounted with root inode @ nid 40. Jul 21 12:37:02.369991 (sd-merge)[2215]: Skipping extension refresh because no change was found, use --always-refresh=yes to always do a refresh. Jul 21 12:37:02.377032 systemd[1]: Found device dev-disk-by\x2dlabel-OEM.device - Amazon Elastic Block Store OEM. Jul 21 12:37:02.384473 systemd[1]: Finished systemd-confext.service - Merge System Configuration Images into /etc/. Jul 21 12:37:02.386000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-confext comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:02.412032 systemd[1]: Starting systemd-fsck@dev-disk-by\x2dlabel-OEM.service - File System Check on /dev/disk/by-label/OEM... Jul 21 12:37:02.418307 systemd[1]: Starting systemd-sysext.service - Merge System Extension Images into /usr/ and /opt/... Jul 21 12:37:02.462949 kernel: loop6: detected capacity change from 0 to 379472 Jul 21 12:37:02.466922 kernel: loop6: p1 p2 p3 Jul 21 12:37:02.493520 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:02.493640 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:37:02.495480 kernel: device-mapper: table: 254:5: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:37:02.495589 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:37:02.496717 systemd-sysext[2227]: device-mapper: reload ioctl on loop6p1-65-verity (254:5) failed: Invalid argument Jul 21 12:37:02.506890 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:02.523209 systemd[1]: Finished systemd-fsck@dev-disk-by\x2dlabel-OEM.service - File System Check on /dev/disk/by-label/OEM. Jul 21 12:37:02.525000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-fsck@dev-disk-by\x2dlabel-OEM comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:02.572878 kernel: erofs: (device dm-5): mounted with root inode @ nid 39. Jul 21 12:37:02.605592 kernel: loop6: detected capacity change from 0 to 281976 Jul 21 12:37:02.608217 kernel: loop6: p1 p2 p3 Jul 21 12:37:02.636601 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:02.636682 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:37:02.638573 kernel: device-mapper: table: 254:5: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:37:02.639998 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:37:02.640131 systemd-sysext[2227]: device-mapper: reload ioctl on loop6p1-70-verity (254:5) failed: Invalid argument Jul 21 12:37:02.646929 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:02.720893 kernel: erofs: (device dm-5): mounted with root inode @ nid 39. Jul 21 12:37:02.758013 kernel: loop6: detected capacity change from 0 to 172472 Jul 21 12:37:02.762936 kernel: loop6: p1 p2 p3 Jul 21 12:37:02.793935 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:02.794033 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:37:02.797551 kernel: device-mapper: table: 254:5: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:37:02.797625 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:37:02.799263 systemd-sysext[2227]: device-mapper: reload ioctl on loop6p1-75-verity (254:5) failed: Invalid argument Jul 21 12:37:02.807935 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:02.877907 kernel: erofs: (device dm-5): mounted with root inode @ nid 39. Jul 21 12:37:02.904775 kernel: loop6: detected capacity change from 0 to 200864 Jul 21 12:37:02.974998 kernel: loop6: detected capacity change from 0 to 379472 Jul 21 12:37:02.978863 kernel: loop6: p1 p2 p3 Jul 21 12:37:03.009648 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:03.009758 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:37:03.011602 kernel: device-mapper: table: 254:5: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:37:03.015492 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:37:03.016384 (sd-merge)[2256]: device-mapper: reload ioctl on loop6p1-83-verity (254:5) failed: Invalid argument Jul 21 12:37:03.021932 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:03.083940 kernel: erofs: (device dm-5): mounted with root inode @ nid 39. Jul 21 12:37:03.091099 kernel: loop7: detected capacity change from 0 to 281976 Jul 21 12:37:03.094928 kernel: loop7: p1 p2 p3 Jul 21 12:37:03.117633 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:03.117854 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:37:03.117906 kernel: device-mapper: table: 254:6: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:37:03.120626 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:37:03.120664 (sd-merge)[2256]: device-mapper: reload ioctl on loop7p1-87-verity (254:6) failed: Invalid argument Jul 21 12:37:03.124971 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:03.178899 kernel: erofs: (device dm-6): mounted with root inode @ nid 39. Jul 21 12:37:03.185629 kernel: loop8: detected capacity change from 0 to 172472 Jul 21 12:37:03.190873 kernel: loop8: p1 p2 p3 Jul 21 12:37:03.218431 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:03.218540 kernel: device-mapper: verity: Unrecognized verity feature request: root_hash_sig_key_desc Jul 21 12:37:03.220722 kernel: device-mapper: table: 254:7: verity: Unrecognized verity feature request (-EINVAL) Jul 21 12:37:03.222134 kernel: device-mapper: ioctl: error adding target to table Jul 21 12:37:03.224291 (sd-merge)[2256]: device-mapper: reload ioctl on loop8p1-91-verity (254:7) failed: Invalid argument Jul 21 12:37:03.230896 kernel: device-mapper: verity: sha256 using shash "sha256-ce" Jul 21 12:37:03.296888 kernel: erofs: (device dm-7): mounted with root inode @ nid 39. Jul 21 12:37:03.302561 kernel: loop9: detected capacity change from 0 to 200864 Jul 21 12:37:03.335056 (sd-merge)[2256]: Skipping extension refresh because no change was found, use --always-refresh=yes to always do a refresh. Jul 21 12:37:03.344047 systemd[1]: Finished systemd-sysext.service - Merge System Extension Images into /usr/ and /opt/. Jul 21 12:37:03.345000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-sysext comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:03.358200 systemd[1]: Starting systemd-tmpfiles-setup.service - Create System Files and Directories... Jul 21 12:37:03.439590 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/base_image_var.conf:29: Duplicate line for path "/var/log/audit", ignoring. Jul 21 12:37:03.444811 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/base_image_var_late.conf:44: Duplicate line for path "/var/log/audit", ignoring. Jul 21 12:37:03.446767 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/baselayout.conf:15: Duplicate line for path "/var", ignoring. Jul 21 12:37:03.446803 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/baselayout.conf:16: Duplicate line for path "/var/empty", ignoring. Jul 21 12:37:03.446987 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/baselayout.conf:21: Duplicate line for path "/var/log", ignoring. Jul 21 12:37:03.447247 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/dbus.conf:5: Duplicate line for path "/var/lib/dbus", ignoring. Jul 21 12:37:03.448125 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/nfs-utils.conf:2: Duplicate line for path "/var/lib/nfs/v4recovery", ignoring. Jul 21 12:37:03.450365 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/nfs-utils.conf:6: Duplicate line for path "/var/lib/nfs/sm", ignoring. Jul 21 12:37:03.450443 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/nfs-utils.conf:7: Duplicate line for path "/var/lib/nfs/sm.bak", ignoring. Jul 21 12:37:03.451110 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/provision.conf:20: Duplicate line for path "/root", ignoring. Jul 21 12:37:03.453702 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/tpm2-tss-fapi.conf:2: Duplicate line for path "/var/lib/tpm2-tss/system/keystore", ignoring. Jul 21 12:37:03.453724 systemd-tmpfiles[2280]: ACLs are not supported, ignoring. Jul 21 12:37:03.453899 systemd-tmpfiles[2280]: ACLs are not supported, ignoring. Jul 21 12:37:03.490493 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/var.conf:10: Duplicate line for path "/var", ignoring. Jul 21 12:37:03.490546 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/var.conf:14: Duplicate line for path "/var/log", ignoring. Jul 21 12:37:03.490815 systemd-tmpfiles[2280]: /usr/lib/tmpfiles.d/var.conf:21: Duplicate line for path "/var/lib", ignoring. Jul 21 12:37:03.500275 systemd-tmpfiles[2280]: Detected autofs mount point '/boot' during canonicalization of 'boot'. Jul 21 12:37:03.500306 systemd-tmpfiles[2280]: Skipping /boot Jul 21 12:37:03.523908 systemd-tmpfiles[2280]: Detected autofs mount point '/boot' during canonicalization of 'boot'. Jul 21 12:37:03.523941 systemd-tmpfiles[2280]: Skipping /boot Jul 21 12:37:03.528346 systemd-networkd[2075]: eth0: Gained IPv6LL Jul 21 12:37:03.537000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-networkd-wait-online comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:03.536028 systemd[1]: Finished systemd-networkd-wait-online.service - Wait for Network to be Online. Jul 21 12:37:03.540261 systemd[1]: Reached target network-online.target - Network is Online. Jul 21 12:37:03.568324 systemd[1]: Finished systemd-tmpfiles-setup.service - Create System Files and Directories. Jul 21 12:37:03.570000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-tmpfiles-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:03.578909 systemd[1]: Starting audit-rules.service - Load Audit Rules... Jul 21 12:37:03.594437 systemd[1]: Starting clean-ca-certificates.service - Clean up broken links in /etc/ssl/certs... Jul 21 12:37:03.613206 systemd[1]: Starting ldconfig.service - Rebuild Dynamic Linker Cache... Jul 21 12:37:03.620318 systemd[1]: Starting systemd-journal-catalog-update.service - Rebuild Journal Catalog... Jul 21 12:37:03.628794 systemd[1]: Starting systemd-update-utmp.service - Record System Boot/Shutdown in UTMP... Jul 21 12:37:03.677000 audit[2298]: AUDIT1127 pid=2298 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg=' comm="systemd-update-utmp" exe="/usr/lib/systemd/systemd-update-utmp" hostname=? addr=? terminal=? res=success' Jul 21 12:37:03.685013 kernel: kauditd_printk_skb: 69 callbacks suppressed Jul 21 12:37:03.685158 kernel: audit: type=1127 audit(1784637423.677:162): pid=2298 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg=' comm="systemd-update-utmp" exe="/usr/lib/systemd/systemd-update-utmp" hostname=? addr=? terminal=? res=success' Jul 21 12:37:03.691384 systemd[1]: Finished systemd-update-utmp.service - Record System Boot/Shutdown in UTMP. Jul 21 12:37:03.693000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-update-utmp comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:03.707960 kernel: audit: type=1130 audit(1784637423.693:163): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-update-utmp comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:03.732071 systemd[1]: Finished systemd-journal-catalog-update.service - Rebuild Journal Catalog. Jul 21 12:37:03.730000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-journal-catalog-update comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:03.741916 kernel: audit: type=1130 audit(1784637423.730:164): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-journal-catalog-update comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:03.831000 audit: CONFIG_CHANGE auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 op=add_rule key=(null) list=5 res=1 Jul 21 12:37:03.836888 augenrules[2314]: No rules Jul 21 12:37:03.831000 audit[2314]: SYSCALL arch=c00000b7 syscall=206 success=yes exit=1056 a0=3 a1=fffff3cd8640 a2=420 a3=0 items=0 ppid=2288 pid=2314 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="auditctl" exe="/usr/bin/auditctl" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:03.840935 systemd[1]: audit-rules.service: Deactivated successfully. Jul 21 12:37:03.843401 kernel: audit: type=1305 audit(1784637423.831:165): auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 op=add_rule key=(null) list=5 res=1 Jul 21 12:37:03.843195 systemd[1]: Finished audit-rules.service - Load Audit Rules. Jul 21 12:37:03.843642 kernel: audit: type=1300 audit(1784637423.831:165): arch=c00000b7 syscall=206 success=yes exit=1056 a0=3 a1=fffff3cd8640 a2=420 a3=0 items=0 ppid=2288 pid=2314 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="auditctl" exe="/usr/bin/auditctl" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:03.831000 audit: PROCTITLE proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573 Jul 21 12:37:03.847150 kernel: audit: type=1327 audit(1784637423.831:165): proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573 Jul 21 12:37:03.853003 systemd[1]: Finished clean-ca-certificates.service - Clean up broken links in /etc/ssl/certs. Jul 21 12:37:03.857704 systemd[1]: update-ca-certificates.service - Update CA bundle at /etc/ssl/certs/ca-certificates.crt skipped, unmet condition check ConditionPathIsSymbolicLink=!/etc/ssl/certs/ca-certificates.crt Jul 21 12:37:07.298890 ldconfig[2294]: ldconfig: /usr/lib/ld.so.conf is not an ELF file - it has the wrong magic bytes at the start. Jul 21 12:37:07.309021 systemd[1]: Finished ldconfig.service - Rebuild Dynamic Linker Cache. Jul 21 12:37:07.314612 systemd[1]: Starting systemd-update-done.service - Update is Completed... Jul 21 12:37:07.347024 systemd[1]: Finished systemd-update-done.service - Update is Completed. Jul 21 12:37:07.350607 systemd[1]: Reached target sysinit.target - System Initialization. Jul 21 12:37:07.353416 systemd[1]: Started motdgen.path - Watch for update engine configuration changes. Jul 21 12:37:07.356533 systemd[1]: Started user-cloudinit@var-lib-flatcar\x2dinstall-user_data.path - Watch for a cloud-config at /var/lib/flatcar-install/user_data. Jul 21 12:37:07.359634 systemd[1]: Started logrotate.timer - Daily rotation of log files. Jul 21 12:37:07.362215 systemd[1]: Started mdadm.timer - Weekly check for MD array's redundancy information.. Jul 21 12:37:07.364976 systemd[1]: Started systemd-sysupdate-reboot.timer - Reboot Automatically After System Update. Jul 21 12:37:07.368045 systemd[1]: Started systemd-sysupdate.timer - Automatic System Update. Jul 21 12:37:07.370438 systemd[1]: Started systemd-tmpfiles-clean.timer - Daily Cleanup of Temporary Directories. Jul 21 12:37:07.373087 systemd[1]: update-engine-stub.timer - Update Engine Stub Timer skipped, unmet condition check ConditionPathExists=/usr/.noupdate Jul 21 12:37:07.373160 systemd[1]: Reached target paths.target - Path Units. Jul 21 12:37:07.375650 systemd[1]: Reached target timers.target - Timer Units. Jul 21 12:37:07.378814 systemd[1]: Listening on dbus.socket - D-Bus System Message Bus Socket. Jul 21 12:37:07.383956 systemd[1]: Starting docker.socket - Docker Socket for the API... Jul 21 12:37:07.389901 systemd[1]: Listening on sshd-unix-local.socket - OpenSSH Server Socket (systemd-ssh-generator, AF_UNIX Local). Jul 21 12:37:07.403936 systemd[1]: Listening on sshd.socket - OpenSSH Server Socket. Jul 21 12:37:07.406903 systemd[1]: Listening on systemd-hostnamed.socket - Hostname Service Socket. Jul 21 12:37:07.410068 systemd[1]: Listening on systemd-logind-varlink.socket - User Login Management Varlink Socket. Jul 21 12:37:07.413436 systemd[1]: Listening on systemd-machined.socket - Virtual Machine and Container Registration Service Socket. Jul 21 12:37:07.417313 systemd[1]: Listening on docker.socket - Docker Socket for the API. Jul 21 12:37:07.419861 systemd[1]: Reached target sockets.target - Socket Units. Jul 21 12:37:07.422198 systemd[1]: Reached target basic.target - Basic System. Jul 21 12:37:07.424430 systemd[1]: addon-config@oem.service - Configure Addon /oem skipped, no trigger condition checks were met. Jul 21 12:37:07.424601 systemd[1]: addon-run@oem.service - Run Addon /oem skipped, no trigger condition checks were met. Jul 21 12:37:07.426671 systemd[1]: Starting containerd.service - containerd container runtime... Jul 21 12:37:07.431757 systemd[1]: Starting dbus.service - D-Bus System Message Bus... Jul 21 12:37:07.439253 systemd[1]: Starting dracut-shutdown.service - Restore /run/initramfs on shutdown... Jul 21 12:37:07.445558 systemd[1]: Starting enable-oem-cloudinit.service - Enable cloudinit... Jul 21 12:37:07.455666 systemd[1]: Starting extend-filesystems.service - Extend Filesystems... Jul 21 12:37:07.458173 systemd[1]: flatcar-setup-environment.service - Modifies /etc/environment for CoreOS skipped, unmet condition check ConditionPathExists=/oem/bin/flatcar-setup-environment Jul 21 12:37:07.462744 systemd[1]: Starting kubelet.service - kubelet: The Kubernetes Node Agent... Jul 21 12:37:07.471274 systemd[1]: Starting motdgen.service - Generate /run/flatcar/motd... Jul 21 12:37:07.495275 systemd[1]: Started ntpd.service - Network Time Service. Jul 21 12:37:07.500694 systemd[1]: Starting nvidia.service - NVIDIA Configure Service... Jul 21 12:37:07.511221 systemd[1]: Starting prepare-helm.service - Unpack helm to /opt/bin... Jul 21 12:37:07.517018 jq[2329]: false Jul 21 12:37:07.521302 systemd[1]: Starting setup-oem.service - Setup OEM... Jul 21 12:37:07.535379 systemd[1]: Starting ssh-key-proc-cmdline.service - Install an ssh key from /proc/cmdline... Jul 21 12:37:07.552087 motdgen[2343]: /oem/oem-release: line 2: EC2: command not found Jul 21 12:37:07.553643 systemd[1]: Starting sshd-keygen.service - Generate sshd host keys... Jul 21 12:37:07.566346 systemd[1]: Starting systemd-logind.service - User Login Management... Jul 21 12:37:07.569406 systemd[1]: tcsd.service - TCG Core Services Daemon skipped, unmet condition check ConditionPathExists=/dev/tpm0 Jul 21 12:37:07.578290 systemd[1]: Starting update-engine.service - Update Engine... Jul 21 12:37:07.583680 systemd[1]: Starting update-ssh-keys-after-ignition.service - Run update-ssh-keys once after Ignition... Jul 21 12:37:07.592874 extend-filesystems[2330]: Found /dev/nvme0n1p6 Jul 21 12:37:07.616979 extend-filesystems[2330]: Found /dev/nvme0n1p9 Jul 21 12:37:07.634913 systemd[1]: Finished dracut-shutdown.service - Restore /run/initramfs on shutdown. Jul 21 12:37:07.639476 systemd[1]: enable-oem-cloudinit.service: Skipped due to 'exec-condition'. Jul 21 12:37:07.640132 systemd[1]: Condition check resulted in enable-oem-cloudinit.service - Enable cloudinit being skipped. Jul 21 12:37:07.648365 ntpd[2333]: ntpd 4.2.8p18@1.4062-o Tue Jul 21 11:02:36 UTC 2026 (1): Starting Jul 21 12:37:07.650491 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: ntpd 4.2.8p18@1.4062-o Tue Jul 21 11:02:36 UTC 2026 (1): Starting Jul 21 12:37:07.650491 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: Command line: /usr/sbin/ntpd -g -n -u ntp:ntp Jul 21 12:37:07.650491 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: ---------------------------------------------------- Jul 21 12:37:07.650491 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: ntp-4 is maintained by Network Time Foundation, Jul 21 12:37:07.650491 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: Inc. (NTF), a non-profit 501(c)(3) public-benefit Jul 21 12:37:07.650491 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: corporation. Support and training for ntp-4 are Jul 21 12:37:07.650491 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: available at https://www.nwtime.org/support Jul 21 12:37:07.650491 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: ---------------------------------------------------- Jul 21 12:37:07.648487 ntpd[2333]: Command line: /usr/sbin/ntpd -g -n -u ntp:ntp Jul 21 12:37:07.648507 ntpd[2333]: ---------------------------------------------------- Jul 21 12:37:07.648526 ntpd[2333]: ntp-4 is maintained by Network Time Foundation, Jul 21 12:37:07.648544 ntpd[2333]: Inc. (NTF), a non-profit 501(c)(3) public-benefit Jul 21 12:37:07.648560 ntpd[2333]: corporation. Support and training for ntp-4 are Jul 21 12:37:07.648578 ntpd[2333]: available at https://www.nwtime.org/support Jul 21 12:37:07.648594 ntpd[2333]: ---------------------------------------------------- Jul 21 12:37:07.655010 extend-filesystems[2330]: Checking size of /dev/nvme0n1p9 Jul 21 12:37:07.660040 ntpd[2333]: proto: precision = 0.084 usec (-23) Jul 21 12:37:07.661534 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: proto: precision = 0.084 usec (-23) Jul 21 12:37:07.661534 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: basedate set to 2026-07-09 Jul 21 12:37:07.661534 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: gps base set to 2026-07-12 (week 2427) Jul 21 12:37:07.661534 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: Listen and drop on 0 v6wildcard [::]:123 Jul 21 12:37:07.661534 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: Listen and drop on 1 v4wildcard 0.0.0.0:123 Jul 21 12:37:07.660499 ntpd[2333]: basedate set to 2026-07-09 Jul 21 12:37:07.660528 ntpd[2333]: gps base set to 2026-07-12 (week 2427) Jul 21 12:37:07.660738 ntpd[2333]: Listen and drop on 0 v6wildcard [::]:123 Jul 21 12:37:07.660787 ntpd[2333]: Listen and drop on 1 v4wildcard 0.0.0.0:123 Jul 21 12:37:07.662630 ntpd[2333]: Listen normally on 2 lo 127.0.0.1:123 Jul 21 12:37:07.662706 systemd[1]: ssh-key-proc-cmdline.service: Deactivated successfully. Jul 21 12:37:07.664397 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: Listen normally on 2 lo 127.0.0.1:123 Jul 21 12:37:07.664397 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: Listen normally on 3 eth0 172.31.16.165:123 Jul 21 12:37:07.664397 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: Listen normally on 4 lo [::1]:123 Jul 21 12:37:07.664397 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: Listen normally on 5 eth0 [fe80::471:38ff:fe23:cb53%2]:123 Jul 21 12:37:07.664397 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: Listening on routing socket on fd #22 for interface updates Jul 21 12:37:07.662700 ntpd[2333]: Listen normally on 3 eth0 172.31.16.165:123 Jul 21 12:37:07.662750 ntpd[2333]: Listen normally on 4 lo [::1]:123 Jul 21 12:37:07.662795 ntpd[2333]: Listen normally on 5 eth0 [fe80::471:38ff:fe23:cb53%2]:123 Jul 21 12:37:07.663905 ntpd[2333]: Listening on routing socket on fd #22 for interface updates Jul 21 12:37:07.675258 systemd[1]: Finished ssh-key-proc-cmdline.service - Install an ssh key from /proc/cmdline. Jul 21 12:37:07.679764 systemd[1]: motdgen.service: Deactivated successfully. Jul 21 12:37:07.685592 ntpd[2333]: kernel reports TIME_ERROR: 0x41: Clock Unsynchronized Jul 21 12:37:07.687293 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: kernel reports TIME_ERROR: 0x41: Clock Unsynchronized Jul 21 12:37:07.687293 ntpd[2333]: 21 Jul 12:37:07 ntpd[2333]: kernel reports TIME_ERROR: 0x41: Clock Unsynchronized Jul 21 12:37:07.681546 systemd[1]: Finished motdgen.service - Generate /run/flatcar/motd. Jul 21 12:37:07.685642 ntpd[2333]: kernel reports TIME_ERROR: 0x41: Clock Unsynchronized Jul 21 12:37:07.696875 jq[2351]: true Jul 21 12:37:07.771646 extend-filesystems[2330]: Resized partition /dev/nvme0n1p9 Jul 21 12:37:07.803307 extend-filesystems[2390]: resize2fs 1.47.4 (6-Mar-2025) Jul 21 12:37:07.837435 tar[2367]: linux-arm64/LICENSE Jul 21 12:37:07.837435 tar[2367]: linux-arm64/helm Jul 21 12:37:07.843428 dbus-daemon[2327]: [system] SELinux support is enabled Jul 21 12:37:07.843946 systemd[1]: Started dbus.service - D-Bus System Message Bus. Jul 21 12:37:07.857615 dbus-daemon[2327]: [system] Activating systemd to hand-off: service name='org.freedesktop.hostname1' unit='dbus-org.freedesktop.hostname1.service' requested by ':1.2' (uid=244 pid=2075 comm="/usr/lib/systemd/systemd-networkd" label="system_u:system_r:kernel_t:s0") Jul 21 12:37:07.858600 dbus-daemon[2327]: [system] Successfully activated service 'org.freedesktop.systemd1' Jul 21 12:37:07.863385 systemd[1]: system-cloudinit@usr-share-coreos-cloud\x2dconfig.yml.service - Load cloud-config from /usr/share/coreos/cloud-config.yml skipped, unmet condition check ConditionFileNotEmpty=/usr/share/coreos/cloud-config.yml Jul 21 12:37:07.863462 systemd[1]: Reached target system-config.target - Load system-provided cloud configs. Jul 21 12:37:07.875333 systemd[1]: Starting systemd-hostnamed.service - Hostname Service... Jul 21 12:37:07.888049 kernel: EXT4-fs (nvme0n1p9): resizing filesystem from 1617920 to 2604027 blocks Jul 21 12:37:07.888104 jq[2374]: true Jul 21 12:37:07.877814 systemd[1]: user-cloudinit-proc-cmdline.service - Load cloud-config from url defined in /proc/cmdline skipped, unmet condition check ConditionKernelCommandLine=cloud-config-url Jul 21 12:37:07.877881 systemd[1]: Reached target user-config.target - Load user-provided cloud configs. Jul 21 12:37:07.909582 systemd[1]: Finished nvidia.service - NVIDIA Configure Service. Jul 21 12:37:07.944952 kernel: EXT4-fs (nvme0n1p9): resized filesystem to 2604027 Jul 21 12:37:07.963989 extend-filesystems[2390]: Filesystem at /dev/nvme0n1p9 is mounted on /; on-line resizing required Jul 21 12:37:07.963989 extend-filesystems[2390]: old_desc_blocks = 1, new_desc_blocks = 2 Jul 21 12:37:07.963989 extend-filesystems[2390]: The filesystem on /dev/nvme0n1p9 is now 2604027 (4k) blocks long. Jul 21 12:37:07.979033 extend-filesystems[2330]: Resized filesystem in /dev/nvme0n1p9 Jul 21 12:37:07.988984 update_engine[2348]: I20260721 12:37:07.988466 2348 main.cc:92] Flatcar Update Engine starting Jul 21 12:37:07.996501 systemd[1]: extend-filesystems.service: Deactivated successfully. Jul 21 12:37:07.998032 systemd[1]: Finished extend-filesystems.service - Extend Filesystems. Jul 21 12:37:08.008854 systemd[1]: Started update-engine.service - Update Engine. Jul 21 12:37:08.017511 systemd[1]: Started locksmithd.service - Cluster reboot manager. Jul 21 12:37:08.026247 update_engine[2348]: I20260721 12:37:08.022746 2348 update_check_scheduler.cc:74] Next update check in 8m59s Jul 21 12:37:08.030077 systemd[1]: Finished setup-oem.service - Setup OEM. Jul 21 12:37:08.040977 systemd[1]: Started amazon-ssm-agent.service - amazon-ssm-agent. Jul 21 12:37:08.141867 bash[2422]: Updated "/home/core/.ssh/authorized_keys" Jul 21 12:37:08.142436 systemd[1]: Finished update-ssh-keys-after-ignition.service - Run update-ssh-keys once after Ignition. Jul 21 12:37:08.152552 systemd[1]: Starting sshkeys.service... Jul 21 12:37:08.208559 systemd-logind[2347]: Watching system buttons on /dev/input/event0 (Power Button) Jul 21 12:37:08.208624 systemd-logind[2347]: Watching system buttons on /dev/input/event1 (Sleep Button) Jul 21 12:37:08.209110 systemd-logind[2347]: New seat seat0. Jul 21 12:37:08.210509 systemd[1]: Started systemd-logind.service - User Login Management. Jul 21 12:37:08.246567 systemd[1]: Created slice system-coreos\x2dmetadata\x2dsshkeys.slice - Slice /system/coreos-metadata-sshkeys. Jul 21 12:37:08.254584 systemd[1]: Starting coreos-metadata-sshkeys@core.service - Flatcar Metadata Agent (SSH Keys)... Jul 21 12:37:08.346735 systemd[1]: Started systemd-hostnamed.service - Hostname Service. Jul 21 12:37:08.382175 dbus-daemon[2327]: [system] Successfully activated service 'org.freedesktop.hostname1' Jul 21 12:37:08.390104 dbus-daemon[2327]: [system] Activating via systemd: service name='org.freedesktop.PolicyKit1' unit='polkit.service' requested by ':1.6' (uid=0 pid=2398 comm="/usr/lib/systemd/systemd-hostnamed" label="system_u:system_r:kernel_t:s0") Jul 21 12:37:08.410148 systemd[1]: Starting polkit.service - Authorization Manager... Jul 21 12:37:08.769629 amazon-ssm-agent[2412]: Initializing new seelog logger Jul 21 12:37:08.769629 amazon-ssm-agent[2412]: New Seelog Logger Creation Complete Jul 21 12:37:08.769629 amazon-ssm-agent[2412]: 2026/07/21 12:37:08 Found config file at /etc/amazon/ssm/amazon-ssm-agent.json. Jul 21 12:37:08.769629 amazon-ssm-agent[2412]: Applying config override from /etc/amazon/ssm/amazon-ssm-agent.json. Jul 21 12:37:08.772934 amazon-ssm-agent[2412]: 2026/07/21 12:37:08 processing appconfig overrides Jul 21 12:37:08.778882 amazon-ssm-agent[2412]: 2026/07/21 12:37:08 Found config file at /etc/amazon/ssm/amazon-ssm-agent.json. Jul 21 12:37:08.779530 amazon-ssm-agent[2412]: Applying config override from /etc/amazon/ssm/amazon-ssm-agent.json. Jul 21 12:37:08.779530 amazon-ssm-agent[2412]: 2026/07/21 12:37:08 processing appconfig overrides Jul 21 12:37:08.780250 amazon-ssm-agent[2412]: 2026/07/21 12:37:08 Found config file at /etc/amazon/ssm/amazon-ssm-agent.json. Jul 21 12:37:08.780385 amazon-ssm-agent[2412]: Applying config override from /etc/amazon/ssm/amazon-ssm-agent.json. Jul 21 12:37:08.780723 amazon-ssm-agent[2412]: 2026/07/21 12:37:08 processing appconfig overrides Jul 21 12:37:08.792732 amazon-ssm-agent[2412]: 2026-07-21 12:37:08.7738 INFO Proxy environment variables: Jul 21 12:37:08.814528 amazon-ssm-agent[2412]: 2026/07/21 12:37:08 Found config file at /etc/amazon/ssm/amazon-ssm-agent.json. Jul 21 12:37:08.814528 amazon-ssm-agent[2412]: Applying config override from /etc/amazon/ssm/amazon-ssm-agent.json. Jul 21 12:37:08.814528 amazon-ssm-agent[2412]: 2026/07/21 12:37:08 processing appconfig overrides Jul 21 12:37:08.826173 coreos-metadata[2430]: Jul 21 12:37:08.825 INFO Putting http://169.254.169.254/latest/api/token: Attempt #1 Jul 21 12:37:08.836916 coreos-metadata[2430]: Jul 21 12:37:08.833 INFO Fetching http://169.254.169.254/2021-01-03/meta-data/public-keys: Attempt #1 Jul 21 12:37:08.832518 polkitd[2443]: Started polkitd version 126 Jul 21 12:37:08.840569 coreos-metadata[2430]: Jul 21 12:37:08.839 INFO Fetch successful Jul 21 12:37:08.840569 coreos-metadata[2430]: Jul 21 12:37:08.840 INFO Fetching http://169.254.169.254/2021-01-03/meta-data/public-keys/0/openssh-key: Attempt #1 Jul 21 12:37:08.844065 coreos-metadata[2430]: Jul 21 12:37:08.843 INFO Fetch successful Jul 21 12:37:08.852536 unknown[2430]: wrote ssh authorized keys file for user: core Jul 21 12:37:08.856462 polkitd[2443]: Loading rules from directory /etc/polkit-1/rules.d Jul 21 12:37:08.856591 polkitd[2443]: Loading rules from directory /run/polkit-1/rules.d Jul 21 12:37:08.856667 polkitd[2443]: Error opening rules directory: Error opening directory “/run/polkit-1/rules.d”: No such file or directory (g-file-error-quark, 4) Jul 21 12:37:08.856692 polkitd[2443]: Loading rules from directory /usr/local/share/polkit-1/rules.d Jul 21 12:37:08.856727 polkitd[2443]: Error opening rules directory: Error opening directory “/usr/local/share/polkit-1/rules.d”: No such file or directory (g-file-error-quark, 4) Jul 21 12:37:08.856746 polkitd[2443]: Loading rules from directory /usr/share/polkit-1/rules.d Jul 21 12:37:08.874758 polkitd[2443]: Finished loading, compiling and executing 5 rules Jul 21 12:37:08.881586 systemd[1]: Started polkit.service - Authorization Manager. Jul 21 12:37:08.888223 locksmithd[2408]: locksmithd starting currentOperation="UPDATE_STATUS_IDLE" strategy="reboot" Jul 21 12:37:08.895269 dbus-daemon[2327]: [system] Successfully activated service 'org.freedesktop.PolicyKit1' Jul 21 12:37:08.897108 polkitd[2443]: Acquired the name org.freedesktop.PolicyKit1 on the system bus Jul 21 12:37:08.903221 amazon-ssm-agent[2412]: 2026-07-21 12:37:08.7759 INFO https_proxy: Jul 21 12:37:08.967931 systemd-hostnamed[2398]: Hostname set to (transient) Jul 21 12:37:08.968125 systemd-resolved[2038]: System hostname changed to 'ip-172-31-16-165'. Jul 21 12:37:08.980958 update-ssh-keys[2508]: Updated "/home/core/.ssh/authorized_keys" Jul 21 12:37:08.982224 systemd[1]: Finished coreos-metadata-sshkeys@core.service - Flatcar Metadata Agent (SSH Keys). Jul 21 12:37:09.005317 amazon-ssm-agent[2412]: 2026-07-21 12:37:08.7759 INFO http_proxy: Jul 21 12:37:09.018513 systemd[1]: Finished sshkeys.service. Jul 21 12:37:09.105315 amazon-ssm-agent[2412]: 2026-07-21 12:37:08.7759 INFO no_proxy: Jul 21 12:37:09.213860 amazon-ssm-agent[2412]: 2026-07-21 12:37:08.7794 INFO Checking if agent identity type OnPrem can be assumed Jul 21 12:37:09.320660 amazon-ssm-agent[2412]: 2026-07-21 12:37:08.7800 INFO Checking if agent identity type EC2 can be assumed Jul 21 12:37:09.421128 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.2507 INFO Agent will take identity from EC2 Jul 21 12:37:09.519359 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.2601 INFO [amazon-ssm-agent] amazon-ssm-agent - v3.3.0.0 Jul 21 12:37:09.618898 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.2601 INFO [amazon-ssm-agent] OS: linux, Arch: arm64 Jul 21 12:37:09.719960 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.2601 INFO [amazon-ssm-agent] Starting Core Agent Jul 21 12:37:09.809454 containerd[2389]: time="2026-07-21T12:37:09Z" level=warning msg="Ignoring unknown key in TOML" column=1 error="strict mode: fields in the document are missing in the target struct" file=/usr/share/containerd/config.toml key=subreaper row=8 Jul 21 12:37:09.815371 containerd[2389]: time="2026-07-21T12:37:09.814433742Z" level=info msg="starting containerd" revision=e53c7c1516c3b2bff98eb76f1f4117477e6f4e66 version=v2.2.5 Jul 21 12:37:09.823503 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.2601 INFO [amazon-ssm-agent] Registrar detected. Attempting registration Jul 21 12:37:09.876671 amazon-ssm-agent[2412]: 2026/07/21 12:37:09 Found config file at /etc/amazon/ssm/amazon-ssm-agent.json. Jul 21 12:37:09.876671 amazon-ssm-agent[2412]: Applying config override from /etc/amazon/ssm/amazon-ssm-agent.json. Jul 21 12:37:09.876671 amazon-ssm-agent[2412]: 2026/07/21 12:37:09 processing appconfig overrides Jul 21 12:37:09.887072 containerd[2389]: time="2026-07-21T12:37:09.886362366Z" level=warning msg="Configuration migrated from version 2, use `containerd config migrate` to avoid migration" t="15.384µs" Jul 21 12:37:09.888203 containerd[2389]: time="2026-07-21T12:37:09.888144018Z" level=info msg="loading plugin" id=io.containerd.content.v1.content type=io.containerd.content.v1 Jul 21 12:37:09.888289 containerd[2389]: time="2026-07-21T12:37:09.888263838Z" level=info msg="loading plugin" id=io.containerd.image-verifier.v1.bindir type=io.containerd.image-verifier.v1 Jul 21 12:37:09.888333 containerd[2389]: time="2026-07-21T12:37:09.888301590Z" level=info msg="loading plugin" id=io.containerd.internal.v1.opt type=io.containerd.internal.v1 Jul 21 12:37:09.890019 containerd[2389]: time="2026-07-21T12:37:09.888595710Z" level=info msg="loading plugin" id=io.containerd.warning.v1.deprecations type=io.containerd.warning.v1 Jul 21 12:37:09.890019 containerd[2389]: time="2026-07-21T12:37:09.888647058Z" level=info msg="loading plugin" id=io.containerd.mount-handler.v1.erofs type=io.containerd.mount-handler.v1 Jul 21 12:37:09.890019 containerd[2389]: time="2026-07-21T12:37:09.888676950Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.blockfile type=io.containerd.snapshotter.v1 Jul 21 12:37:09.890019 containerd[2389]: time="2026-07-21T12:37:09.888799422Z" level=info msg="skip loading plugin" error="no scratch file generator: skip plugin" id=io.containerd.snapshotter.v1.blockfile type=io.containerd.snapshotter.v1 Jul 21 12:37:09.890019 containerd[2389]: time="2026-07-21T12:37:09.888854754Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.btrfs type=io.containerd.snapshotter.v1 Jul 21 12:37:09.890019 containerd[2389]: time="2026-07-21T12:37:09.889240638Z" level=info msg="skip loading plugin" error="path /var/lib/containerd/io.containerd.snapshotter.v1.btrfs (ext4) must be a btrfs filesystem to be used with the btrfs snapshotter: skip plugin" id=io.containerd.snapshotter.v1.btrfs type=io.containerd.snapshotter.v1 Jul 21 12:37:09.890019 containerd[2389]: time="2026-07-21T12:37:09.889280346Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.devmapper type=io.containerd.snapshotter.v1 Jul 21 12:37:09.890019 containerd[2389]: time="2026-07-21T12:37:09.889308438Z" level=info msg="skip loading plugin" error="devmapper not configured: skip plugin" id=io.containerd.snapshotter.v1.devmapper type=io.containerd.snapshotter.v1 Jul 21 12:37:09.890019 containerd[2389]: time="2026-07-21T12:37:09.889328682Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.erofs type=io.containerd.snapshotter.v1 Jul 21 12:37:09.890019 containerd[2389]: time="2026-07-21T12:37:09.889681866Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.native type=io.containerd.snapshotter.v1 Jul 21 12:37:09.895107 containerd[2389]: time="2026-07-21T12:37:09.895044510Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.overlayfs type=io.containerd.snapshotter.v1 Jul 21 12:37:09.895889 containerd[2389]: time="2026-07-21T12:37:09.895472910Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.zfs type=io.containerd.snapshotter.v1 Jul 21 12:37:09.895889 containerd[2389]: time="2026-07-21T12:37:09.895550898Z" level=info msg="skip loading plugin" error="lstat /var/lib/containerd/io.containerd.snapshotter.v1.zfs: no such file or directory: skip plugin" id=io.containerd.snapshotter.v1.zfs type=io.containerd.snapshotter.v1 Jul 21 12:37:09.895889 containerd[2389]: time="2026-07-21T12:37:09.895578054Z" level=info msg="loading plugin" id=io.containerd.event.v1.exchange type=io.containerd.event.v1 Jul 21 12:37:09.898271 containerd[2389]: time="2026-07-21T12:37:09.898191654Z" level=info msg="loading plugin" id=io.containerd.monitor.task.v1.cgroups type=io.containerd.monitor.task.v1 Jul 21 12:37:09.903369 containerd[2389]: time="2026-07-21T12:37:09.903307770Z" level=info msg="loading plugin" id=io.containerd.metadata.v1.bolt type=io.containerd.metadata.v1 Jul 21 12:37:09.904265 containerd[2389]: time="2026-07-21T12:37:09.903500418Z" level=info msg="metadata content store policy set" policy=shared Jul 21 12:37:09.906563 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.2601 INFO [Registrar] Starting registrar module Jul 21 12:37:09.906563 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.2653 INFO [EC2Identity] Checking disk for registration info Jul 21 12:37:09.906563 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.2654 INFO [EC2Identity] No registration info found for ec2 instance, attempting registration Jul 21 12:37:09.907626 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.2654 INFO [EC2Identity] Generating registration keypair Jul 21 12:37:09.907626 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.8037 INFO [EC2Identity] Checking write access before registering Jul 21 12:37:09.907626 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.8044 INFO [EC2Identity] Registering EC2 instance with Systems Manager Jul 21 12:37:09.908762 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.8732 INFO [EC2Identity] EC2 registration was successful. Jul 21 12:37:09.908762 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.8732 INFO [amazon-ssm-agent] Registration attempted. Resuming core agent startup. Jul 21 12:37:09.908762 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.8749 INFO [CredentialRefresher] credentialRefresher has started Jul 21 12:37:09.908762 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.8749 INFO [CredentialRefresher] Starting credentials refresher loop Jul 21 12:37:09.908762 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.9044 INFO EC2RoleProvider Successfully connected with instance profile role credentials Jul 21 12:37:09.908762 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.9063 INFO [CredentialRefresher] Credentials ready Jul 21 12:37:09.911086 containerd[2389]: time="2026-07-21T12:37:09.910965630Z" level=info msg="loading plugin" id=io.containerd.gc.v1.scheduler type=io.containerd.gc.v1 Jul 21 12:37:09.911086 containerd[2389]: time="2026-07-21T12:37:09.911066730Z" level=info msg="loading plugin" id=io.containerd.nri.v1.nri type=io.containerd.nri.v1 Jul 21 12:37:09.914969 containerd[2389]: time="2026-07-21T12:37:09.914913438Z" level=info msg="built-in NRI default validator is disabled" Jul 21 12:37:09.914969 containerd[2389]: time="2026-07-21T12:37:09.914958006Z" level=info msg="runtime interface created" Jul 21 12:37:09.914969 containerd[2389]: time="2026-07-21T12:37:09.914975094Z" level=info msg="created NRI interface" Jul 21 12:37:09.915133 containerd[2389]: time="2026-07-21T12:37:09.915003786Z" level=info msg="loading plugin" id=io.containerd.differ.v1.erofs type=io.containerd.differ.v1 Jul 21 12:37:09.924688 amazon-ssm-agent[2412]: 2026-07-21 12:37:09.9085 INFO [CredentialRefresher] Next credential rotation will be in 29.9999318502 minutes Jul 21 12:37:09.928127 containerd[2389]: time="2026-07-21T12:37:09.928056295Z" level=info msg="loading plugin" id=io.containerd.mount-manager.v1.bolt type=io.containerd.mount-manager.v1 Jul 21 12:37:09.930508 containerd[2389]: time="2026-07-21T12:37:09.930428023Z" level=info msg="loading plugin" id=io.containerd.differ.v1.walking type=io.containerd.differ.v1 Jul 21 12:37:09.930508 containerd[2389]: time="2026-07-21T12:37:09.930498007Z" level=info msg="loading plugin" id=io.containerd.lease.v1.manager type=io.containerd.lease.v1 Jul 21 12:37:09.930713 containerd[2389]: time="2026-07-21T12:37:09.930530251Z" level=info msg="loading plugin" id=io.containerd.service.v1.containers-service type=io.containerd.service.v1 Jul 21 12:37:09.930713 containerd[2389]: time="2026-07-21T12:37:09.930564403Z" level=info msg="loading plugin" id=io.containerd.service.v1.content-service type=io.containerd.service.v1 Jul 21 12:37:09.930713 containerd[2389]: time="2026-07-21T12:37:09.930589387Z" level=info msg="loading plugin" id=io.containerd.service.v1.diff-service type=io.containerd.service.v1 Jul 21 12:37:09.930713 containerd[2389]: time="2026-07-21T12:37:09.930616771Z" level=info msg="loading plugin" id=io.containerd.service.v1.images-service type=io.containerd.service.v1 Jul 21 12:37:09.930713 containerd[2389]: time="2026-07-21T12:37:09.930655015Z" level=info msg="loading plugin" id=io.containerd.service.v1.introspection-service type=io.containerd.service.v1 Jul 21 12:37:09.930713 containerd[2389]: time="2026-07-21T12:37:09.930686347Z" level=info msg="loading plugin" id=io.containerd.service.v1.namespaces-service type=io.containerd.service.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.930713251Z" level=info msg="loading plugin" id=io.containerd.service.v1.snapshots-service type=io.containerd.service.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.930737047Z" level=info msg="loading plugin" id=io.containerd.shim.v1.manager type=io.containerd.shim.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.930763039Z" level=info msg="loading plugin" id=io.containerd.runtime.v2.task type=io.containerd.runtime.v2 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932052787Z" level=info msg="loading plugin" id=io.containerd.service.v1.tasks-service type=io.containerd.service.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932108083Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.containers type=io.containerd.grpc.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932141035Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.content type=io.containerd.grpc.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932169103Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.diff type=io.containerd.grpc.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932196931Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.events type=io.containerd.grpc.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932229487Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.images type=io.containerd.grpc.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932258227Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.introspection type=io.containerd.grpc.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932284123Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.leases type=io.containerd.grpc.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932314003Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.mounts type=io.containerd.grpc.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932339635Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.namespaces type=io.containerd.grpc.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932368171Z" level=info msg="loading plugin" id=io.containerd.sandbox.store.v1.local type=io.containerd.sandbox.store.v1 Jul 21 12:37:09.932594 containerd[2389]: time="2026-07-21T12:37:09.932394559Z" level=info msg="loading plugin" id=io.containerd.transfer.v1.local type=io.containerd.transfer.v1 Jul 21 12:37:09.933263 containerd[2389]: time="2026-07-21T12:37:09.932457523Z" level=info msg="loading plugin" id=io.containerd.cri.v1.images type=io.containerd.cri.v1 Jul 21 12:37:09.937002 containerd[2389]: time="2026-07-21T12:37:09.936185551Z" level=info msg="Get image filesystem path \"/var/lib/containerd/io.containerd.snapshotter.v1.overlayfs\" for snapshotter \"overlayfs\"" Jul 21 12:37:09.937002 containerd[2389]: time="2026-07-21T12:37:09.936270019Z" level=info msg="Start snapshots syncer" Jul 21 12:37:09.938329 containerd[2389]: time="2026-07-21T12:37:09.937348003Z" level=info msg="loading plugin" id=io.containerd.cri.v1.runtime type=io.containerd.cri.v1 Jul 21 12:37:09.940730 containerd[2389]: time="2026-07-21T12:37:09.940074955Z" level=info msg="starting cri plugin" config="{\"containerd\":{\"defaultRuntimeName\":\"runc\",\"runtimes\":{\"runc\":{\"runtimeType\":\"io.containerd.runc.v2\",\"runtimePath\":\"\",\"PodAnnotations\":null,\"ContainerAnnotations\":null,\"options\":{\"BinaryName\":\"\",\"CriuImagePath\":\"\",\"CriuWorkPath\":\"\",\"IoGid\":0,\"IoUid\":0,\"NoNewKeyring\":false,\"Root\":\"\",\"ShimCgroup\":\"\",\"SystemdCgroup\":true},\"privileged_without_host_devices\":false,\"privileged_without_host_devices_all_devices_allowed\":false,\"cgroupWritable\":false,\"baseRuntimeSpec\":\"\",\"cniConfDir\":\"\",\"cniMaxConfNum\":0,\"snapshotter\":\"\",\"sandboxer\":\"podsandbox\",\"io_type\":\"\"}},\"ignoreBlockIONotEnabledErrors\":false,\"ignoreRdtNotEnabledErrors\":false},\"cni\":{\"binDir\":\"\",\"binDirs\":[\"/opt/cni/bin\"],\"confDir\":\"/etc/cni/net.d\",\"maxConfNum\":1,\"setupSerially\":false,\"confTemplate\":\"\",\"ipPref\":\"\",\"useInternalLoopback\":false},\"enableSelinux\":true,\"selinuxCategoryRange\":1024,\"maxContainerLogLineSize\":16384,\"disableApparmor\":false,\"restrictOOMScoreAdj\":false,\"disableProcMount\":false,\"unsetSeccompProfile\":\"\",\"tolerateMissingHugetlbController\":true,\"disableHugetlbController\":true,\"device_ownership_from_security_context\":false,\"ignoreImageDefinedVolumes\":false,\"netnsMountsUnderStateDir\":false,\"enableUnprivilegedPorts\":true,\"enableUnprivilegedICMP\":true,\"enableCDI\":true,\"cdiSpecDirs\":[\"/etc/cdi\",\"/var/run/cdi\"],\"drainExecSyncIOTimeout\":\"0s\",\"ignoreDeprecationWarnings\":null,\"containerdRootDir\":\"/var/lib/containerd\",\"containerdEndpoint\":\"/run/containerd/containerd.sock\",\"rootDir\":\"/var/lib/containerd/io.containerd.grpc.v1.cri\",\"stateDir\":\"/run/containerd/io.containerd.grpc.v1.cri\"}" Jul 21 12:37:09.942474 containerd[2389]: time="2026-07-21T12:37:09.941123911Z" level=info msg="loading plugin" id=io.containerd.podsandbox.controller.v1.podsandbox type=io.containerd.podsandbox.controller.v1 Jul 21 12:37:09.942474 containerd[2389]: time="2026-07-21T12:37:09.941577499Z" level=info msg="loading plugin" id=io.containerd.sandbox.controller.v1.shim type=io.containerd.sandbox.controller.v1 Jul 21 12:37:09.945883 containerd[2389]: time="2026-07-21T12:37:09.945495847Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.sandbox-controllers type=io.containerd.grpc.v1 Jul 21 12:37:09.945883 containerd[2389]: time="2026-07-21T12:37:09.945571039Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.sandboxes type=io.containerd.grpc.v1 Jul 21 12:37:09.945883 containerd[2389]: time="2026-07-21T12:37:09.945602299Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.snapshots type=io.containerd.grpc.v1 Jul 21 12:37:09.945883 containerd[2389]: time="2026-07-21T12:37:09.945628519Z" level=info msg="loading plugin" id=io.containerd.streaming.v1.manager type=io.containerd.streaming.v1 Jul 21 12:37:09.945883 containerd[2389]: time="2026-07-21T12:37:09.945655999Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.streaming type=io.containerd.grpc.v1 Jul 21 12:37:09.945883 containerd[2389]: time="2026-07-21T12:37:09.945685567Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.tasks type=io.containerd.grpc.v1 Jul 21 12:37:09.945883 containerd[2389]: time="2026-07-21T12:37:09.945714331Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.transfer type=io.containerd.grpc.v1 Jul 21 12:37:09.945883 containerd[2389]: time="2026-07-21T12:37:09.945743935Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.version type=io.containerd.grpc.v1 Jul 21 12:37:09.945883 containerd[2389]: time="2026-07-21T12:37:09.945767251Z" level=info msg="loading plugin" id=io.containerd.monitor.container.v1.restart type=io.containerd.monitor.container.v1 Jul 21 12:37:09.947983 containerd[2389]: time="2026-07-21T12:37:09.947928823Z" level=info msg="loading plugin" id=io.containerd.tracing.processor.v1.otlp type=io.containerd.tracing.processor.v1 Jul 21 12:37:09.948156 containerd[2389]: time="2026-07-21T12:37:09.947992975Z" level=info msg="skip loading plugin" error="skip plugin: tracing endpoint not configured" id=io.containerd.tracing.processor.v1.otlp type=io.containerd.tracing.processor.v1 Jul 21 12:37:09.948156 containerd[2389]: time="2026-07-21T12:37:09.948018163Z" level=info msg="loading plugin" id=io.containerd.internal.v1.tracing type=io.containerd.internal.v1 Jul 21 12:37:09.948156 containerd[2389]: time="2026-07-21T12:37:09.948042067Z" level=info msg="skip loading plugin" error="skip plugin: tracing endpoint not configured" id=io.containerd.internal.v1.tracing type=io.containerd.internal.v1 Jul 21 12:37:09.948156 containerd[2389]: time="2026-07-21T12:37:09.948067099Z" level=info msg="loading plugin" id=io.containerd.ttrpc.v1.otelttrpc type=io.containerd.ttrpc.v1 Jul 21 12:37:09.948156 containerd[2389]: time="2026-07-21T12:37:09.948092011Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.healthcheck type=io.containerd.grpc.v1 Jul 21 12:37:09.948156 containerd[2389]: time="2026-07-21T12:37:09.948120727Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.cri type=io.containerd.grpc.v1 Jul 21 12:37:09.948156 containerd[2389]: time="2026-07-21T12:37:09.948150751Z" level=info msg="Connect containerd service" Jul 21 12:37:09.948422 containerd[2389]: time="2026-07-21T12:37:09.948207739Z" level=info msg="using experimental NRI integration - disable nri plugin to prevent this" Jul 21 12:37:09.952069 containerd[2389]: time="2026-07-21T12:37:09.951984103Z" level=error msg="failed to load cni during init, please check CRI plugin status before setting up network for pods" error="cni config load failed: no network config found in /etc/cni/net.d: cni plugin not initialized: failed to load cni config" Jul 21 12:37:10.126996 tar[2367]: linux-arm64/README.md Jul 21 12:37:10.175887 systemd[1]: Finished prepare-helm.service - Unpack helm to /opt/bin. Jul 21 12:37:10.304282 containerd[2389]: time="2026-07-21T12:37:10.303589696Z" level=info msg="Start subscribing containerd event" Jul 21 12:37:10.304282 containerd[2389]: time="2026-07-21T12:37:10.303699688Z" level=info msg="Start recovering state" Jul 21 12:37:10.304282 containerd[2389]: time="2026-07-21T12:37:10.303923752Z" level=info msg="Start event monitor" Jul 21 12:37:10.304282 containerd[2389]: time="2026-07-21T12:37:10.303977032Z" level=info msg="Start cni network conf syncer for default" Jul 21 12:37:10.304282 containerd[2389]: time="2026-07-21T12:37:10.303997768Z" level=info msg="Start streaming server" Jul 21 12:37:10.304282 containerd[2389]: time="2026-07-21T12:37:10.304065460Z" level=info msg="Registered namespace \"k8s.io\" with NRI" Jul 21 12:37:10.304282 containerd[2389]: time="2026-07-21T12:37:10.304085356Z" level=info msg="runtime interface starting up..." Jul 21 12:37:10.304282 containerd[2389]: time="2026-07-21T12:37:10.304100116Z" level=info msg="starting plugins..." Jul 21 12:37:10.304282 containerd[2389]: time="2026-07-21T12:37:10.304156636Z" level=info msg="Synchronizing NRI (plugin) with current runtime state" Jul 21 12:37:10.307533 containerd[2389]: time="2026-07-21T12:37:10.307106572Z" level=info msg=serving... address=/run/containerd/containerd.sock.ttrpc Jul 21 12:37:10.307533 containerd[2389]: time="2026-07-21T12:37:10.307239220Z" level=info msg=serving... address=/run/containerd/containerd.sock Jul 21 12:37:10.313224 containerd[2389]: time="2026-07-21T12:37:10.309334492Z" level=info msg="containerd successfully booted in 0.501600s" Jul 21 12:37:10.309945 systemd[1]: Started containerd.service - containerd container runtime. Jul 21 12:37:10.429393 sshd_keygen[2394]: ssh-keygen: generating new host keys: RSA ECDSA ED25519 Jul 21 12:37:10.477036 systemd[1]: Finished sshd-keygen.service - Generate sshd host keys. Jul 21 12:37:10.483379 systemd[1]: Starting issuegen.service - Generate /run/issue... Jul 21 12:37:10.519748 systemd[1]: issuegen.service: Deactivated successfully. Jul 21 12:37:10.521947 systemd[1]: Finished issuegen.service - Generate /run/issue. Jul 21 12:37:10.529459 systemd[1]: Starting systemd-user-sessions.service - Permit User Sessions... Jul 21 12:37:10.560926 systemd[1]: Finished systemd-user-sessions.service - Permit User Sessions. Jul 21 12:37:10.569597 systemd[1]: Started getty@tty1.service - Getty on tty1. Jul 21 12:37:10.576580 systemd[1]: Started serial-getty@ttyS0.service - Serial Getty on ttyS0. Jul 21 12:37:10.579955 systemd[1]: Reached target getty.target - Login Prompts. Jul 21 12:37:10.938468 amazon-ssm-agent[2412]: 2026-07-21 12:37:10.9383 INFO [amazon-ssm-agent] [LongRunningWorkerContainer] [WorkerProvider] Worker ssm-agent-worker is not running, starting worker process Jul 21 12:37:11.039540 amazon-ssm-agent[2412]: 2026-07-21 12:37:10.9400 INFO [amazon-ssm-agent] [LongRunningWorkerContainer] [WorkerProvider] Worker ssm-agent-worker (pid:2616) started Jul 21 12:37:11.140080 amazon-ssm-agent[2412]: 2026-07-21 12:37:10.9400 INFO [amazon-ssm-agent] [LongRunningWorkerContainer] Monitor long running worker health every 60 seconds Jul 21 12:37:13.100385 systemd[1]: Started kubelet.service - kubelet: The Kubernetes Node Agent. Jul 21 12:37:13.106935 systemd[1]: Reached target multi-user.target - Multi-User System. Jul 21 12:37:13.115056 systemd[1]: Startup finished in 3.894s (kernel) + 17.220s (initrd) + 18.390s (userspace) = 39.506s. Jul 21 12:37:13.119126 (kubelet)[2632]: kubelet.service: Referenced but unset environment variable evaluates to an empty string: KUBELET_EXTRA_ARGS, KUBELET_KUBEADM_ARGS Jul 21 12:37:13.742613 systemd[1]: Created slice system-sshd.slice - Slice /system/sshd. Jul 21 12:37:13.746060 systemd[1]: Started sshd@0-1-172.31.16.165:22-20.76.1.115:47424.service - OpenSSH per-connection server daemon (20.76.1.115:47424). Jul 21 12:37:14.494925 systemd-resolved[2038]: Clock change detected. Flushing caches. Jul 21 12:37:14.542567 sshd[2639]: Accepted publickey for core from 20.76.1.115 port 47424 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:37:14.547916 sshd-session[2639]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:37:14.569188 systemd[1]: Created slice user-500.slice - User Slice of UID 500. Jul 21 12:37:14.574716 systemd[1]: Starting user-runtime-dir@500.service - User Runtime Directory /run/user/500... Jul 21 12:37:14.594571 systemd-logind[2347]: New session '1' of user 'core' with class 'user' and type 'tty'. Jul 21 12:37:14.622790 systemd[1]: Finished user-runtime-dir@500.service - User Runtime Directory /run/user/500. Jul 21 12:37:14.627723 systemd[1]: Starting user@500.service - User Manager for UID 500... Jul 21 12:37:14.672278 (systemd)[2647]: pam_unix(systemd-user:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:37:14.677866 systemd-logind[2347]: New session '2' of user 'core' with class 'manager-early' and type 'unspecified'. Jul 21 12:37:14.829679 kubelet[2632]: E0721 12:37:14.829542 2632 run.go:72] "command failed" err="failed to load kubelet config file, path: /var/lib/kubelet/config.yaml, error: failed to load Kubelet config file /var/lib/kubelet/config.yaml, error failed to read kubelet config file \"/var/lib/kubelet/config.yaml\", error: open /var/lib/kubelet/config.yaml: no such file or directory" Jul 21 12:37:14.834253 systemd[1]: kubelet.service: Main process exited, code=exited, status=1/FAILURE Jul 21 12:37:14.834717 systemd[1]: kubelet.service: Failed with result 'exit-code'. Jul 21 12:37:14.835594 systemd[1]: kubelet.service: Consumed 1.349s CPU time over 7.526s wall clock time, 259.4M memory peak. Jul 21 12:37:15.162801 systemd[2647]: Queued start job for default target default.target. Jul 21 12:37:15.172246 systemd[2647]: Created slice app.slice - User Application Slice. Jul 21 12:37:15.172317 systemd[2647]: Started systemd-tmpfiles-clean.timer - Daily Cleanup of User's Temporary Directories. Jul 21 12:37:15.172353 systemd[2647]: Reached target machines.target - Virtual Machines and Containers. Jul 21 12:37:15.172460 systemd[2647]: Reached target paths.target - Paths. Jul 21 12:37:15.172529 systemd[2647]: Reached target timers.target - Timers. Jul 21 12:37:15.175025 systemd[2647]: Starting dbus.socket - D-Bus User Message Bus Socket... Jul 21 12:37:15.178613 systemd[2647]: Listening on systemd-ask-password.socket - Query the User Interactively for a Password. Jul 21 12:37:15.179053 systemd[2647]: Listening on systemd-importd.socket - Disk Image Download Service Socket. Jul 21 12:37:15.181167 systemd[2647]: Listening on systemd-journalctl.socket - Journal Log Access Socket. Jul 21 12:37:15.181830 systemd[2647]: Listening on systemd-machined.socket - Virtual Machine and Container Registration Service Socket. Jul 21 12:37:15.183602 systemd[2647]: Starting systemd-tmpfiles-setup.service - Create User Files and Directories... Jul 21 12:37:15.212708 systemd[2647]: Listening on dbus.socket - D-Bus User Message Bus Socket. Jul 21 12:37:15.212906 systemd[2647]: Reached target sockets.target - Sockets. Jul 21 12:37:15.218668 systemd[2647]: Finished systemd-tmpfiles-setup.service - Create User Files and Directories. Jul 21 12:37:15.219111 systemd[2647]: Reached target basic.target - Basic System. Jul 21 12:37:15.219405 systemd[2647]: Reached target default.target - Main User Target. Jul 21 12:37:15.219735 systemd[1]: Started user@500.service - User Manager for UID 500. Jul 21 12:37:15.221344 systemd[2647]: Startup finished in 529ms. Jul 21 12:37:15.224527 systemd[1]: Started session-1.scope - Session 1 of User core. Jul 21 12:37:15.740015 systemd[1]: Started sshd@1-4097-172.31.16.165:22-20.76.1.115:47436.service - OpenSSH per-connection server daemon (20.76.1.115:47436). Jul 21 12:37:16.609986 sshd[2662]: Accepted publickey for core from 20.76.1.115 port 47436 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:37:16.612657 sshd-session[2662]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:37:16.621318 systemd-logind[2347]: New session '3' of user 'core' with class 'user' and type 'tty'. Jul 21 12:37:16.631513 systemd[1]: Started session-3.scope - Session 3 of User core. Jul 21 12:37:17.095838 sshd[2666]: Connection closed by 20.76.1.115 port 47436 Jul 21 12:37:17.096805 sshd-session[2662]: pam_unix(sshd:session): session closed for user core Jul 21 12:37:17.102010 systemd[1]: session-3.scope: Deactivated successfully. Jul 21 12:37:17.104220 systemd[1]: sshd@1-4097-172.31.16.165:22-20.76.1.115:47436.service: Deactivated successfully. Jul 21 12:37:17.108421 systemd-logind[2347]: Session 3 logged out. Waiting for processes to exit. Jul 21 12:37:17.111566 systemd-logind[2347]: Removed session 3. Jul 21 12:37:17.264529 systemd[1]: Started sshd@2-2-172.31.16.165:22-20.76.1.115:47450.service - OpenSSH per-connection server daemon (20.76.1.115:47450). Jul 21 12:37:18.106976 sshd[2672]: Accepted publickey for core from 20.76.1.115 port 47450 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:37:18.109893 sshd-session[2672]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:37:18.120310 systemd-logind[2347]: New session '4' of user 'core' with class 'user' and type 'tty'. Jul 21 12:37:18.130590 systemd[1]: Started session-4.scope - Session 4 of User core. Jul 21 12:37:18.572043 sshd[2676]: Connection closed by 20.76.1.115 port 47450 Jul 21 12:37:18.573284 sshd-session[2672]: pam_unix(sshd:session): session closed for user core Jul 21 12:37:18.578773 systemd[1]: session-4.scope: Deactivated successfully. Jul 21 12:37:18.581022 systemd[1]: sshd@2-2-172.31.16.165:22-20.76.1.115:47450.service: Deactivated successfully. Jul 21 12:37:18.589763 systemd-logind[2347]: Session 4 logged out. Waiting for processes to exit. Jul 21 12:37:18.593610 systemd-logind[2347]: Removed session 4. Jul 21 12:37:18.743103 systemd[1]: Started sshd@3-3-172.31.16.165:22-20.76.1.115:47462.service - OpenSSH per-connection server daemon (20.76.1.115:47462). Jul 21 12:37:19.603253 sshd[2682]: Accepted publickey for core from 20.76.1.115 port 47462 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:37:19.605639 sshd-session[2682]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:37:19.613587 systemd-logind[2347]: New session '5' of user 'core' with class 'user' and type 'tty'. Jul 21 12:37:19.621497 systemd[1]: Started session-5.scope - Session 5 of User core. Jul 21 12:37:20.083552 sshd[2686]: Connection closed by 20.76.1.115 port 47462 Jul 21 12:37:20.083376 sshd-session[2682]: pam_unix(sshd:session): session closed for user core Jul 21 12:37:20.091149 systemd[1]: sshd@3-3-172.31.16.165:22-20.76.1.115:47462.service: Deactivated successfully. Jul 21 12:37:20.095739 systemd[1]: session-5.scope: Deactivated successfully. Jul 21 12:37:20.098871 systemd-logind[2347]: Session 5 logged out. Waiting for processes to exit. Jul 21 12:37:20.102669 systemd-logind[2347]: Removed session 5. Jul 21 12:37:20.267000 systemd[1]: Started sshd@4-4098-172.31.16.165:22-20.76.1.115:47474.service - OpenSSH per-connection server daemon (20.76.1.115:47474). Jul 21 12:37:21.152977 sshd[2692]: Accepted publickey for core from 20.76.1.115 port 47474 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:37:21.155921 sshd-session[2692]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:37:21.165359 systemd-logind[2347]: New session '6' of user 'core' with class 'user' and type 'tty'. Jul 21 12:37:21.174526 systemd[1]: Started session-6.scope - Session 6 of User core. Jul 21 12:37:21.505788 sudo[2697]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/setenforce 1 Jul 21 12:37:21.506515 sudo[2697]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Jul 21 12:37:21.518667 sudo[2697]: pam_unix(sudo:session): session closed for user root Jul 21 12:37:21.683766 sshd[2696]: Connection closed by 20.76.1.115 port 47474 Jul 21 12:37:21.683592 sshd-session[2692]: pam_unix(sshd:session): session closed for user core Jul 21 12:37:21.690099 systemd[1]: sshd@4-4098-172.31.16.165:22-20.76.1.115:47474.service: Deactivated successfully. Jul 21 12:37:21.694069 systemd[1]: session-6.scope: Deactivated successfully. Jul 21 12:37:21.697418 systemd-logind[2347]: Session 6 logged out. Waiting for processes to exit. Jul 21 12:37:21.699901 systemd-logind[2347]: Removed session 6. Jul 21 12:37:21.853462 systemd[1]: Started sshd@5-4099-172.31.16.165:22-20.76.1.115:37090.service - OpenSSH per-connection server daemon (20.76.1.115:37090). Jul 21 12:37:22.698901 sshd[2704]: Accepted publickey for core from 20.76.1.115 port 37090 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:37:22.701597 sshd-session[2704]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:37:22.709564 systemd-logind[2347]: New session '7' of user 'core' with class 'user' and type 'tty'. Jul 21 12:37:22.717510 systemd[1]: Started session-7.scope - Session 7 of User core. Jul 21 12:37:23.021405 sudo[2710]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/rm -rf /etc/audit/rules.d/80-selinux.rules /etc/audit/rules.d/99-default.rules Jul 21 12:37:23.022075 sudo[2710]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Jul 21 12:37:23.025169 sudo[2710]: pam_unix(sudo:session): session closed for user root Jul 21 12:37:23.037520 sudo[2709]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/systemctl restart audit-rules Jul 21 12:37:23.038143 sudo[2709]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Jul 21 12:37:23.052657 systemd[1]: Starting audit-rules.service - Load Audit Rules... Jul 21 12:37:23.111000 audit: CONFIG_CHANGE auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 op=remove_rule key=(null) list=5 res=1 Jul 21 12:37:23.111000 audit[2734]: SYSCALL arch=c00000b7 syscall=206 success=yes exit=1056 a0=3 a1=ffffcc9b7ee0 a2=420 a3=0 items=0 ppid=2715 pid=2734 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="auditctl" exe="/usr/bin/auditctl" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:23.116028 augenrules[2734]: No rules Jul 21 12:37:23.116421 kernel: audit: type=1305 audit(1784637443.111:166): auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 op=remove_rule key=(null) list=5 res=1 Jul 21 12:37:23.123137 systemd[1]: audit-rules.service: Deactivated successfully. Jul 21 12:37:23.111000 audit: PROCTITLE proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573 Jul 21 12:37:23.126004 kernel: audit: type=1300 audit(1784637443.111:166): arch=c00000b7 syscall=206 success=yes exit=1056 a0=3 a1=ffffcc9b7ee0 a2=420 a3=0 items=0 ppid=2715 pid=2734 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="auditctl" exe="/usr/bin/auditctl" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:23.125780 systemd[1]: Finished audit-rules.service - Load Audit Rules. Jul 21 12:37:23.126164 kernel: audit: type=1327 audit(1784637443.111:166): proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573 Jul 21 12:37:23.125000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=audit-rules comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:23.128688 sudo[2709]: pam_unix(sudo:session): session closed for user root Jul 21 12:37:23.132622 kernel: audit: type=1130 audit(1784637443.125:167): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=audit-rules comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:23.125000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=audit-rules comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:23.136787 kernel: audit: type=1131 audit(1784637443.125:168): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=audit-rules comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:23.127000 audit[2709]: AUDIT1106 pid=2709 uid=500 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:37:23.141303 kernel: audit: type=1106 audit(1784637443.127:169): pid=2709 uid=500 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:37:23.127000 audit[2709]: AUDIT1104 pid=2709 uid=500 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:37:23.145415 kernel: audit: type=1104 audit(1784637443.127:170): pid=2709 uid=500 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:37:23.285657 sshd[2708]: Connection closed by 20.76.1.115 port 37090 Jul 21 12:37:23.286849 sshd-session[2704]: pam_unix(sshd:session): session closed for user core Jul 21 12:37:23.286000 audit[2704]: AUDIT1106 pid=2704 uid=0 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:37:23.286000 audit[2704]: AUDIT1104 pid=2704 uid=0 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:37:23.300014 systemd[1]: sshd@5-4099-172.31.16.165:22-20.76.1.115:37090.service: Deactivated successfully. Jul 21 12:37:23.300256 kernel: audit: type=1106 audit(1784637443.286:171): pid=2704 uid=0 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:37:23.300326 kernel: audit: type=1104 audit(1784637443.286:172): pid=2704 uid=0 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:37:23.299000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@5-4099-172.31.16.165:22-20.76.1.115:37090 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:23.304259 systemd[1]: session-7.scope: Deactivated successfully. Jul 21 12:37:23.306010 kernel: audit: type=1131 audit(1784637443.299:173): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@5-4099-172.31.16.165:22-20.76.1.115:37090 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:23.307818 systemd-logind[2347]: Session 7 logged out. Waiting for processes to exit. Jul 21 12:37:23.310665 systemd-logind[2347]: Removed session 7. Jul 21 12:37:23.455014 systemd[1]: Started sshd@6-4100-172.31.16.165:22-20.76.1.115:37106.service - OpenSSH per-connection server daemon (20.76.1.115:37106). Jul 21 12:37:23.454000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@6-4100-172.31.16.165:22-20.76.1.115:37106 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:24.297000 audit[2743]: AUDIT1101 pid=2743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:37:24.299137 sshd[2743]: Accepted publickey for core from 20.76.1.115 port 37106 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:37:24.299000 audit[2743]: AUDIT1103 pid=2743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:37:24.299000 audit[2743]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=fffff9b1d1a0 a2=3 a3=0 items=0 ppid=1 pid=2743 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=8 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:24.299000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:37:24.301990 sshd-session[2743]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:37:24.311876 systemd-logind[2347]: New session '8' of user 'core' with class 'user' and type 'tty'. Jul 21 12:37:24.314521 systemd[1]: Started session-8.scope - Session 8 of User core. Jul 21 12:37:24.318000 audit[2743]: AUDIT1105 pid=2743 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:37:24.322000 audit[2747]: AUDIT1103 pid=2747 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:37:24.621668 sudo[2748]: core : PWD=/home/core ; USER=root ; COMMAND=/home/core/install.sh Jul 21 12:37:24.620000 audit[2748]: AUDIT1101 pid=2748 uid=500 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:37:24.620000 audit[2748]: AUDIT1110 pid=2748 uid=500 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:37:24.623121 sudo[2748]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Jul 21 12:37:24.622000 audit[2748]: AUDIT1105 pid=2748 uid=500 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:37:24.850891 systemd[1]: kubelet.service: Scheduled restart job, restart counter is at 1. Jul 21 12:37:24.853634 systemd[1]: Starting kubelet.service - kubelet: The Kubernetes Node Agent... Jul 21 12:37:25.336616 systemd[1]: Started kubelet.service - kubelet: The Kubernetes Node Agent. Jul 21 12:37:25.336000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:25.356726 (kubelet)[2775]: kubelet.service: Referenced but unset environment variable evaluates to an empty string: KUBELET_EXTRA_ARGS, KUBELET_KUBEADM_ARGS Jul 21 12:37:25.437743 kubelet[2775]: E0721 12:37:25.437059 2775 run.go:72] "command failed" err="failed to load kubelet config file, path: /var/lib/kubelet/config.yaml, error: failed to load Kubelet config file /var/lib/kubelet/config.yaml, error failed to read kubelet config file \"/var/lib/kubelet/config.yaml\", error: open /var/lib/kubelet/config.yaml: no such file or directory" Jul 21 12:37:25.447122 systemd[1]: kubelet.service: Main process exited, code=exited, status=1/FAILURE Jul 21 12:37:25.447605 systemd[1]: kubelet.service: Failed with result 'exit-code'. Jul 21 12:37:25.448000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' Jul 21 12:37:25.449511 systemd[1]: kubelet.service: Consumed 336ms CPU time over 10.610s wall clock time, 115.5M memory peak. Jul 21 12:37:25.603309 systemd[1]: Starting docker.service - Docker Application Container Engine... Jul 21 12:37:25.620825 (dockerd)[2782]: docker.service: Referenced but unset environment variable evaluates to an empty string: DOCKER_CGROUPS, DOCKER_OPTS, DOCKER_OPT_BIP, DOCKER_OPT_IPMASQ, DOCKER_OPT_MTU Jul 21 12:37:26.347032 dockerd[2782]: time="2026-07-21T12:37:26.346683410Z" level=info msg="Starting up" Jul 21 12:37:26.351960 dockerd[2782]: time="2026-07-21T12:37:26.351904514Z" level=info msg="OTEL tracing is not configured, using no-op tracer provider" Jul 21 12:37:26.352761 dockerd[2782]: time="2026-07-21T12:37:26.352721090Z" level=info msg="CDI directory does not exist, skipping: failed to monitor for changes: no such file or directory" dir=/var/run/cdi Jul 21 12:37:26.352932 dockerd[2782]: time="2026-07-21T12:37:26.352904750Z" level=info msg="CDI directory does not exist, skipping: failed to monitor for changes: no such file or directory" dir=/etc/cdi Jul 21 12:37:26.379625 dockerd[2782]: time="2026-07-21T12:37:26.379527639Z" level=info msg="Creating a containerd client" address=/var/run/docker/libcontainerd/docker-containerd.sock timeout=1m0s Jul 21 12:37:26.405331 dockerd[2782]: time="2026-07-21T12:37:26.405247563Z" level=info msg="Loading containers: start." Jul 21 12:37:26.405551 dockerd[2782]: time="2026-07-21T12:37:26.405524091Z" level=info msg="Starting daemon with containerd snapshotter integration enabled" Jul 21 12:37:26.421363 dockerd[2782]: time="2026-07-21T12:37:26.420969279Z" level=info msg="Restoring containers: start." Jul 21 12:37:26.473019 dockerd[2782]: time="2026-07-21T12:37:26.472963179Z" level=info msg="Deleting nftables IPv4 rules" error="exit status 1" Jul 21 12:37:26.479870 dockerd[2782]: time="2026-07-21T12:37:26.479815143Z" level=info msg="Deleting nftables IPv6 rules" error="exit status 1" Jul 21 12:37:26.555000 audit[2835]: NETFILTER_CFG table=nat:2 family=2 entries=2 op=nft_register_chain pid=2835 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.555000 audit[2835]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=116 a0=3 a1=ffffe78fe330 a2=0 a3=0 items=0 ppid=2782 pid=2835 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.555000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D4E00444F434B4552 Jul 21 12:37:26.559000 audit[2837]: NETFILTER_CFG table=filter:3 family=2 entries=2 op=nft_register_chain pid=2837 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.559000 audit[2837]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=124 a0=3 a1=ffffc7358b60 a2=0 a3=0 items=0 ppid=2782 pid=2837 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.559000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B4552 Jul 21 12:37:26.563000 audit[2839]: NETFILTER_CFG table=filter:4 family=2 entries=1 op=nft_register_chain pid=2839 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.563000 audit[2839]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffcad489b0 a2=0 a3=0 items=0 ppid=2782 pid=2839 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.563000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D464F5257415244 Jul 21 12:37:26.567000 audit[2841]: NETFILTER_CFG table=filter:5 family=2 entries=1 op=nft_register_chain pid=2841 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.567000 audit[2841]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffc0527a40 a2=0 a3=0 items=0 ppid=2782 pid=2841 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.567000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D425249444745 Jul 21 12:37:26.572000 audit[2843]: NETFILTER_CFG table=filter:6 family=2 entries=1 op=nft_register_chain pid=2843 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.572000 audit[2843]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=96 a0=3 a1=ffffdca4f620 a2=0 a3=0 items=0 ppid=2782 pid=2843 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.572000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D4354 Jul 21 12:37:26.576000 audit[2845]: NETFILTER_CFG table=filter:7 family=2 entries=1 op=nft_register_chain pid=2845 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.576000 audit[2845]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffc174d830 a2=0 a3=0 items=0 ppid=2782 pid=2845 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.576000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D494E5445524E414C Jul 21 12:37:26.581000 audit[2847]: NETFILTER_CFG table=nat:8 family=2 entries=2 op=nft_register_chain pid=2847 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.581000 audit[2847]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=384 a0=3 a1=fffff000e1f0 a2=0 a3=0 items=0 ppid=2782 pid=2847 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.581000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D4100505245524F5554494E47002D6D006164647274797065002D2D6473742D74797065004C4F43414C002D6A00444F434B4552 Jul 21 12:37:26.622000 audit[2850]: NETFILTER_CFG table=nat:9 family=2 entries=2 op=nft_register_chain pid=2850 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.622000 audit[2850]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=472 a0=3 a1=ffffe2669500 a2=0 a3=0 items=0 ppid=2782 pid=2850 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.622000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D41004F5554505554002D6D006164647274797065002D2D6473742D74797065004C4F43414C002D6A00444F434B45520000002D2D647374003132372E302E302E302F38 Jul 21 12:37:26.626000 audit[2852]: NETFILTER_CFG table=filter:10 family=2 entries=2 op=nft_register_chain pid=2852 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.626000 audit[2852]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=340 a0=3 a1=fffffc1b8220 a2=0 a3=0 items=0 ppid=2782 pid=2852 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.626000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4900464F5257415244002D6A00444F434B45522D464F5257415244 Jul 21 12:37:26.630000 audit[2854]: NETFILTER_CFG table=filter:11 family=2 entries=1 op=nft_register_rule pid=2854 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.630000 audit[2854]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=236 a0=3 a1=fffff8a27040 a2=0 a3=0 items=0 ppid=2782 pid=2854 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.630000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4900444F434B45522D464F5257415244002D6A00444F434B45522D425249444745 Jul 21 12:37:26.635000 audit[2856]: NETFILTER_CFG table=filter:12 family=2 entries=1 op=nft_register_rule pid=2856 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.635000 audit[2856]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=236 a0=3 a1=ffffd8cc22d0 a2=0 a3=0 items=0 ppid=2782 pid=2856 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.635000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4900444F434B45522D464F5257415244002D6A00444F434B45522D494E5445524E414C Jul 21 12:37:26.639000 audit[2858]: NETFILTER_CFG table=filter:13 family=2 entries=1 op=nft_register_rule pid=2858 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.639000 audit[2858]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=232 a0=3 a1=ffffe47ed300 a2=0 a3=0 items=0 ppid=2782 pid=2858 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.639000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4900444F434B45522D464F5257415244002D6A00444F434B45522D4354 Jul 21 12:37:26.716000 audit[2890]: NETFILTER_CFG table=nat:14 family=10 entries=2 op=nft_register_chain pid=2890 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.716000 audit[2890]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=116 a0=3 a1=ffffc34e5870 a2=0 a3=0 items=0 ppid=2782 pid=2890 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.716000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D74006E6174002D4E00444F434B4552 Jul 21 12:37:26.720000 audit[2892]: NETFILTER_CFG table=filter:15 family=10 entries=2 op=nft_register_chain pid=2892 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.720000 audit[2892]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=124 a0=3 a1=ffffdf5f1ff0 a2=0 a3=0 items=0 ppid=2782 pid=2892 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.720000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B4552 Jul 21 12:37:26.724000 audit[2894]: NETFILTER_CFG table=filter:16 family=10 entries=1 op=nft_register_chain pid=2894 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.724000 audit[2894]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=fffff19df6a0 a2=0 a3=0 items=0 ppid=2782 pid=2894 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.724000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D464F5257415244 Jul 21 12:37:26.727000 audit[2896]: NETFILTER_CFG table=filter:17 family=10 entries=1 op=nft_register_chain pid=2896 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.727000 audit[2896]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=fffffb5499a0 a2=0 a3=0 items=0 ppid=2782 pid=2896 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.727000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D425249444745 Jul 21 12:37:26.732000 audit[2898]: NETFILTER_CFG table=filter:18 family=10 entries=1 op=nft_register_chain pid=2898 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.732000 audit[2898]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=96 a0=3 a1=fffffa0081e0 a2=0 a3=0 items=0 ppid=2782 pid=2898 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.732000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D4354 Jul 21 12:37:26.736000 audit[2900]: NETFILTER_CFG table=filter:19 family=10 entries=1 op=nft_register_chain pid=2900 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.736000 audit[2900]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffde2bff80 a2=0 a3=0 items=0 ppid=2782 pid=2900 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.736000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D494E5445524E414C Jul 21 12:37:26.741000 audit[2902]: NETFILTER_CFG table=nat:20 family=10 entries=2 op=nft_register_chain pid=2902 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.741000 audit[2902]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=384 a0=3 a1=ffffe1061320 a2=0 a3=0 items=0 ppid=2782 pid=2902 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.741000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D74006E6174002D4100505245524F5554494E47002D6D006164647274797065002D2D6473742D74797065004C4F43414C002D6A00444F434B4552 Jul 21 12:37:26.745000 audit[2904]: NETFILTER_CFG table=nat:21 family=10 entries=2 op=nft_register_chain pid=2904 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.745000 audit[2904]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=484 a0=3 a1=ffffff96c820 a2=0 a3=0 items=0 ppid=2782 pid=2904 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.745000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D74006E6174002D41004F5554505554002D6D006164647274797065002D2D6473742D74797065004C4F43414C002D6A00444F434B45520000002D2D647374003A3A312F313238 Jul 21 12:37:26.749000 audit[2906]: NETFILTER_CFG table=filter:22 family=10 entries=2 op=nft_register_chain pid=2906 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.749000 audit[2906]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=340 a0=3 a1=ffffd6cc67e0 a2=0 a3=0 items=0 ppid=2782 pid=2906 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.749000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4900464F5257415244002D6A00444F434B45522D464F5257415244 Jul 21 12:37:26.753000 audit[2908]: NETFILTER_CFG table=filter:23 family=10 entries=1 op=nft_register_rule pid=2908 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.753000 audit[2908]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=236 a0=3 a1=ffffd97e8e00 a2=0 a3=0 items=0 ppid=2782 pid=2908 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.753000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4900444F434B45522D464F5257415244002D6A00444F434B45522D425249444745 Jul 21 12:37:26.757000 audit[2910]: NETFILTER_CFG table=filter:24 family=10 entries=1 op=nft_register_rule pid=2910 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.757000 audit[2910]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=236 a0=3 a1=fffff55f3c30 a2=0 a3=0 items=0 ppid=2782 pid=2910 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.757000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4900444F434B45522D464F5257415244002D6A00444F434B45522D494E5445524E414C Jul 21 12:37:26.762000 audit[2912]: NETFILTER_CFG table=filter:25 family=10 entries=1 op=nft_register_rule pid=2912 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.762000 audit[2912]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=232 a0=3 a1=fffff528d1b0 a2=0 a3=0 items=0 ppid=2782 pid=2912 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.762000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4900444F434B45522D464F5257415244002D6A00444F434B45522D4354 Jul 21 12:37:26.781554 kernel: Initializing XFRM netlink socket Jul 21 12:37:26.786000 audit[2918]: NETFILTER_CFG table=filter:26 family=2 entries=1 op=nft_register_chain pid=2918 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.786000 audit[2918]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=96 a0=3 a1=ffffd0f52260 a2=0 a3=0 items=0 ppid=2782 pid=2918 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.786000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D55534552 Jul 21 12:37:26.790000 audit[2920]: NETFILTER_CFG table=filter:27 family=2 entries=1 op=nft_register_rule pid=2920 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.790000 audit[2920]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=224 a0=3 a1=ffffe1c920c0 a2=0 a3=0 items=0 ppid=2782 pid=2920 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.790000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4900464F5257415244002D6A00444F434B45522D55534552 Jul 21 12:37:26.794000 audit[2922]: NETFILTER_CFG table=filter:28 family=10 entries=1 op=nft_register_chain pid=2922 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.794000 audit[2922]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=96 a0=3 a1=ffffe70d5d30 a2=0 a3=0 items=0 ppid=2782 pid=2922 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.794000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D55534552 Jul 21 12:37:26.798000 audit[2924]: NETFILTER_CFG table=filter:29 family=10 entries=1 op=nft_register_rule pid=2924 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:26.798000 audit[2924]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=224 a0=3 a1=ffffff57e760 a2=0 a3=0 items=0 ppid=2782 pid=2924 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.798000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4900464F5257415244002D6A00444F434B45522D55534552 Jul 21 12:37:26.822743 (udev-worker)[2807]: Network interface NamePolicy= disabled on kernel command line. Jul 21 12:37:26.834000 audit[2928]: NETFILTER_CFG table=nat:30 family=2 entries=2 op=nft_register_chain pid=2928 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.834000 audit[2928]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=520 a0=3 a1=fffff8dc9980 a2=0 a3=0 items=0 ppid=2782 pid=2928 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.834000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D4900504F5354524F5554494E47002D73003137322E31372E302E302F31360000002D6F00646F636B657230002D6A004D415351554552414445 Jul 21 12:37:26.855000 audit[2938]: NETFILTER_CFG table=filter:31 family=2 entries=1 op=nft_register_rule pid=2938 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.855000 audit[2938]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=300 a0=3 a1=fffff5f554d0 a2=0 a3=0 items=0 ppid=2782 pid=2938 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.855000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4100444F434B45522D464F5257415244002D6900646F636B657230002D6A00414343455054 Jul 21 12:37:26.873000 audit[2944]: NETFILTER_CFG table=filter:32 family=2 entries=1 op=nft_register_rule pid=2944 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.873000 audit[2944]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=376 a0=3 a1=ffffe52079e0 a2=0 a3=0 items=0 ppid=2782 pid=2944 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.873000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4100444F434B45520000002D6900646F636B657230002D6F00646F636B657230002D6A0044524F50 Jul 21 12:37:26.879000 audit[2946]: NETFILTER_CFG table=filter:33 family=2 entries=1 op=nft_register_rule pid=2946 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.879000 audit[2946]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=512 a0=3 a1=ffffe0ba3150 a2=0 a3=0 items=0 ppid=2782 pid=2946 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.879000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4100444F434B45522D4354002D6F00646F636B657230002D6D00636F6E6E747261636B002D2D637473746174650052454C415445442C45535441424C4953484544002D6A00414343455054 Jul 21 12:37:26.883000 audit[2948]: NETFILTER_CFG table=filter:34 family=2 entries=1 op=nft_register_rule pid=2948 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:26.883000 audit[2948]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=312 a0=3 a1=ffffec4a8810 a2=0 a3=0 items=0 ppid=2782 pid=2948 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:26.883000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4100444F434B45522D425249444745002D6F00646F636B657230002D6A00444F434B4552 Jul 21 12:37:26.886245 systemd-networkd[2075]: docker0: Link UP Jul 21 12:37:26.896227 dockerd[2782]: time="2026-07-21T12:37:26.896001257Z" level=info msg="Loading containers: done." Jul 21 12:37:26.919086 dockerd[2782]: time="2026-07-21T12:37:26.919037825Z" level=info msg="Docker daemon" commit=fbf3ed25f893e6ce21336f1101590e40a13934f4 containerd-snapshotter=true storage-driver=overlayfs version=29.1.3 Jul 21 12:37:26.923039 dockerd[2782]: time="2026-07-21T12:37:26.922713425Z" level=info msg="Initializing buildkit" Jul 21 12:37:26.973080 dockerd[2782]: time="2026-07-21T12:37:26.973030205Z" level=info msg="Completed buildkit initialization" Jul 21 12:37:26.982745 dockerd[2782]: time="2026-07-21T12:37:26.982674282Z" level=info msg="Daemon has completed initialization" Jul 21 12:37:26.984075 dockerd[2782]: time="2026-07-21T12:37:26.982783698Z" level=info msg="API listen on /run/docker.sock" Jul 21 12:37:26.983317 systemd[1]: Started docker.service - Docker Application Container Engine. Jul 21 12:37:26.982000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=docker comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:27.814144 containerd[2389]: time="2026-07-21T12:37:27.814090506Z" level=info msg="PullImage \"registry.k8s.io/kube-apiserver:v1.34.9\"" Jul 21 12:37:28.791270 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount2112061091.mount: Deactivated successfully. Jul 21 12:37:30.064311 containerd[2389]: time="2026-07-21T12:37:30.064243229Z" level=info msg="ImageCreate event name:\"registry.k8s.io/kube-apiserver:v1.34.9\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:30.066261 containerd[2389]: time="2026-07-21T12:37:30.066157073Z" level=info msg="stop pulling image registry.k8s.io/kube-apiserver:v1.34.9: active requests=0, bytes read=22793809" Jul 21 12:37:30.068243 containerd[2389]: time="2026-07-21T12:37:30.067799513Z" level=info msg="ImageCreate event name:\"sha256:36d79d8bed61e5ce4793ebad5b694768c768ea68a4b27ec4760fff5aebb969a9\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:30.073362 containerd[2389]: time="2026-07-21T12:37:30.073288109Z" level=info msg="ImageCreate event name:\"registry.k8s.io/kube-apiserver@sha256:c63e3de35256e066a9462c8783667e85e18833d0098ebc1669d3315079a30c39\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:30.076323 containerd[2389]: time="2026-07-21T12:37:30.075237653Z" level=info msg="Pulled image \"registry.k8s.io/kube-apiserver:v1.34.9\" with image id \"sha256:36d79d8bed61e5ce4793ebad5b694768c768ea68a4b27ec4760fff5aebb969a9\", repo tag \"registry.k8s.io/kube-apiserver:v1.34.9\", repo digest \"registry.k8s.io/kube-apiserver@sha256:c63e3de35256e066a9462c8783667e85e18833d0098ebc1669d3315079a30c39\", size \"24229872\" in 2.261086211s" Jul 21 12:37:30.076323 containerd[2389]: time="2026-07-21T12:37:30.075298289Z" level=info msg="PullImage \"registry.k8s.io/kube-apiserver:v1.34.9\" returns image reference \"sha256:36d79d8bed61e5ce4793ebad5b694768c768ea68a4b27ec4760fff5aebb969a9\"" Jul 21 12:37:30.076323 containerd[2389]: time="2026-07-21T12:37:30.075940061Z" level=info msg="PullImage \"registry.k8s.io/kube-controller-manager:v1.34.9\"" Jul 21 12:37:31.873952 containerd[2389]: time="2026-07-21T12:37:31.873562114Z" level=info msg="ImageCreate event name:\"registry.k8s.io/kube-controller-manager:v1.34.9\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:31.876093 containerd[2389]: time="2026-07-21T12:37:31.876029098Z" level=info msg="stop pulling image registry.k8s.io/kube-controller-manager:v1.34.9: active requests=1, bytes read=4194304" Jul 21 12:37:31.877117 containerd[2389]: time="2026-07-21T12:37:31.877081570Z" level=info msg="ImageCreate event name:\"sha256:9df7801454cb42f5f5df7279c0b718eafc2aead15d6a66817d3c7a827f1496b5\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:31.881776 containerd[2389]: time="2026-07-21T12:37:31.881715802Z" level=info msg="ImageCreate event name:\"registry.k8s.io/kube-controller-manager@sha256:5166aca14a5c126b2920b9b05fe21a254cd89e0748c520bb9009ae5b5971a200\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:31.884050 containerd[2389]: time="2026-07-21T12:37:31.883992814Z" level=info msg="Pulled image \"registry.k8s.io/kube-controller-manager:v1.34.9\" with image id \"sha256:9df7801454cb42f5f5df7279c0b718eafc2aead15d6a66817d3c7a827f1496b5\", repo tag \"registry.k8s.io/kube-controller-manager:v1.34.9\", repo digest \"registry.k8s.io/kube-controller-manager@sha256:5166aca14a5c126b2920b9b05fe21a254cd89e0748c520bb9009ae5b5971a200\", size \"20436198\" in 1.808010189s" Jul 21 12:37:31.884164 containerd[2389]: time="2026-07-21T12:37:31.884046046Z" level=info msg="PullImage \"registry.k8s.io/kube-controller-manager:v1.34.9\" returns image reference \"sha256:9df7801454cb42f5f5df7279c0b718eafc2aead15d6a66817d3c7a827f1496b5\"" Jul 21 12:37:31.884624 containerd[2389]: time="2026-07-21T12:37:31.884588266Z" level=info msg="PullImage \"registry.k8s.io/kube-scheduler:v1.34.9\"" Jul 21 12:37:33.374771 containerd[2389]: time="2026-07-21T12:37:33.374698965Z" level=info msg="ImageCreate event name:\"registry.k8s.io/kube-scheduler:v1.34.9\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:33.377889 containerd[2389]: time="2026-07-21T12:37:33.377802933Z" level=info msg="stop pulling image registry.k8s.io/kube-scheduler:v1.34.9: active requests=0, bytes read=0" Jul 21 12:37:33.379285 containerd[2389]: time="2026-07-21T12:37:33.379229289Z" level=info msg="ImageCreate event name:\"sha256:5c969680778fc67e4d31e26f5a4775f7f7e0a4d67b267b12613b23b6c5391fa2\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:33.384240 containerd[2389]: time="2026-07-21T12:37:33.383986761Z" level=info msg="ImageCreate event name:\"registry.k8s.io/kube-scheduler@sha256:79a157c52816760d4868db0ce1a2287dc82f19ca3f9e35da17a74a76c0a7fb4a\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:33.386324 containerd[2389]: time="2026-07-21T12:37:33.386089509Z" level=info msg="Pulled image \"registry.k8s.io/kube-scheduler:v1.34.9\" with image id \"sha256:5c969680778fc67e4d31e26f5a4775f7f7e0a4d67b267b12613b23b6c5391fa2\", repo tag \"registry.k8s.io/kube-scheduler:v1.34.9\", repo digest \"registry.k8s.io/kube-scheduler@sha256:79a157c52816760d4868db0ce1a2287dc82f19ca3f9e35da17a74a76c0a7fb4a\", size \"15584862\" in 1.500231571s" Jul 21 12:37:33.386324 containerd[2389]: time="2026-07-21T12:37:33.386143209Z" level=info msg="PullImage \"registry.k8s.io/kube-scheduler:v1.34.9\" returns image reference \"sha256:5c969680778fc67e4d31e26f5a4775f7f7e0a4d67b267b12613b23b6c5391fa2\"" Jul 21 12:37:33.387607 containerd[2389]: time="2026-07-21T12:37:33.387158469Z" level=info msg="PullImage \"registry.k8s.io/kube-proxy:v1.34.9\"" Jul 21 12:37:35.237050 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount2614914453.mount: Deactivated successfully. Jul 21 12:37:35.602010 systemd[1]: kubelet.service: Scheduled restart job, restart counter is at 2. Jul 21 12:37:35.606548 systemd[1]: Starting kubelet.service - kubelet: The Kubernetes Node Agent... Jul 21 12:37:35.698239 containerd[2389]: time="2026-07-21T12:37:35.697747801Z" level=info msg="ImageCreate event name:\"registry.k8s.io/kube-proxy:v1.34.9\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:35.700911 containerd[2389]: time="2026-07-21T12:37:35.700824745Z" level=info msg="stop pulling image registry.k8s.io/kube-proxy:v1.34.9: active requests=0, bytes read=0" Jul 21 12:37:35.702306 containerd[2389]: time="2026-07-21T12:37:35.702191569Z" level=info msg="ImageCreate event name:\"sha256:a5cdd9106d269cb9bba2168adc194eb2da1a4b8adad341e919f2295021606959\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:35.708311 containerd[2389]: time="2026-07-21T12:37:35.708178525Z" level=info msg="ImageCreate event name:\"registry.k8s.io/kube-proxy@sha256:501b4d94d65ada1d491869d96c6f0ea4deb5a4766a2986a8ec3ff9859160c964\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:35.710668 containerd[2389]: time="2026-07-21T12:37:35.710544037Z" level=info msg="Pulled image \"registry.k8s.io/kube-proxy:v1.34.9\" with image id \"sha256:a5cdd9106d269cb9bba2168adc194eb2da1a4b8adad341e919f2295021606959\", repo tag \"registry.k8s.io/kube-proxy:v1.34.9\", repo digest \"registry.k8s.io/kube-proxy@sha256:501b4d94d65ada1d491869d96c6f0ea4deb5a4766a2986a8ec3ff9859160c964\", size \"22633325\" in 2.323310028s" Jul 21 12:37:35.710668 containerd[2389]: time="2026-07-21T12:37:35.710608105Z" level=info msg="PullImage \"registry.k8s.io/kube-proxy:v1.34.9\" returns image reference \"sha256:a5cdd9106d269cb9bba2168adc194eb2da1a4b8adad341e919f2295021606959\"" Jul 21 12:37:35.711905 containerd[2389]: time="2026-07-21T12:37:35.711634945Z" level=info msg="PullImage \"registry.k8s.io/coredns/coredns:v1.12.1\"" Jul 21 12:37:35.972965 systemd[1]: Started kubelet.service - kubelet: The Kubernetes Node Agent. Jul 21 12:37:35.972000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:35.978592 kernel: kauditd_printk_skb: 113 callbacks suppressed Jul 21 12:37:35.978663 kernel: audit: type=1130 audit(1784637455.972:219): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:35.990176 (kubelet)[3051]: kubelet.service: Referenced but unset environment variable evaluates to an empty string: KUBELET_EXTRA_ARGS, KUBELET_KUBEADM_ARGS Jul 21 12:37:36.065109 kubelet[3051]: E0721 12:37:36.065014 3051 run.go:72] "command failed" err="failed to load kubelet config file, path: /var/lib/kubelet/config.yaml, error: failed to load Kubelet config file /var/lib/kubelet/config.yaml, error failed to read kubelet config file \"/var/lib/kubelet/config.yaml\", error: open /var/lib/kubelet/config.yaml: no such file or directory" Jul 21 12:37:36.069738 systemd[1]: kubelet.service: Main process exited, code=exited, status=1/FAILURE Jul 21 12:37:36.069990 systemd[1]: kubelet.service: Failed with result 'exit-code'. Jul 21 12:37:36.069000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' Jul 21 12:37:36.070986 systemd[1]: kubelet.service: Consumed 321ms CPU time over 10.619s wall clock time, 118.9M memory peak. Jul 21 12:37:36.077214 kernel: audit: type=1131 audit(1784637456.069:220): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' Jul 21 12:37:36.709011 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount1936586806.mount: Deactivated successfully. Jul 21 12:37:37.978822 containerd[2389]: time="2026-07-21T12:37:37.978754360Z" level=info msg="ImageCreate event name:\"registry.k8s.io/coredns/coredns:v1.12.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:37.981233 containerd[2389]: time="2026-07-21T12:37:37.980944084Z" level=info msg="stop pulling image registry.k8s.io/coredns/coredns:v1.12.1: active requests=1, bytes read=14680064" Jul 21 12:37:37.983876 containerd[2389]: time="2026-07-21T12:37:37.983803528Z" level=info msg="ImageCreate event name:\"sha256:138784d87c9c50f8e59412544da4cf4928d61ccbaf93b9f5898a3ba406871bfc\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:37.996140 containerd[2389]: time="2026-07-21T12:37:37.996041704Z" level=info msg="ImageCreate event name:\"registry.k8s.io/coredns/coredns@sha256:e8c262566636e6bc340ece6473b0eed193cad045384401529721ddbe6463d31c\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:38.004224 containerd[2389]: time="2026-07-21T12:37:38.004122756Z" level=info msg="Pulled image \"registry.k8s.io/coredns/coredns:v1.12.1\" with image id \"sha256:138784d87c9c50f8e59412544da4cf4928d61ccbaf93b9f5898a3ba406871bfc\", repo tag \"registry.k8s.io/coredns/coredns:v1.12.1\", repo digest \"registry.k8s.io/coredns/coredns@sha256:e8c262566636e6bc340ece6473b0eed193cad045384401529721ddbe6463d31c\", size \"20392204\" in 2.292434651s" Jul 21 12:37:38.004533 containerd[2389]: time="2026-07-21T12:37:38.004184472Z" level=info msg="PullImage \"registry.k8s.io/coredns/coredns:v1.12.1\" returns image reference \"sha256:138784d87c9c50f8e59412544da4cf4928d61ccbaf93b9f5898a3ba406871bfc\"" Jul 21 12:37:38.005096 containerd[2389]: time="2026-07-21T12:37:38.004996272Z" level=info msg="PullImage \"registry.k8s.io/pause:3.10.1\"" Jul 21 12:37:38.848175 systemd[1]: systemd-hostnamed.service: Deactivated successfully. Jul 21 12:37:38.849000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-hostnamed comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:38.856447 kernel: audit: type=1131 audit(1784637458.849:221): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-hostnamed comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:38.868000 audit: BPF prog-id=35 op=UNLOAD Jul 21 12:37:38.871225 kernel: audit: type=1334 audit(1784637458.868:222): prog-id=35 op=UNLOAD Jul 21 12:37:38.938795 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount853835053.mount: Deactivated successfully. Jul 21 12:37:38.946980 containerd[2389]: time="2026-07-21T12:37:38.946905725Z" level=info msg="ImageCreate event name:\"registry.k8s.io/pause:3.10.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"} labels:{key:\"io.cri-containerd.pinned\" value:\"pinned\"}" Jul 21 12:37:38.948412 containerd[2389]: time="2026-07-21T12:37:38.948323621Z" level=info msg="stop pulling image registry.k8s.io/pause:3.10.1: active requests=0, bytes read=0" Jul 21 12:37:38.950411 containerd[2389]: time="2026-07-21T12:37:38.949691021Z" level=info msg="ImageCreate event name:\"sha256:d7b100cd9a77ba782c5e428c8dd5a1df4a1e79d4cb6294acd7d01290ab3babbd\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"} labels:{key:\"io.cri-containerd.pinned\" value:\"pinned\"}" Jul 21 12:37:38.953628 containerd[2389]: time="2026-07-21T12:37:38.953568605Z" level=info msg="ImageCreate event name:\"registry.k8s.io/pause@sha256:278fb9dbcca9518083ad1e11276933a2e96f23de604a3a08cc3c80002767d24c\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"} labels:{key:\"io.cri-containerd.pinned\" value:\"pinned\"}" Jul 21 12:37:38.955334 containerd[2389]: time="2026-07-21T12:37:38.955266881Z" level=info msg="Pulled image \"registry.k8s.io/pause:3.10.1\" with image id \"sha256:d7b100cd9a77ba782c5e428c8dd5a1df4a1e79d4cb6294acd7d01290ab3babbd\", repo tag \"registry.k8s.io/pause:3.10.1\", repo digest \"registry.k8s.io/pause@sha256:278fb9dbcca9518083ad1e11276933a2e96f23de604a3a08cc3c80002767d24c\", size \"267939\" in 950.213825ms" Jul 21 12:37:38.955464 containerd[2389]: time="2026-07-21T12:37:38.955330733Z" level=info msg="PullImage \"registry.k8s.io/pause:3.10.1\" returns image reference \"sha256:d7b100cd9a77ba782c5e428c8dd5a1df4a1e79d4cb6294acd7d01290ab3babbd\"" Jul 21 12:37:38.956063 containerd[2389]: time="2026-07-21T12:37:38.956008877Z" level=info msg="PullImage \"registry.k8s.io/etcd:3.6.5-0\"" Jul 21 12:37:40.166883 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount1221773584.mount: Deactivated successfully. Jul 21 12:37:41.281997 containerd[2389]: time="2026-07-21T12:37:41.281910881Z" level=info msg="ImageCreate event name:\"registry.k8s.io/etcd:3.6.5-0\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:41.285161 containerd[2389]: time="2026-07-21T12:37:41.284659133Z" level=info msg="stop pulling image registry.k8s.io/etcd:3.6.5-0: active requests=0, bytes read=8780561" Jul 21 12:37:41.287042 containerd[2389]: time="2026-07-21T12:37:41.286983941Z" level=info msg="ImageCreate event name:\"sha256:2c5f0dedd21c25ec3a6709934d22152d53ec50fe57b72d29e4450655e3d14d42\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:41.292452 containerd[2389]: time="2026-07-21T12:37:41.292388117Z" level=info msg="ImageCreate event name:\"registry.k8s.io/etcd@sha256:042ef9c02799eb9303abf1aa99b09f09d94b8ee3ba0c2dd3f42dc4e1d3dce534\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:37:41.294852 containerd[2389]: time="2026-07-21T12:37:41.294802901Z" level=info msg="Pulled image \"registry.k8s.io/etcd:3.6.5-0\" with image id \"sha256:2c5f0dedd21c25ec3a6709934d22152d53ec50fe57b72d29e4450655e3d14d42\", repo tag \"registry.k8s.io/etcd:3.6.5-0\", repo digest \"registry.k8s.io/etcd@sha256:042ef9c02799eb9303abf1aa99b09f09d94b8ee3ba0c2dd3f42dc4e1d3dce534\", size \"21136588\" in 2.338739736s" Jul 21 12:37:41.295032 containerd[2389]: time="2026-07-21T12:37:41.295002065Z" level=info msg="PullImage \"registry.k8s.io/etcd:3.6.5-0\" returns image reference \"sha256:2c5f0dedd21c25ec3a6709934d22152d53ec50fe57b72d29e4450655e3d14d42\"" Jul 21 12:37:46.102505 systemd[1]: kubelet.service: Scheduled restart job, restart counter is at 3. Jul 21 12:37:46.106572 systemd[1]: Starting kubelet.service - kubelet: The Kubernetes Node Agent... Jul 21 12:37:46.463573 systemd[1]: Started kubelet.service - kubelet: The Kubernetes Node Agent. Jul 21 12:37:46.462000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:46.471262 kernel: audit: type=1130 audit(1784637466.462:223): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:46.478185 (kubelet)[3208]: kubelet.service: Referenced but unset environment variable evaluates to an empty string: KUBELET_EXTRA_ARGS, KUBELET_KUBEADM_ARGS Jul 21 12:37:46.555601 kubelet[3208]: E0721 12:37:46.555537 3208 run.go:72] "command failed" err="failed to load kubelet config file, path: /var/lib/kubelet/config.yaml, error: failed to load Kubelet config file /var/lib/kubelet/config.yaml, error failed to read kubelet config file \"/var/lib/kubelet/config.yaml\", error: open /var/lib/kubelet/config.yaml: no such file or directory" Jul 21 12:37:46.562580 systemd[1]: kubelet.service: Main process exited, code=exited, status=1/FAILURE Jul 21 12:37:46.562995 systemd[1]: kubelet.service: Failed with result 'exit-code'. Jul 21 12:37:46.565345 systemd[1]: kubelet.service: Consumed 314ms CPU time over 10.492s wall clock time, 115.3M memory peak. Jul 21 12:37:46.564000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' Jul 21 12:37:46.571501 kernel: audit: type=1131 audit(1784637466.564:224): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' Jul 21 12:37:50.898111 systemd[1]: Stopped kubelet.service - kubelet: The Kubernetes Node Agent. Jul 21 12:37:50.899310 systemd[1]: kubelet.service: Consumed 314ms CPU time over 4.332s wall clock time, 115.3M memory peak. Jul 21 12:37:50.898000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:50.898000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:50.905293 systemd[1]: Starting kubelet.service - kubelet: The Kubernetes Node Agent... Jul 21 12:37:50.909225 kernel: audit: type=1130 audit(1784637470.898:225): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:50.909353 kernel: audit: type=1131 audit(1784637470.898:226): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:50.967070 systemd[1]: Reload requested from client PID 3223 ('systemctl') (unit session-8.scope)... Jul 21 12:37:50.967102 systemd[1]: Reloading... Jul 21 12:37:51.225809 zram_generator::config[3278]: No configuration found. Jul 21 12:37:51.876893 systemd[1]: Reloading finished in 909 ms. Jul 21 12:37:51.883000 audit: BPF prog-id=39 op=LOAD Jul 21 12:37:51.887265 kernel: audit: type=1334 audit(1784637471.883:227): prog-id=39 op=LOAD Jul 21 12:37:51.885000 audit: BPF prog-id=31 op=UNLOAD Jul 21 12:37:51.891225 kernel: audit: type=1334 audit(1784637471.885:228): prog-id=31 op=UNLOAD Jul 21 12:37:51.890000 audit: BPF prog-id=40 op=LOAD Jul 21 12:37:51.890000 audit: BPF prog-id=38 op=UNLOAD Jul 21 12:37:51.894880 kernel: audit: type=1334 audit(1784637471.890:229): prog-id=40 op=LOAD Jul 21 12:37:51.894932 kernel: audit: type=1334 audit(1784637471.890:230): prog-id=38 op=UNLOAD Jul 21 12:37:51.895000 audit: BPF prog-id=41 op=LOAD Jul 21 12:37:51.895000 audit: BPF prog-id=16 op=UNLOAD Jul 21 12:37:51.899425 kernel: audit: type=1334 audit(1784637471.895:231): prog-id=41 op=LOAD Jul 21 12:37:51.899471 kernel: audit: type=1334 audit(1784637471.895:232): prog-id=16 op=UNLOAD Jul 21 12:37:51.898000 audit: BPF prog-id=42 op=LOAD Jul 21 12:37:51.900936 kernel: audit: type=1334 audit(1784637471.898:233): prog-id=42 op=LOAD Jul 21 12:37:51.898000 audit: BPF prog-id=43 op=LOAD Jul 21 12:37:51.902472 kernel: audit: type=1334 audit(1784637471.898:234): prog-id=43 op=LOAD Jul 21 12:37:51.898000 audit: BPF prog-id=17 op=UNLOAD Jul 21 12:37:51.904017 kernel: audit: type=1334 audit(1784637471.898:235): prog-id=17 op=UNLOAD Jul 21 12:37:51.898000 audit: BPF prog-id=18 op=UNLOAD Jul 21 12:37:51.905567 kernel: audit: type=1334 audit(1784637471.898:236): prog-id=18 op=UNLOAD Jul 21 12:37:51.899000 audit: BPF prog-id=44 op=LOAD Jul 21 12:37:51.899000 audit: BPF prog-id=22 op=UNLOAD Jul 21 12:37:51.901000 audit: BPF prog-id=45 op=LOAD Jul 21 12:37:51.901000 audit: BPF prog-id=23 op=UNLOAD Jul 21 12:37:51.901000 audit: BPF prog-id=46 op=LOAD Jul 21 12:37:51.902000 audit: BPF prog-id=47 op=LOAD Jul 21 12:37:51.902000 audit: BPF prog-id=24 op=UNLOAD Jul 21 12:37:51.902000 audit: BPF prog-id=25 op=UNLOAD Jul 21 12:37:51.904000 audit: BPF prog-id=48 op=LOAD Jul 21 12:37:51.904000 audit: BPF prog-id=19 op=UNLOAD Jul 21 12:37:51.904000 audit: BPF prog-id=49 op=LOAD Jul 21 12:37:51.904000 audit: BPF prog-id=50 op=LOAD Jul 21 12:37:51.904000 audit: BPF prog-id=20 op=UNLOAD Jul 21 12:37:51.904000 audit: BPF prog-id=21 op=UNLOAD Jul 21 12:37:51.905000 audit: BPF prog-id=51 op=LOAD Jul 21 12:37:51.905000 audit: BPF prog-id=26 op=UNLOAD Jul 21 12:37:51.905000 audit: BPF prog-id=52 op=LOAD Jul 21 12:37:51.905000 audit: BPF prog-id=53 op=LOAD Jul 21 12:37:51.905000 audit: BPF prog-id=27 op=UNLOAD Jul 21 12:37:51.906000 audit: BPF prog-id=28 op=UNLOAD Jul 21 12:37:51.912000 audit: BPF prog-id=54 op=LOAD Jul 21 12:37:51.912000 audit: BPF prog-id=32 op=UNLOAD Jul 21 12:37:51.912000 audit: BPF prog-id=55 op=LOAD Jul 21 12:37:51.912000 audit: BPF prog-id=56 op=LOAD Jul 21 12:37:51.912000 audit: BPF prog-id=33 op=UNLOAD Jul 21 12:37:51.912000 audit: BPF prog-id=34 op=UNLOAD Jul 21 12:37:51.914000 audit: BPF prog-id=57 op=LOAD Jul 21 12:37:51.914000 audit: BPF prog-id=58 op=LOAD Jul 21 12:37:51.914000 audit: BPF prog-id=29 op=UNLOAD Jul 21 12:37:51.914000 audit: BPF prog-id=30 op=UNLOAD Jul 21 12:37:51.971049 systemd[1]: kubelet.service: Control process exited, code=killed, status=15/TERM Jul 21 12:37:51.970000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' Jul 21 12:37:51.971221 systemd[1]: kubelet.service: Failed with result 'signal'. Jul 21 12:37:51.971806 systemd[1]: Stopped kubelet.service - kubelet: The Kubernetes Node Agent. Jul 21 12:37:51.971897 systemd[1]: kubelet.service: Consumed 225ms CPU time over 1.066s wall clock time, 95.8M memory peak. Jul 21 12:37:51.974977 systemd[1]: Starting kubelet.service - kubelet: The Kubernetes Node Agent... Jul 21 12:37:52.344776 systemd[1]: Started kubelet.service - kubelet: The Kubernetes Node Agent. Jul 21 12:37:52.344000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:37:52.359159 (kubelet)[3339]: kubelet.service: Referenced but unset environment variable evaluates to an empty string: KUBELET_EXTRA_ARGS Jul 21 12:37:52.436966 kubelet[3339]: Flag --pod-infra-container-image has been deprecated, will be removed in 1.35. Image garbage collector will get sandbox image information from CRI. Jul 21 12:37:52.437386 kubelet[3339]: Flag --volume-plugin-dir has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/ for more information. Jul 21 12:37:52.438717 kubelet[3339]: I0721 12:37:52.438659 3339 server.go:213] "--pod-infra-container-image will not be pruned by the image garbage collector in kubelet and should also be set in the remote runtime" Jul 21 12:37:53.316074 kubelet[3339]: I0721 12:37:53.315724 3339 server.go:529] "Kubelet version" kubeletVersion="v1.34.4" Jul 21 12:37:53.316074 kubelet[3339]: I0721 12:37:53.315769 3339 server.go:531] "Golang settings" GOGC="" GOMAXPROCS="" GOTRACEBACK="" Jul 21 12:37:53.316074 kubelet[3339]: I0721 12:37:53.315814 3339 watchdog_linux.go:95] "Systemd watchdog is not enabled" Jul 21 12:37:53.316074 kubelet[3339]: I0721 12:37:53.315827 3339 watchdog_linux.go:137] "Systemd watchdog is not enabled or the interval is invalid, so health checking will not be started." Jul 21 12:37:53.316584 kubelet[3339]: I0721 12:37:53.316559 3339 server.go:956] "Client rotation is on, will bootstrap in background" Jul 21 12:37:53.327340 kubelet[3339]: E0721 12:37:53.327276 3339 certificate_manager.go:596] "Failed while requesting a signed certificate from the control plane" err="cannot create certificate signing request: Post \"https://172.31.16.165:6443/apis/certificates.k8s.io/v1/certificatesigningrequests\": dial tcp 172.31.16.165:6443: connect: connection refused" logger="kubernetes.io/kube-apiserver-client-kubelet.UnhandledError" Jul 21 12:37:53.329490 kubelet[3339]: I0721 12:37:53.329447 3339 dynamic_cafile_content.go:161] "Starting controller" name="client-ca-bundle::/etc/kubernetes/pki/ca.crt" Jul 21 12:37:53.337425 kubelet[3339]: I0721 12:37:53.337340 3339 server.go:1423] "Using cgroup driver setting received from the CRI runtime" cgroupDriver="systemd" Jul 21 12:37:53.344069 kubelet[3339]: I0721 12:37:53.344014 3339 server.go:781] "--cgroups-per-qos enabled, but --cgroup-root was not specified. Defaulting to /" Jul 21 12:37:53.344588 kubelet[3339]: I0721 12:37:53.344535 3339 container_manager_linux.go:270] "Container manager verified user specified cgroup-root exists" cgroupRoot=[] Jul 21 12:37:53.346256 kubelet[3339]: I0721 12:37:53.344590 3339 container_manager_linux.go:275] "Creating Container Manager object based on Node Config" nodeConfig={"NodeName":"ip-172-31-16-165","RuntimeCgroupsName":"","SystemCgroupsName":"","KubeletCgroupsName":"","KubeletOOMScoreAdj":-999,"ContainerRuntime":"","CgroupsPerQOS":true,"CgroupRoot":"/","CgroupDriver":"systemd","KubeletRootDir":"/var/lib/kubelet","ProtectKernelDefaults":false,"KubeReservedCgroupName":"","SystemReservedCgroupName":"","ReservedSystemCPUs":{},"EnforceNodeAllocatable":{"pods":{}},"KubeReserved":null,"SystemReserved":null,"HardEvictionThresholds":[{"Signal":"imagefs.available","Operator":"LessThan","Value":{"Quantity":null,"Percentage":0.15},"GracePeriod":0,"MinReclaim":null},{"Signal":"imagefs.inodesFree","Operator":"LessThan","Value":{"Quantity":null,"Percentage":0.05},"GracePeriod":0,"MinReclaim":null},{"Signal":"memory.available","Operator":"LessThan","Value":{"Quantity":"100Mi","Percentage":0},"GracePeriod":0,"MinReclaim":null},{"Signal":"nodefs.available","Operator":"LessThan","Value":{"Quantity":null,"Percentage":0.1},"GracePeriod":0,"MinReclaim":null},{"Signal":"nodefs.inodesFree","Operator":"LessThan","Value":{"Quantity":null,"Percentage":0.05},"GracePeriod":0,"MinReclaim":null}],"QOSReserved":{},"CPUManagerPolicy":"none","CPUManagerPolicyOptions":null,"TopologyManagerScope":"container","CPUManagerReconcilePeriod":10000000000,"MemoryManagerPolicy":"None","MemoryManagerReservedMemory":null,"PodPidsLimit":-1,"EnforceCPULimits":true,"CPUCFSQuotaPeriod":100000000,"TopologyManagerPolicy":"none","TopologyManagerPolicyOptions":null,"CgroupVersion":2} Jul 21 12:37:53.346256 kubelet[3339]: I0721 12:37:53.345229 3339 topology_manager.go:138] "Creating topology manager with none policy" Jul 21 12:37:53.346256 kubelet[3339]: I0721 12:37:53.345257 3339 container_manager_linux.go:306] "Creating device plugin manager" Jul 21 12:37:53.346256 kubelet[3339]: I0721 12:37:53.345442 3339 container_manager_linux.go:315] "Creating Dynamic Resource Allocation (DRA) manager" Jul 21 12:37:53.350060 kubelet[3339]: I0721 12:37:53.349933 3339 state_mem.go:36] "Initialized new in-memory state store" Jul 21 12:37:53.353539 kubelet[3339]: I0721 12:37:53.353478 3339 kubelet.go:475] "Attempting to sync node with API server" Jul 21 12:37:53.353539 kubelet[3339]: I0721 12:37:53.353537 3339 kubelet.go:376] "Adding static pod path" path="/etc/kubernetes/manifests" Jul 21 12:37:53.354860 kubelet[3339]: I0721 12:37:53.354767 3339 kubelet.go:387] "Adding apiserver pod source" Jul 21 12:37:53.354860 kubelet[3339]: I0721 12:37:53.354814 3339 apiserver.go:42] "Waiting for node sync before watching apiserver pods" Jul 21 12:37:53.355585 kubelet[3339]: E0721 12:37:53.355534 3339 reflector.go:205] "Failed to watch" err="failed to list *v1.Node: Get \"https://172.31.16.165:6443/api/v1/nodes?fieldSelector=metadata.name%3Dip-172-31-16-165&limit=500&resourceVersion=0\": dial tcp 172.31.16.165:6443: connect: connection refused" logger="UnhandledError" reflector="k8s.io/client-go/informers/factory.go:160" type="*v1.Node" Jul 21 12:37:53.359319 kubelet[3339]: E0721 12:37:53.359174 3339 reflector.go:205] "Failed to watch" err="failed to list *v1.Service: Get \"https://172.31.16.165:6443/api/v1/services?fieldSelector=spec.clusterIP%21%3DNone&limit=500&resourceVersion=0\": dial tcp 172.31.16.165:6443: connect: connection refused" logger="UnhandledError" reflector="k8s.io/client-go/informers/factory.go:160" type="*v1.Service" Jul 21 12:37:53.360512 kubelet[3339]: I0721 12:37:53.360258 3339 kuberuntime_manager.go:291] "Container runtime initialized" containerRuntime="containerd" version="v2.2.5" apiVersion="v1" Jul 21 12:37:53.361753 kubelet[3339]: I0721 12:37:53.361672 3339 kubelet.go:940] "Not starting ClusterTrustBundle informer because we are in static kubelet mode or the ClusterTrustBundleProjection featuregate is disabled" Jul 21 12:37:53.361895 kubelet[3339]: I0721 12:37:53.361875 3339 kubelet.go:964] "Not starting PodCertificateRequest manager because we are in static kubelet mode or the PodCertificateProjection feature gate is disabled" Jul 21 12:37:53.362100 kubelet[3339]: W0721 12:37:53.362081 3339 probe.go:272] Flexvolume plugin directory at /opt/libexec/kubernetes/kubelet-plugins/volume/exec/ does not exist. Recreating. Jul 21 12:37:53.371404 kubelet[3339]: I0721 12:37:53.371369 3339 server.go:1262] "Started kubelet" Jul 21 12:37:53.372226 kubelet[3339]: I0721 12:37:53.372149 3339 server.go:180] "Starting to listen" address="0.0.0.0" port=10250 Jul 21 12:37:53.373812 kubelet[3339]: I0721 12:37:53.373777 3339 server.go:310] "Adding debug handlers to kubelet server" Jul 21 12:37:53.378248 kubelet[3339]: I0721 12:37:53.377378 3339 ratelimit.go:56] "Setting rate limiting for endpoint" service="podresources" qps=100 burstTokens=10 Jul 21 12:37:53.378248 kubelet[3339]: I0721 12:37:53.377494 3339 server_v1.go:49] "podresources" method="list" useActivePods=true Jul 21 12:37:53.378248 kubelet[3339]: I0721 12:37:53.377980 3339 server.go:249] "Starting to serve the podresources API" endpoint="unix:/var/lib/kubelet/pod-resources/kubelet.sock" Jul 21 12:37:53.380736 kubelet[3339]: E0721 12:37:53.378507 3339 event.go:368] "Unable to write event (may retry after sleeping)" err="Post \"https://172.31.16.165:6443/api/v1/namespaces/default/events\": dial tcp 172.31.16.165:6443: connect: connection refused" event="&Event{ObjectMeta:{ip-172-31-16-165.18c44e539d248211 default 0 0001-01-01 00:00:00 +0000 UTC map[] map[] [] [] []},InvolvedObject:ObjectReference{Kind:Node,Namespace:,Name:ip-172-31-16-165,UID:ip-172-31-16-165,APIVersion:,ResourceVersion:,FieldPath:,},Reason:Starting,Message:Starting kubelet.,Source:EventSource{Component:kubelet,Host:ip-172-31-16-165,},FirstTimestamp:2026-07-21 12:37:53.371226641 +0000 UTC m=+1.005218142,LastTimestamp:2026-07-21 12:37:53.371226641 +0000 UTC m=+1.005218142,Count:1,Type:Normal,EventTime:0001-01-01 00:00:00 +0000 UTC,Series:nil,Action:,Related:nil,ReportingController:kubelet,ReportingInstance:ip-172-31-16-165,}" Jul 21 12:37:53.383541 kubelet[3339]: I0721 12:37:53.383481 3339 fs_resource_analyzer.go:67] "Starting FS ResourceAnalyzer" Jul 21 12:37:53.384577 kubelet[3339]: I0721 12:37:53.384401 3339 dynamic_serving_content.go:135] "Starting controller" name="kubelet-server-cert-files::/var/lib/kubelet/pki/kubelet.crt::/var/lib/kubelet/pki/kubelet.key" Jul 21 12:37:53.390629 kubelet[3339]: E0721 12:37:53.390575 3339 kubelet.go:1615] "Image garbage collection failed once. Stats initialization may not have completed yet" err="invalid capacity 0 on image filesystem" Jul 21 12:37:53.391997 kubelet[3339]: E0721 12:37:53.391951 3339 kubelet_node_status.go:404] "Error getting the current node from lister" err="node \"ip-172-31-16-165\" not found" Jul 21 12:37:53.392161 kubelet[3339]: I0721 12:37:53.392010 3339 volume_manager.go:313] "Starting Kubelet Volume Manager" Jul 21 12:37:53.393026 kubelet[3339]: I0721 12:37:53.392362 3339 desired_state_of_world_populator.go:146] "Desired state populator starts to run" Jul 21 12:37:53.393026 kubelet[3339]: I0721 12:37:53.392445 3339 reconciler.go:29] "Reconciler: start to sync state" Jul 21 12:37:53.393626 kubelet[3339]: E0721 12:37:53.393570 3339 reflector.go:205] "Failed to watch" err="failed to list *v1.CSIDriver: Get \"https://172.31.16.165:6443/apis/storage.k8s.io/v1/csidrivers?limit=500&resourceVersion=0\": dial tcp 172.31.16.165:6443: connect: connection refused" logger="UnhandledError" reflector="k8s.io/client-go/informers/factory.go:160" type="*v1.CSIDriver" Jul 21 12:37:53.394668 kubelet[3339]: I0721 12:37:53.394316 3339 factory.go:221] Registration of the crio container factory failed: Get "http://%2Fvar%2Frun%2Fcrio%2Fcrio.sock/info": dial unix /var/run/crio/crio.sock: connect: no such file or directory Jul 21 12:37:53.396795 kubelet[3339]: I0721 12:37:53.396743 3339 factory.go:223] Registration of the containerd container factory successfully Jul 21 12:37:53.396795 kubelet[3339]: I0721 12:37:53.396782 3339 factory.go:223] Registration of the systemd container factory successfully Jul 21 12:37:53.398000 audit[3355]: NETFILTER_CFG table=mangle:35 family=2 entries=2 op=nft_register_chain pid=3355 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:53.398000 audit[3355]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=136 a0=3 a1=fffffcbcf820 a2=0 a3=0 items=0 ppid=3339 pid=3355 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.398000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D49505441424C45532D48494E54002D74006D616E676C65 Jul 21 12:37:53.401000 audit[3356]: NETFILTER_CFG table=filter:36 family=2 entries=1 op=nft_register_chain pid=3356 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:53.401000 audit[3356]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=fffffe1e5ac0 a2=0 a3=0 items=0 ppid=3339 pid=3356 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.401000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D4649524557414C4C002D740066696C746572 Jul 21 12:37:53.406000 audit[3358]: NETFILTER_CFG table=filter:37 family=2 entries=2 op=nft_register_chain pid=3358 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:53.406000 audit[3358]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=340 a0=3 a1=ffffc7938ef0 a2=0 a3=0 items=0 ppid=3339 pid=3358 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.406000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D49004F5554505554002D740066696C746572002D6A004B5542452D4649524557414C4C Jul 21 12:37:53.411000 audit[3360]: NETFILTER_CFG table=filter:38 family=2 entries=2 op=nft_register_chain pid=3360 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:53.411000 audit[3360]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=340 a0=3 a1=ffffdff7ca00 a2=0 a3=0 items=0 ppid=3339 pid=3360 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.411000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4900494E505554002D740066696C746572002D6A004B5542452D4649524557414C4C Jul 21 12:37:53.429128 kubelet[3339]: E0721 12:37:53.428186 3339 controller.go:145] "Failed to ensure lease exists, will retry" err="Get \"https://172.31.16.165:6443/apis/coordination.k8s.io/v1/namespaces/kube-node-lease/leases/ip-172-31-16-165?timeout=10s\": dial tcp 172.31.16.165:6443: connect: connection refused" interval="200ms" Jul 21 12:37:53.433000 audit[3364]: NETFILTER_CFG table=filter:39 family=2 entries=1 op=nft_register_rule pid=3364 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:53.433000 audit[3364]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=924 a0=3 a1=fffffec56560 a2=0 a3=0 items=0 ppid=3339 pid=3364 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.433000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D41004B5542452D4649524557414C4C002D740066696C746572002D6D00636F6D6D656E74002D2D636F6D6D656E7400626C6F636B20696E636F6D696E67206C6F63616C6E657420636F6E6E656374696F6E73002D2D647374003132372E302E302E302F380000002D2D737263003132372E Jul 21 12:37:53.441117 kubelet[3339]: I0721 12:37:53.440803 3339 kubelet_network_linux.go:54] "Initialized iptables rules." protocol="IPv4" Jul 21 12:37:53.443000 audit[3365]: NETFILTER_CFG table=mangle:40 family=10 entries=2 op=nft_register_chain pid=3365 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:53.443000 audit[3365]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=136 a0=3 a1=ffffc7353500 a2=0 a3=0 items=0 ppid=3339 pid=3365 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.443000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D49505441424C45532D48494E54002D74006D616E676C65 Jul 21 12:37:53.447682 kubelet[3339]: I0721 12:37:53.447636 3339 kubelet_network_linux.go:54] "Initialized iptables rules." protocol="IPv6" Jul 21 12:37:53.450346 kubelet[3339]: I0721 12:37:53.450304 3339 status_manager.go:244] "Starting to sync pod status with apiserver" Jul 21 12:37:53.450914 kubelet[3339]: I0721 12:37:53.450876 3339 kubelet.go:2428] "Starting kubelet main sync loop" Jul 21 12:37:53.450000 audit[3366]: NETFILTER_CFG table=mangle:41 family=2 entries=1 op=nft_register_chain pid=3366 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:53.450000 audit[3366]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=104 a0=3 a1=ffffea0f6090 a2=0 a3=0 items=0 ppid=3339 pid=3366 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.450000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D4B5542454C45542D43414E415259002D74006D616E676C65 Jul 21 12:37:53.451000 audit[3370]: NETFILTER_CFG table=mangle:42 family=10 entries=1 op=nft_register_chain pid=3370 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:53.451000 audit[3370]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=104 a0=3 a1=ffffdc3ca6e0 a2=0 a3=0 items=0 ppid=3339 pid=3370 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.451000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D4B5542454C45542D43414E415259002D74006D616E676C65 Jul 21 12:37:53.455620 kubelet[3339]: E0721 12:37:53.455546 3339 kubelet.go:2452] "Skipping pod synchronization" err="[container runtime status check may not have completed yet, PLEG is not healthy: pleg has yet to be successful]" Jul 21 12:37:53.457027 kubelet[3339]: E0721 12:37:53.456576 3339 reflector.go:205] "Failed to watch" err="failed to list *v1.RuntimeClass: Get \"https://172.31.16.165:6443/apis/node.k8s.io/v1/runtimeclasses?limit=500&resourceVersion=0\": dial tcp 172.31.16.165:6443: connect: connection refused" logger="UnhandledError" reflector="k8s.io/client-go/informers/factory.go:160" type="*v1.RuntimeClass" Jul 21 12:37:53.457000 audit[3372]: NETFILTER_CFG table=nat:43 family=10 entries=1 op=nft_register_chain pid=3372 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:53.457000 audit[3372]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffe35e8a30 a2=0 a3=0 items=0 ppid=3339 pid=3372 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.457000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D4B5542454C45542D43414E415259002D74006E6174 Jul 21 12:37:53.461000 audit[3373]: NETFILTER_CFG table=nat:44 family=2 entries=1 op=nft_register_chain pid=3373 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:53.461000 audit[3373]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffd1782690 a2=0 a3=0 items=0 ppid=3339 pid=3373 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.461000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D4B5542454C45542D43414E415259002D74006E6174 Jul 21 12:37:53.464000 audit[3374]: NETFILTER_CFG table=filter:45 family=10 entries=1 op=nft_register_chain pid=3374 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:37:53.464000 audit[3374]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=104 a0=3 a1=ffffc0f55310 a2=0 a3=0 items=0 ppid=3339 pid=3374 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.464000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D4B5542454C45542D43414E415259002D740066696C746572 Jul 21 12:37:53.468434 update_engine[2348]: I20260721 12:37:53.468348 2348 update_attempter.cc:509] Updating boot flags... Jul 21 12:37:53.469000 audit[3375]: NETFILTER_CFG table=filter:46 family=2 entries=1 op=nft_register_chain pid=3375 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:37:53.469000 audit[3375]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=104 a0=3 a1=ffffd9796cb0 a2=0 a3=0 items=0 ppid=3339 pid=3375 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:53.469000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D4B5542454C45542D43414E415259002D740066696C746572 Jul 21 12:37:53.474227 kubelet[3339]: I0721 12:37:53.473793 3339 cpu_manager.go:221] "Starting CPU manager" policy="none" Jul 21 12:37:53.474227 kubelet[3339]: I0721 12:37:53.474132 3339 cpu_manager.go:222] "Reconciling" reconcilePeriod="10s" Jul 21 12:37:53.474227 kubelet[3339]: I0721 12:37:53.474162 3339 state_mem.go:36] "Initialized new in-memory state store" Jul 21 12:37:53.479383 kubelet[3339]: I0721 12:37:53.479338 3339 policy_none.go:49] "None policy: Start" Jul 21 12:37:53.479383 kubelet[3339]: I0721 12:37:53.479385 3339 memory_manager.go:187] "Starting memorymanager" policy="None" Jul 21 12:37:53.479598 kubelet[3339]: I0721 12:37:53.479415 3339 state_mem.go:36] "Initializing new in-memory state store" logger="Memory Manager state checkpoint" Jul 21 12:37:53.482834 kubelet[3339]: I0721 12:37:53.482791 3339 policy_none.go:47] "Start" Jul 21 12:37:53.492819 kubelet[3339]: E0721 12:37:53.492765 3339 kubelet_node_status.go:404] "Error getting the current node from lister" err="node \"ip-172-31-16-165\" not found" Jul 21 12:37:53.504375 systemd[1]: Created slice kubepods.slice - libcontainer container kubepods.slice. Jul 21 12:37:53.529284 systemd[1]: Created slice kubepods-burstable.slice - libcontainer container kubepods-burstable.slice. Jul 21 12:37:53.537081 systemd[1]: Created slice kubepods-besteffort.slice - libcontainer container kubepods-besteffort.slice. Jul 21 12:37:53.549230 kubelet[3339]: E0721 12:37:53.548836 3339 manager.go:513] "Failed to read data from checkpoint" err="checkpoint is not found" checkpoint="kubelet_internal_checkpoint" Jul 21 12:37:53.549230 kubelet[3339]: I0721 12:37:53.549122 3339 eviction_manager.go:189] "Eviction manager: starting control loop" Jul 21 12:37:53.549230 kubelet[3339]: I0721 12:37:53.549141 3339 container_log_manager.go:146] "Initializing container log rotate workers" workers=1 monitorPeriod="10s" Jul 21 12:37:53.550332 kubelet[3339]: I0721 12:37:53.549899 3339 plugin_manager.go:118] "Starting Kubelet Plugin Manager" Jul 21 12:37:53.552188 kubelet[3339]: E0721 12:37:53.552138 3339 eviction_manager.go:267] "eviction manager: failed to check if we have separate container filesystem. Ignoring." err="no imagefs label for configured runtime" Jul 21 12:37:53.552362 kubelet[3339]: E0721 12:37:53.552244 3339 eviction_manager.go:292] "Eviction manager: failed to get summary stats" err="failed to get node info: node \"ip-172-31-16-165\" not found" Jul 21 12:37:53.582188 systemd[1]: Created slice kubepods-burstable-pod070e974c580b4b82d9462a1a67e7f1dc.slice - libcontainer container kubepods-burstable-pod070e974c580b4b82d9462a1a67e7f1dc.slice. Jul 21 12:37:53.596046 kubelet[3339]: E0721 12:37:53.595883 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:53.603074 systemd[1]: Created slice kubepods-burstable-podbe13b97079a2d26b51850bcc02ff8d64.slice - libcontainer container kubepods-burstable-podbe13b97079a2d26b51850bcc02ff8d64.slice. Jul 21 12:37:53.611086 kubelet[3339]: E0721 12:37:53.611026 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:53.613910 systemd[1]: Created slice kubepods-burstable-pod2cad5d234e9a82b90b8b7846ec7fa929.slice - libcontainer container kubepods-burstable-pod2cad5d234e9a82b90b8b7846ec7fa929.slice. Jul 21 12:37:53.618530 kubelet[3339]: E0721 12:37:53.618496 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:53.629950 kubelet[3339]: E0721 12:37:53.629905 3339 controller.go:145] "Failed to ensure lease exists, will retry" err="Get \"https://172.31.16.165:6443/apis/coordination.k8s.io/v1/namespaces/kube-node-lease/leases/ip-172-31-16-165?timeout=10s\": dial tcp 172.31.16.165:6443: connect: connection refused" interval="400ms" Jul 21 12:37:53.652721 kubelet[3339]: I0721 12:37:53.652688 3339 kubelet_node_status.go:75] "Attempting to register node" node="ip-172-31-16-165" Jul 21 12:37:53.653587 kubelet[3339]: E0721 12:37:53.653524 3339 kubelet_node_status.go:107] "Unable to register node with API server" err="Post \"https://172.31.16.165:6443/api/v1/nodes\": dial tcp 172.31.16.165:6443: connect: connection refused" node="ip-172-31-16-165" Jul 21 12:37:53.694011 kubelet[3339]: I0721 12:37:53.693950 3339 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kubeconfig\" (UniqueName: \"kubernetes.io/host-path/070e974c580b4b82d9462a1a67e7f1dc-kubeconfig\") pod \"kube-scheduler-ip-172-31-16-165\" (UID: \"070e974c580b4b82d9462a1a67e7f1dc\") " pod="kube-system/kube-scheduler-ip-172-31-16-165" Jul 21 12:37:53.694144 kubelet[3339]: I0721 12:37:53.694013 3339 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"k8s-certs\" (UniqueName: \"kubernetes.io/host-path/2cad5d234e9a82b90b8b7846ec7fa929-k8s-certs\") pod \"kube-apiserver-ip-172-31-16-165\" (UID: \"2cad5d234e9a82b90b8b7846ec7fa929\") " pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:37:53.694144 kubelet[3339]: I0721 12:37:53.694054 3339 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"usr-share-ca-certificates\" (UniqueName: \"kubernetes.io/host-path/2cad5d234e9a82b90b8b7846ec7fa929-usr-share-ca-certificates\") pod \"kube-apiserver-ip-172-31-16-165\" (UID: \"2cad5d234e9a82b90b8b7846ec7fa929\") " pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:37:53.694144 kubelet[3339]: I0721 12:37:53.694096 3339 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"ca-certs\" (UniqueName: \"kubernetes.io/host-path/be13b97079a2d26b51850bcc02ff8d64-ca-certs\") pod \"kube-controller-manager-ip-172-31-16-165\" (UID: \"be13b97079a2d26b51850bcc02ff8d64\") " pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:37:53.694144 kubelet[3339]: I0721 12:37:53.694134 3339 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"flexvolume-dir\" (UniqueName: \"kubernetes.io/host-path/be13b97079a2d26b51850bcc02ff8d64-flexvolume-dir\") pod \"kube-controller-manager-ip-172-31-16-165\" (UID: \"be13b97079a2d26b51850bcc02ff8d64\") " pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:37:53.694372 kubelet[3339]: I0721 12:37:53.694171 3339 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"k8s-certs\" (UniqueName: \"kubernetes.io/host-path/be13b97079a2d26b51850bcc02ff8d64-k8s-certs\") pod \"kube-controller-manager-ip-172-31-16-165\" (UID: \"be13b97079a2d26b51850bcc02ff8d64\") " pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:37:53.694372 kubelet[3339]: I0721 12:37:53.694259 3339 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"usr-share-ca-certificates\" (UniqueName: \"kubernetes.io/host-path/be13b97079a2d26b51850bcc02ff8d64-usr-share-ca-certificates\") pod \"kube-controller-manager-ip-172-31-16-165\" (UID: \"be13b97079a2d26b51850bcc02ff8d64\") " pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:37:53.694372 kubelet[3339]: I0721 12:37:53.694298 3339 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"ca-certs\" (UniqueName: \"kubernetes.io/host-path/2cad5d234e9a82b90b8b7846ec7fa929-ca-certs\") pod \"kube-apiserver-ip-172-31-16-165\" (UID: \"2cad5d234e9a82b90b8b7846ec7fa929\") " pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:37:53.694372 kubelet[3339]: I0721 12:37:53.694333 3339 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kubeconfig\" (UniqueName: \"kubernetes.io/host-path/be13b97079a2d26b51850bcc02ff8d64-kubeconfig\") pod \"kube-controller-manager-ip-172-31-16-165\" (UID: \"be13b97079a2d26b51850bcc02ff8d64\") " pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:37:53.856078 kubelet[3339]: I0721 12:37:53.856025 3339 kubelet_node_status.go:75] "Attempting to register node" node="ip-172-31-16-165" Jul 21 12:37:53.856679 kubelet[3339]: E0721 12:37:53.856623 3339 kubelet_node_status.go:107] "Unable to register node with API server" err="Post \"https://172.31.16.165:6443/api/v1/nodes\": dial tcp 172.31.16.165:6443: connect: connection refused" node="ip-172-31-16-165" Jul 21 12:37:53.901720 containerd[2389]: time="2026-07-21T12:37:53.901581379Z" level=info msg="RunPodSandbox for name:\"kube-scheduler-ip-172-31-16-165\" uid:\"070e974c580b4b82d9462a1a67e7f1dc\" namespace:\"kube-system\"" Jul 21 12:37:53.917554 containerd[2389]: time="2026-07-21T12:37:53.917346355Z" level=info msg="RunPodSandbox for name:\"kube-controller-manager-ip-172-31-16-165\" uid:\"be13b97079a2d26b51850bcc02ff8d64\" namespace:\"kube-system\"" Jul 21 12:37:53.925991 containerd[2389]: time="2026-07-21T12:37:53.925738135Z" level=info msg="RunPodSandbox for name:\"kube-apiserver-ip-172-31-16-165\" uid:\"2cad5d234e9a82b90b8b7846ec7fa929\" namespace:\"kube-system\"" Jul 21 12:37:53.951600 containerd[2389]: time="2026-07-21T12:37:53.951513643Z" level=info msg="connecting to shim 115c6d35035a0944d448195978ed9700305cc0123ed5f3143cfada96d1fc2e58" address="unix:///run/containerd/s/308e33583940f89b30cb6d8e3bd8ad44aca8ab5fdd14fda8a088bc7151055c7b" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:37:54.031903 kubelet[3339]: E0721 12:37:54.031182 3339 controller.go:145] "Failed to ensure lease exists, will retry" err="Get \"https://172.31.16.165:6443/apis/coordination.k8s.io/v1/namespaces/kube-node-lease/leases/ip-172-31-16-165?timeout=10s\": dial tcp 172.31.16.165:6443: connect: connection refused" interval="800ms" Jul 21 12:37:54.034998 containerd[2389]: time="2026-07-21T12:37:54.034927780Z" level=info msg="connecting to shim 5f00a266627b1d2c614a8525f8f40483b9e88b952546e7866af7460f7b4a6b0b" address="unix:///run/containerd/s/e1731909dfe263c02aa6cefa9dc786f89775012f0e5f5cf0be20af40511d6383" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:37:54.036900 systemd[1]: Started cri-containerd-115c6d35035a0944d448195978ed9700305cc0123ed5f3143cfada96d1fc2e58.scope - libcontainer container 115c6d35035a0944d448195978ed9700305cc0123ed5f3143cfada96d1fc2e58. Jul 21 12:37:54.046980 containerd[2389]: time="2026-07-21T12:37:54.046915732Z" level=info msg="connecting to shim c47a2792930df7d58fff0c1a69e873eae6b010cebad9550a9ef1d17464530fdb" address="unix:///run/containerd/s/b98a369f226ce3c41f6b280c8ef4a54361202d0dcef2a06492b2237f109c598b" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:37:54.097000 audit: BPF prog-id=59 op=LOAD Jul 21 12:37:54.098000 audit: BPF prog-id=60 op=LOAD Jul 21 12:37:54.098000 audit[3404]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=49279b931f90 a2=98 a3=0 items=0 ppid=3393 pid=3404 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.098000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3131356336643335303335613039343464343438313935393738656439 Jul 21 12:37:54.098000 audit: BPF prog-id=60 op=UNLOAD Jul 21 12:37:54.098000 audit[3404]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=3393 pid=3404 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.098000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3131356336643335303335613039343464343438313935393738656439 Jul 21 12:37:54.101000 audit: BPF prog-id=61 op=LOAD Jul 21 12:37:54.101000 audit[3404]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=49279b932268 a2=98 a3=0 items=0 ppid=3393 pid=3404 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.101000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3131356336643335303335613039343464343438313935393738656439 Jul 21 12:37:54.101000 audit: BPF prog-id=62 op=LOAD Jul 21 12:37:54.101000 audit[3404]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=49279b931fa8 a2=98 a3=0 items=0 ppid=3393 pid=3404 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.101000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3131356336643335303335613039343464343438313935393738656439 Jul 21 12:37:54.101000 audit: BPF prog-id=62 op=UNLOAD Jul 21 12:37:54.101000 audit[3404]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=3393 pid=3404 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.101000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3131356336643335303335613039343464343438313935393738656439 Jul 21 12:37:54.101000 audit: BPF prog-id=61 op=UNLOAD Jul 21 12:37:54.101000 audit[3404]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=3393 pid=3404 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.101000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3131356336643335303335613039343464343438313935393738656439 Jul 21 12:37:54.101000 audit: BPF prog-id=63 op=LOAD Jul 21 12:37:54.101000 audit[3404]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=49279b9324b8 a2=98 a3=0 items=0 ppid=3393 pid=3404 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.101000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3131356336643335303335613039343464343438313935393738656439 Jul 21 12:37:54.132191 systemd[1]: Started cri-containerd-5f00a266627b1d2c614a8525f8f40483b9e88b952546e7866af7460f7b4a6b0b.scope - libcontainer container 5f00a266627b1d2c614a8525f8f40483b9e88b952546e7866af7460f7b4a6b0b. Jul 21 12:37:54.154974 systemd[1]: Started cri-containerd-c47a2792930df7d58fff0c1a69e873eae6b010cebad9550a9ef1d17464530fdb.scope - libcontainer container c47a2792930df7d58fff0c1a69e873eae6b010cebad9550a9ef1d17464530fdb. Jul 21 12:37:54.200000 audit: BPF prog-id=64 op=LOAD Jul 21 12:37:54.205000 audit: BPF prog-id=65 op=LOAD Jul 21 12:37:54.205000 audit[3456]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=40ab2f05ff90 a2=98 a3=0 items=0 ppid=3426 pid=3456 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.205000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3566303061323636363237623164326336313461383532356638663430 Jul 21 12:37:54.206000 audit: BPF prog-id=65 op=UNLOAD Jul 21 12:37:54.206000 audit[3456]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=3426 pid=3456 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.206000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3566303061323636363237623164326336313461383532356638663430 Jul 21 12:37:54.209000 audit: BPF prog-id=66 op=LOAD Jul 21 12:37:54.209000 audit[3456]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=40ab2f060268 a2=98 a3=0 items=0 ppid=3426 pid=3456 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.209000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3566303061323636363237623164326336313461383532356638663430 Jul 21 12:37:54.210000 audit: BPF prog-id=67 op=LOAD Jul 21 12:37:54.210000 audit[3456]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=40ab2f05ffa8 a2=98 a3=0 items=0 ppid=3426 pid=3456 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.210000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3566303061323636363237623164326336313461383532356638663430 Jul 21 12:37:54.210000 audit: BPF prog-id=67 op=UNLOAD Jul 21 12:37:54.210000 audit[3456]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=3426 pid=3456 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.210000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3566303061323636363237623164326336313461383532356638663430 Jul 21 12:37:54.210000 audit: BPF prog-id=66 op=UNLOAD Jul 21 12:37:54.212497 containerd[2389]: time="2026-07-21T12:37:54.212377901Z" level=info msg="RunPodSandbox for name:\"kube-scheduler-ip-172-31-16-165\" uid:\"070e974c580b4b82d9462a1a67e7f1dc\" namespace:\"kube-system\" returns sandbox id \"115c6d35035a0944d448195978ed9700305cc0123ed5f3143cfada96d1fc2e58\"" Jul 21 12:37:54.210000 audit[3456]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=3426 pid=3456 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.210000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3566303061323636363237623164326336313461383532356638663430 Jul 21 12:37:54.211000 audit: BPF prog-id=68 op=LOAD Jul 21 12:37:54.211000 audit[3456]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=40ab2f0604b8 a2=98 a3=0 items=0 ppid=3426 pid=3456 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.211000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3566303061323636363237623164326336313461383532356638663430 Jul 21 12:37:54.223000 audit: BPF prog-id=69 op=LOAD Jul 21 12:37:54.225000 audit: BPF prog-id=70 op=LOAD Jul 21 12:37:54.225000 audit[3467]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=5f3664431f90 a2=98 a3=0 items=0 ppid=3439 pid=3467 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.225000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6334376132373932393330646637643538666666306331613639653837 Jul 21 12:37:54.225000 audit: BPF prog-id=70 op=UNLOAD Jul 21 12:37:54.225000 audit[3467]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=3439 pid=3467 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.225000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6334376132373932393330646637643538666666306331613639653837 Jul 21 12:37:54.225000 audit: BPF prog-id=71 op=LOAD Jul 21 12:37:54.225000 audit[3467]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=5f3664432268 a2=98 a3=0 items=0 ppid=3439 pid=3467 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.225000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6334376132373932393330646637643538666666306331613639653837 Jul 21 12:37:54.225000 audit: BPF prog-id=72 op=LOAD Jul 21 12:37:54.225000 audit[3467]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=5f3664431fa8 a2=98 a3=0 items=0 ppid=3439 pid=3467 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.225000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6334376132373932393330646637643538666666306331613639653837 Jul 21 12:37:54.226000 audit: BPF prog-id=72 op=UNLOAD Jul 21 12:37:54.226000 audit[3467]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=3439 pid=3467 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.226000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6334376132373932393330646637643538666666306331613639653837 Jul 21 12:37:54.226000 audit: BPF prog-id=71 op=UNLOAD Jul 21 12:37:54.226000 audit[3467]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=3439 pid=3467 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.226000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6334376132373932393330646637643538666666306331613639653837 Jul 21 12:37:54.226000 audit: BPF prog-id=73 op=LOAD Jul 21 12:37:54.226000 audit[3467]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=5f36644324b8 a2=98 a3=0 items=0 ppid=3439 pid=3467 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.226000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6334376132373932393330646637643538666666306331613639653837 Jul 21 12:37:54.237493 containerd[2389]: time="2026-07-21T12:37:54.237411857Z" level=info msg="CreateContainer within sandbox \"115c6d35035a0944d448195978ed9700305cc0123ed5f3143cfada96d1fc2e58\" for container name:\"kube-scheduler\"" Jul 21 12:37:54.280904 kubelet[3339]: I0721 12:37:54.280833 3339 kubelet_node_status.go:75] "Attempting to register node" node="ip-172-31-16-165" Jul 21 12:37:54.281416 kubelet[3339]: E0721 12:37:54.281354 3339 kubelet_node_status.go:107] "Unable to register node with API server" err="Post \"https://172.31.16.165:6443/api/v1/nodes\": dial tcp 172.31.16.165:6443: connect: connection refused" node="ip-172-31-16-165" Jul 21 12:37:54.307892 containerd[2389]: time="2026-07-21T12:37:54.307546037Z" level=info msg="RunPodSandbox for name:\"kube-apiserver-ip-172-31-16-165\" uid:\"2cad5d234e9a82b90b8b7846ec7fa929\" namespace:\"kube-system\" returns sandbox id \"5f00a266627b1d2c614a8525f8f40483b9e88b952546e7866af7460f7b4a6b0b\"" Jul 21 12:37:54.326528 containerd[2389]: time="2026-07-21T12:37:54.326457461Z" level=info msg="CreateContainer within sandbox \"5f00a266627b1d2c614a8525f8f40483b9e88b952546e7866af7460f7b4a6b0b\" for container name:\"kube-apiserver\"" Jul 21 12:37:54.328961 containerd[2389]: time="2026-07-21T12:37:54.328866293Z" level=info msg="CreateContainer within sandbox \"115c6d35035a0944d448195978ed9700305cc0123ed5f3143cfada96d1fc2e58\" for name:\"kube-scheduler\" returns container id \"262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584\"" Jul 21 12:37:54.330087 containerd[2389]: time="2026-07-21T12:37:54.329950421Z" level=info msg="StartContainer for \"262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584\"" Jul 21 12:37:54.332633 containerd[2389]: time="2026-07-21T12:37:54.332550869Z" level=info msg="connecting to shim 262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584" address="unix:///run/containerd/s/308e33583940f89b30cb6d8e3bd8ad44aca8ab5fdd14fda8a088bc7151055c7b" protocol=ttrpc version=3 Jul 21 12:37:54.360755 containerd[2389]: time="2026-07-21T12:37:54.360702726Z" level=info msg="RunPodSandbox for name:\"kube-controller-manager-ip-172-31-16-165\" uid:\"be13b97079a2d26b51850bcc02ff8d64\" namespace:\"kube-system\" returns sandbox id \"c47a2792930df7d58fff0c1a69e873eae6b010cebad9550a9ef1d17464530fdb\"" Jul 21 12:37:54.373817 containerd[2389]: time="2026-07-21T12:37:54.373631814Z" level=info msg="CreateContainer within sandbox \"c47a2792930df7d58fff0c1a69e873eae6b010cebad9550a9ef1d17464530fdb\" for container name:\"kube-controller-manager\"" Jul 21 12:37:54.385539 containerd[2389]: time="2026-07-21T12:37:54.385393410Z" level=info msg="CreateContainer within sandbox \"5f00a266627b1d2c614a8525f8f40483b9e88b952546e7866af7460f7b4a6b0b\" for name:\"kube-apiserver\" returns container id \"afdc35670d6803ba3499cf53f7de79c7a103214e54bd739f3732e977a2f9faeb\"" Jul 21 12:37:54.388233 containerd[2389]: time="2026-07-21T12:37:54.387982614Z" level=info msg="StartContainer for \"afdc35670d6803ba3499cf53f7de79c7a103214e54bd739f3732e977a2f9faeb\"" Jul 21 12:37:54.396229 containerd[2389]: time="2026-07-21T12:37:54.395872590Z" level=info msg="connecting to shim afdc35670d6803ba3499cf53f7de79c7a103214e54bd739f3732e977a2f9faeb" address="unix:///run/containerd/s/e1731909dfe263c02aa6cefa9dc786f89775012f0e5f5cf0be20af40511d6383" protocol=ttrpc version=3 Jul 21 12:37:54.396902 systemd[1]: Started cri-containerd-262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584.scope - libcontainer container 262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584. Jul 21 12:37:54.448000 audit: BPF prog-id=74 op=LOAD Jul 21 12:37:54.450000 audit: BPF prog-id=75 op=LOAD Jul 21 12:37:54.450000 audit[3519]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=121a8f0df90 a2=98 a3=0 items=0 ppid=3393 pid=3519 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.450000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3236326664316536616166653839376365363966333762333864313331 Jul 21 12:37:54.450000 audit: BPF prog-id=75 op=UNLOAD Jul 21 12:37:54.450000 audit[3519]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=3393 pid=3519 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.450000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3236326664316536616166653839376365363966333762333864313331 Jul 21 12:37:54.451000 audit: BPF prog-id=76 op=LOAD Jul 21 12:37:54.451000 audit[3519]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=121a8f0e268 a2=98 a3=0 items=0 ppid=3393 pid=3519 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.451000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3236326664316536616166653839376365363966333762333864313331 Jul 21 12:37:54.452000 audit: BPF prog-id=77 op=LOAD Jul 21 12:37:54.452000 audit[3519]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=121a8f0dfa8 a2=98 a3=0 items=0 ppid=3393 pid=3519 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.452000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3236326664316536616166653839376365363966333762333864313331 Jul 21 12:37:54.452000 audit: BPF prog-id=77 op=UNLOAD Jul 21 12:37:54.452000 audit[3519]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=3393 pid=3519 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.452000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3236326664316536616166653839376365363966333762333864313331 Jul 21 12:37:54.453000 audit: BPF prog-id=76 op=UNLOAD Jul 21 12:37:54.453000 audit[3519]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=3393 pid=3519 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.453000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3236326664316536616166653839376365363966333762333864313331 Jul 21 12:37:54.454000 audit: BPF prog-id=78 op=LOAD Jul 21 12:37:54.454000 audit[3519]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=121a8f0e4b8 a2=98 a3=0 items=0 ppid=3393 pid=3519 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.454000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3236326664316536616166653839376365363966333762333864313331 Jul 21 12:37:54.461184 containerd[2389]: time="2026-07-21T12:37:54.461021334Z" level=info msg="CreateContainer within sandbox \"c47a2792930df7d58fff0c1a69e873eae6b010cebad9550a9ef1d17464530fdb\" for name:\"kube-controller-manager\" returns container id \"a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2\"" Jul 21 12:37:54.463794 systemd[1]: Started cri-containerd-afdc35670d6803ba3499cf53f7de79c7a103214e54bd739f3732e977a2f9faeb.scope - libcontainer container afdc35670d6803ba3499cf53f7de79c7a103214e54bd739f3732e977a2f9faeb. Jul 21 12:37:54.468226 containerd[2389]: time="2026-07-21T12:37:54.466463202Z" level=info msg="StartContainer for \"a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2\"" Jul 21 12:37:54.474765 containerd[2389]: time="2026-07-21T12:37:54.474427710Z" level=info msg="connecting to shim a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2" address="unix:///run/containerd/s/b98a369f226ce3c41f6b280c8ef4a54361202d0dcef2a06492b2237f109c598b" protocol=ttrpc version=3 Jul 21 12:37:54.531644 systemd[1]: Started cri-containerd-a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2.scope - libcontainer container a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2. Jul 21 12:37:54.543000 audit: BPF prog-id=79 op=LOAD Jul 21 12:37:54.548000 audit: BPF prog-id=80 op=LOAD Jul 21 12:37:54.548000 audit[3535]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=36e85684bf90 a2=98 a3=0 items=0 ppid=3426 pid=3535 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.548000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6166646333353637306436383033626133343939636635336637646537 Jul 21 12:37:54.552000 audit: BPF prog-id=80 op=UNLOAD Jul 21 12:37:54.552000 audit[3535]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=3426 pid=3535 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.552000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6166646333353637306436383033626133343939636635336637646537 Jul 21 12:37:54.552000 audit: BPF prog-id=81 op=LOAD Jul 21 12:37:54.552000 audit[3535]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=36e85684c268 a2=98 a3=0 items=0 ppid=3426 pid=3535 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.552000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6166646333353637306436383033626133343939636635336637646537 Jul 21 12:37:54.552000 audit: BPF prog-id=82 op=LOAD Jul 21 12:37:54.552000 audit[3535]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=36e85684bfa8 a2=98 a3=0 items=0 ppid=3426 pid=3535 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.552000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6166646333353637306436383033626133343939636635336637646537 Jul 21 12:37:54.552000 audit: BPF prog-id=82 op=UNLOAD Jul 21 12:37:54.552000 audit[3535]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=3426 pid=3535 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.552000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6166646333353637306436383033626133343939636635336637646537 Jul 21 12:37:54.552000 audit: BPF prog-id=81 op=UNLOAD Jul 21 12:37:54.552000 audit[3535]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=3426 pid=3535 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.552000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6166646333353637306436383033626133343939636635336637646537 Jul 21 12:37:54.552000 audit: BPF prog-id=83 op=LOAD Jul 21 12:37:54.552000 audit[3535]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=36e85684c4b8 a2=98 a3=0 items=0 ppid=3426 pid=3535 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.552000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6166646333353637306436383033626133343939636635336637646537 Jul 21 12:37:54.598000 audit: BPF prog-id=84 op=LOAD Jul 21 12:37:54.601000 audit: BPF prog-id=85 op=LOAD Jul 21 12:37:54.601000 audit[3556]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2304bcab1f90 a2=98 a3=0 items=0 ppid=3439 pid=3556 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.601000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6131383234323432303731366364323665326162363434313431333730 Jul 21 12:37:54.601000 audit: BPF prog-id=85 op=UNLOAD Jul 21 12:37:54.601000 audit[3556]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=3439 pid=3556 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.601000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6131383234323432303731366364323665326162363434313431333730 Jul 21 12:37:54.603000 audit: BPF prog-id=86 op=LOAD Jul 21 12:37:54.603000 audit[3556]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2304bcab2268 a2=98 a3=0 items=0 ppid=3439 pid=3556 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.603000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6131383234323432303731366364323665326162363434313431333730 Jul 21 12:37:54.604000 audit: BPF prog-id=87 op=LOAD Jul 21 12:37:54.604000 audit[3556]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=2304bcab1fa8 a2=98 a3=0 items=0 ppid=3439 pid=3556 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.604000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6131383234323432303731366364323665326162363434313431333730 Jul 21 12:37:54.605000 audit: BPF prog-id=87 op=UNLOAD Jul 21 12:37:54.605000 audit[3556]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=3439 pid=3556 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.605000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6131383234323432303731366364323665326162363434313431333730 Jul 21 12:37:54.605000 audit: BPF prog-id=86 op=UNLOAD Jul 21 12:37:54.605000 audit[3556]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=3439 pid=3556 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.605000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6131383234323432303731366364323665326162363434313431333730 Jul 21 12:37:54.611000 audit: BPF prog-id=88 op=LOAD Jul 21 12:37:54.611000 audit[3556]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2304bcab24b8 a2=98 a3=0 items=0 ppid=3439 pid=3556 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:37:54.611000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6131383234323432303731366364323665326162363434313431333730 Jul 21 12:37:54.617624 kubelet[3339]: E0721 12:37:54.617396 3339 reflector.go:205] "Failed to watch" err="failed to list *v1.Service: Get \"https://172.31.16.165:6443/api/v1/services?fieldSelector=spec.clusterIP%21%3DNone&limit=500&resourceVersion=0\": dial tcp 172.31.16.165:6443: connect: connection refused" logger="UnhandledError" reflector="k8s.io/client-go/informers/factory.go:160" type="*v1.Service" Jul 21 12:37:54.626830 containerd[2389]: time="2026-07-21T12:37:54.626369731Z" level=info msg="StartContainer for \"262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584\" returns successfully" Jul 21 12:37:54.680499 kubelet[3339]: E0721 12:37:54.678781 3339 reflector.go:205] "Failed to watch" err="failed to list *v1.Node: Get \"https://172.31.16.165:6443/api/v1/nodes?fieldSelector=metadata.name%3Dip-172-31-16-165&limit=500&resourceVersion=0\": dial tcp 172.31.16.165:6443: connect: connection refused" logger="UnhandledError" reflector="k8s.io/client-go/informers/factory.go:160" type="*v1.Node" Jul 21 12:37:54.695229 containerd[2389]: time="2026-07-21T12:37:54.694713007Z" level=info msg="StartContainer for \"afdc35670d6803ba3499cf53f7de79c7a103214e54bd739f3732e977a2f9faeb\" returns successfully" Jul 21 12:37:54.783936 kubelet[3339]: E0721 12:37:54.783739 3339 reflector.go:205] "Failed to watch" err="failed to list *v1.RuntimeClass: Get \"https://172.31.16.165:6443/apis/node.k8s.io/v1/runtimeclasses?limit=500&resourceVersion=0\": dial tcp 172.31.16.165:6443: connect: connection refused" logger="UnhandledError" reflector="k8s.io/client-go/informers/factory.go:160" type="*v1.RuntimeClass" Jul 21 12:37:54.789366 containerd[2389]: time="2026-07-21T12:37:54.789103712Z" level=info msg="StartContainer for \"a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2\" returns successfully" Jul 21 12:37:54.832834 kubelet[3339]: E0721 12:37:54.832781 3339 controller.go:145] "Failed to ensure lease exists, will retry" err="Get \"https://172.31.16.165:6443/apis/coordination.k8s.io/v1/namespaces/kube-node-lease/leases/ip-172-31-16-165?timeout=10s\": dial tcp 172.31.16.165:6443: connect: connection refused" interval="1.6s" Jul 21 12:37:54.933811 kubelet[3339]: E0721 12:37:54.933443 3339 reflector.go:205] "Failed to watch" err="failed to list *v1.CSIDriver: Get \"https://172.31.16.165:6443/apis/storage.k8s.io/v1/csidrivers?limit=500&resourceVersion=0\": dial tcp 172.31.16.165:6443: connect: connection refused" logger="UnhandledError" reflector="k8s.io/client-go/informers/factory.go:160" type="*v1.CSIDriver" Jul 21 12:37:55.088658 kubelet[3339]: I0721 12:37:55.088590 3339 kubelet_node_status.go:75] "Attempting to register node" node="ip-172-31-16-165" Jul 21 12:37:55.529448 kubelet[3339]: E0721 12:37:55.529359 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:55.540097 kubelet[3339]: E0721 12:37:55.538790 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:55.552506 kubelet[3339]: E0721 12:37:55.552460 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:56.555297 kubelet[3339]: E0721 12:37:56.554843 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:56.555297 kubelet[3339]: E0721 12:37:56.554933 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:56.556068 kubelet[3339]: E0721 12:37:56.555389 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:57.558380 kubelet[3339]: E0721 12:37:57.558189 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:57.560115 kubelet[3339]: E0721 12:37:57.559341 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:58.380994 kubelet[3339]: E0721 12:37:58.380728 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:58.579047 kubelet[3339]: E0721 12:37:58.578992 3339 kubelet.go:3216] "No need to create a mirror pod, since failed to get node info from the cluster" err="node \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:58.892595 kubelet[3339]: E0721 12:37:58.892531 3339 nodelease.go:49] "Failed to get node when trying to set owner ref to the node lease" err="nodes \"ip-172-31-16-165\" not found" node="ip-172-31-16-165" Jul 21 12:37:59.048851 kubelet[3339]: I0721 12:37:59.048786 3339 kubelet_node_status.go:78] "Successfully registered node" node="ip-172-31-16-165" Jul 21 12:37:59.101889 kubelet[3339]: I0721 12:37:59.101816 3339 kubelet.go:3220] "Creating a mirror pod for static pod" pod="kube-system/kube-scheduler-ip-172-31-16-165" Jul 21 12:37:59.122245 kubelet[3339]: E0721 12:37:59.121368 3339 kubelet.go:3222] "Failed creating a mirror pod" err="pods \"kube-scheduler-ip-172-31-16-165\" is forbidden: no PriorityClass with name system-node-critical was found" pod="kube-system/kube-scheduler-ip-172-31-16-165" Jul 21 12:37:59.122245 kubelet[3339]: I0721 12:37:59.121463 3339 kubelet.go:3220] "Creating a mirror pod for static pod" pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:37:59.128727 kubelet[3339]: E0721 12:37:59.128302 3339 kubelet.go:3222] "Failed creating a mirror pod" err="pods \"kube-apiserver-ip-172-31-16-165\" is forbidden: no PriorityClass with name system-node-critical was found" pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:37:59.128727 kubelet[3339]: I0721 12:37:59.128358 3339 kubelet.go:3220] "Creating a mirror pod for static pod" pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:37:59.134112 kubelet[3339]: E0721 12:37:59.134048 3339 kubelet.go:3222] "Failed creating a mirror pod" err="pods \"kube-controller-manager-ip-172-31-16-165\" is forbidden: no PriorityClass with name system-node-critical was found" pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:37:59.362144 kubelet[3339]: I0721 12:37:59.362058 3339 apiserver.go:52] "Watching apiserver" Jul 21 12:37:59.393017 kubelet[3339]: I0721 12:37:59.392954 3339 desired_state_of_world_populator.go:154] "Finished populating initial desired state of world" Jul 21 12:38:01.388327 systemd[1]: Reload requested from client PID 3886 ('systemctl') (unit session-8.scope)... Jul 21 12:38:01.388975 systemd[1]: Reloading... Jul 21 12:38:01.623234 kubelet[3339]: I0721 12:38:01.622037 3339 kubelet.go:3220] "Creating a mirror pod for static pod" pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:38:01.720391 zram_generator::config[3944]: No configuration found. Jul 21 12:38:02.460081 systemd[1]: Reloading finished in 1070 ms. Jul 21 12:38:02.481000 audit: BPF prog-id=89 op=LOAD Jul 21 12:38:02.483855 kernel: kauditd_printk_skb: 200 callbacks suppressed Jul 21 12:38:02.483939 kernel: audit: type=1334 audit(1784637482.481:329): prog-id=89 op=LOAD Jul 21 12:38:02.481000 audit: BPF prog-id=39 op=UNLOAD Jul 21 12:38:02.487423 kernel: audit: type=1334 audit(1784637482.481:330): prog-id=39 op=UNLOAD Jul 21 12:38:02.484000 audit: BPF prog-id=90 op=LOAD Jul 21 12:38:02.489340 kernel: audit: type=1334 audit(1784637482.484:331): prog-id=90 op=LOAD Jul 21 12:38:02.484000 audit: BPF prog-id=84 op=UNLOAD Jul 21 12:38:02.491345 kernel: audit: type=1334 audit(1784637482.484:332): prog-id=84 op=UNLOAD Jul 21 12:38:02.490000 audit: BPF prog-id=91 op=LOAD Jul 21 12:38:02.492967 kernel: audit: type=1334 audit(1784637482.490:333): prog-id=91 op=LOAD Jul 21 12:38:02.490000 audit: BPF prog-id=40 op=UNLOAD Jul 21 12:38:02.494844 kernel: audit: type=1334 audit(1784637482.490:334): prog-id=40 op=UNLOAD Jul 21 12:38:02.493000 audit: BPF prog-id=92 op=LOAD Jul 21 12:38:02.496466 kernel: audit: type=1334 audit(1784637482.493:335): prog-id=92 op=LOAD Jul 21 12:38:02.493000 audit: BPF prog-id=74 op=UNLOAD Jul 21 12:38:02.498355 kernel: audit: type=1334 audit(1784637482.493:336): prog-id=74 op=UNLOAD Jul 21 12:38:02.500000 audit: BPF prog-id=93 op=LOAD Jul 21 12:38:02.500000 audit: BPF prog-id=41 op=UNLOAD Jul 21 12:38:02.505174 kernel: audit: type=1334 audit(1784637482.500:337): prog-id=93 op=LOAD Jul 21 12:38:02.502000 audit: BPF prog-id=94 op=LOAD Jul 21 12:38:02.505348 kernel: audit: type=1334 audit(1784637482.500:338): prog-id=41 op=UNLOAD Jul 21 12:38:02.504000 audit: BPF prog-id=95 op=LOAD Jul 21 12:38:02.504000 audit: BPF prog-id=42 op=UNLOAD Jul 21 12:38:02.504000 audit: BPF prog-id=43 op=UNLOAD Jul 21 12:38:02.505000 audit: BPF prog-id=96 op=LOAD Jul 21 12:38:02.505000 audit: BPF prog-id=44 op=UNLOAD Jul 21 12:38:02.506000 audit: BPF prog-id=97 op=LOAD Jul 21 12:38:02.506000 audit: BPF prog-id=45 op=UNLOAD Jul 21 12:38:02.506000 audit: BPF prog-id=98 op=LOAD Jul 21 12:38:02.506000 audit: BPF prog-id=99 op=LOAD Jul 21 12:38:02.506000 audit: BPF prog-id=46 op=UNLOAD Jul 21 12:38:02.506000 audit: BPF prog-id=47 op=UNLOAD Jul 21 12:38:02.507000 audit: BPF prog-id=100 op=LOAD Jul 21 12:38:02.507000 audit: BPF prog-id=79 op=UNLOAD Jul 21 12:38:02.509000 audit: BPF prog-id=101 op=LOAD Jul 21 12:38:02.509000 audit: BPF prog-id=48 op=UNLOAD Jul 21 12:38:02.509000 audit: BPF prog-id=102 op=LOAD Jul 21 12:38:02.509000 audit: BPF prog-id=103 op=LOAD Jul 21 12:38:02.509000 audit: BPF prog-id=49 op=UNLOAD Jul 21 12:38:02.509000 audit: BPF prog-id=50 op=UNLOAD Jul 21 12:38:02.510000 audit: BPF prog-id=104 op=LOAD Jul 21 12:38:02.510000 audit: BPF prog-id=51 op=UNLOAD Jul 21 12:38:02.511000 audit: BPF prog-id=105 op=LOAD Jul 21 12:38:02.511000 audit: BPF prog-id=106 op=LOAD Jul 21 12:38:02.511000 audit: BPF prog-id=52 op=UNLOAD Jul 21 12:38:02.511000 audit: BPF prog-id=53 op=UNLOAD Jul 21 12:38:02.512000 audit: BPF prog-id=107 op=LOAD Jul 21 12:38:02.512000 audit: BPF prog-id=64 op=UNLOAD Jul 21 12:38:02.519000 audit: BPF prog-id=108 op=LOAD Jul 21 12:38:02.519000 audit: BPF prog-id=54 op=UNLOAD Jul 21 12:38:02.519000 audit: BPF prog-id=109 op=LOAD Jul 21 12:38:02.519000 audit: BPF prog-id=110 op=LOAD Jul 21 12:38:02.519000 audit: BPF prog-id=55 op=UNLOAD Jul 21 12:38:02.519000 audit: BPF prog-id=56 op=UNLOAD Jul 21 12:38:02.522000 audit: BPF prog-id=111 op=LOAD Jul 21 12:38:02.522000 audit: BPF prog-id=112 op=LOAD Jul 21 12:38:02.522000 audit: BPF prog-id=57 op=UNLOAD Jul 21 12:38:02.522000 audit: BPF prog-id=58 op=UNLOAD Jul 21 12:38:02.525000 audit: BPF prog-id=113 op=LOAD Jul 21 12:38:02.525000 audit: BPF prog-id=69 op=UNLOAD Jul 21 12:38:02.528000 audit: BPF prog-id=114 op=LOAD Jul 21 12:38:02.528000 audit: BPF prog-id=59 op=UNLOAD Jul 21 12:38:02.605288 systemd[1]: Stopping kubelet.service - kubelet: The Kubernetes Node Agent... Jul 21 12:38:02.619651 systemd[1]: kubelet.service: Deactivated successfully. Jul 21 12:38:02.620286 systemd[1]: Stopped kubelet.service - kubelet: The Kubernetes Node Agent. Jul 21 12:38:02.620427 systemd[1]: kubelet.service: Consumed 1.856s CPU time over 10.644s wall clock time, 145.5M memory peak. Jul 21 12:38:02.619000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:02.625122 systemd[1]: Starting kubelet.service - kubelet: The Kubernetes Node Agent... Jul 21 12:38:03.012619 systemd[1]: Started kubelet.service - kubelet: The Kubernetes Node Agent. Jul 21 12:38:03.012000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:03.036900 (kubelet)[4002]: kubelet.service: Referenced but unset environment variable evaluates to an empty string: KUBELET_EXTRA_ARGS Jul 21 12:38:03.141188 kubelet[4002]: Flag --pod-infra-container-image has been deprecated, will be removed in 1.35. Image garbage collector will get sandbox image information from CRI. Jul 21 12:38:03.142269 kubelet[4002]: Flag --volume-plugin-dir has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/ for more information. Jul 21 12:38:03.142269 kubelet[4002]: I0721 12:38:03.141505 4002 server.go:213] "--pod-infra-container-image will not be pruned by the image garbage collector in kubelet and should also be set in the remote runtime" Jul 21 12:38:03.158536 kubelet[4002]: I0721 12:38:03.158491 4002 server.go:529] "Kubelet version" kubeletVersion="v1.34.4" Jul 21 12:38:03.158735 kubelet[4002]: I0721 12:38:03.158714 4002 server.go:531] "Golang settings" GOGC="" GOMAXPROCS="" GOTRACEBACK="" Jul 21 12:38:03.158857 kubelet[4002]: I0721 12:38:03.158839 4002 watchdog_linux.go:95] "Systemd watchdog is not enabled" Jul 21 12:38:03.158977 kubelet[4002]: I0721 12:38:03.158951 4002 watchdog_linux.go:137] "Systemd watchdog is not enabled or the interval is invalid, so health checking will not be started." Jul 21 12:38:03.160119 kubelet[4002]: I0721 12:38:03.159583 4002 server.go:956] "Client rotation is on, will bootstrap in background" Jul 21 12:38:03.169244 kubelet[4002]: I0721 12:38:03.166756 4002 certificate_store.go:147] "Loading cert/key pair from a file" filePath="/var/lib/kubelet/pki/kubelet-client-current.pem" Jul 21 12:38:03.172459 kubelet[4002]: I0721 12:38:03.172418 4002 dynamic_cafile_content.go:161] "Starting controller" name="client-ca-bundle::/etc/kubernetes/pki/ca.crt" Jul 21 12:38:03.188388 kubelet[4002]: I0721 12:38:03.188335 4002 server.go:1423] "Using cgroup driver setting received from the CRI runtime" cgroupDriver="systemd" Jul 21 12:38:03.197544 kubelet[4002]: I0721 12:38:03.197478 4002 server.go:781] "--cgroups-per-qos enabled, but --cgroup-root was not specified. Defaulting to /" Jul 21 12:38:03.198086 kubelet[4002]: I0721 12:38:03.197918 4002 container_manager_linux.go:270] "Container manager verified user specified cgroup-root exists" cgroupRoot=[] Jul 21 12:38:03.198325 kubelet[4002]: I0721 12:38:03.197966 4002 container_manager_linux.go:275] "Creating Container Manager object based on Node Config" nodeConfig={"NodeName":"ip-172-31-16-165","RuntimeCgroupsName":"","SystemCgroupsName":"","KubeletCgroupsName":"","KubeletOOMScoreAdj":-999,"ContainerRuntime":"","CgroupsPerQOS":true,"CgroupRoot":"/","CgroupDriver":"systemd","KubeletRootDir":"/var/lib/kubelet","ProtectKernelDefaults":false,"KubeReservedCgroupName":"","SystemReservedCgroupName":"","ReservedSystemCPUs":{},"EnforceNodeAllocatable":{"pods":{}},"KubeReserved":null,"SystemReserved":null,"HardEvictionThresholds":[{"Signal":"memory.available","Operator":"LessThan","Value":{"Quantity":"100Mi","Percentage":0},"GracePeriod":0,"MinReclaim":null},{"Signal":"nodefs.available","Operator":"LessThan","Value":{"Quantity":null,"Percentage":0.1},"GracePeriod":0,"MinReclaim":null},{"Signal":"nodefs.inodesFree","Operator":"LessThan","Value":{"Quantity":null,"Percentage":0.05},"GracePeriod":0,"MinReclaim":null},{"Signal":"imagefs.available","Operator":"LessThan","Value":{"Quantity":null,"Percentage":0.15},"GracePeriod":0,"MinReclaim":null},{"Signal":"imagefs.inodesFree","Operator":"LessThan","Value":{"Quantity":null,"Percentage":0.05},"GracePeriod":0,"MinReclaim":null}],"QOSReserved":{},"CPUManagerPolicy":"none","CPUManagerPolicyOptions":null,"TopologyManagerScope":"container","CPUManagerReconcilePeriod":10000000000,"MemoryManagerPolicy":"None","MemoryManagerReservedMemory":null,"PodPidsLimit":-1,"EnforceCPULimits":true,"CPUCFSQuotaPeriod":100000000,"TopologyManagerPolicy":"none","TopologyManagerPolicyOptions":null,"CgroupVersion":2} Jul 21 12:38:03.198325 kubelet[4002]: I0721 12:38:03.198295 4002 topology_manager.go:138] "Creating topology manager with none policy" Jul 21 12:38:03.198325 kubelet[4002]: I0721 12:38:03.198317 4002 container_manager_linux.go:306] "Creating device plugin manager" Jul 21 12:38:03.198912 kubelet[4002]: I0721 12:38:03.198369 4002 container_manager_linux.go:315] "Creating Dynamic Resource Allocation (DRA) manager" Jul 21 12:38:03.198912 kubelet[4002]: I0721 12:38:03.198778 4002 state_mem.go:36] "Initialized new in-memory state store" Jul 21 12:38:03.199120 kubelet[4002]: I0721 12:38:03.199085 4002 kubelet.go:475] "Attempting to sync node with API server" Jul 21 12:38:03.200252 kubelet[4002]: I0721 12:38:03.199941 4002 kubelet.go:376] "Adding static pod path" path="/etc/kubernetes/manifests" Jul 21 12:38:03.200252 kubelet[4002]: I0721 12:38:03.200013 4002 kubelet.go:387] "Adding apiserver pod source" Jul 21 12:38:03.200252 kubelet[4002]: I0721 12:38:03.200037 4002 apiserver.go:42] "Waiting for node sync before watching apiserver pods" Jul 21 12:38:03.206269 kubelet[4002]: I0721 12:38:03.205882 4002 kuberuntime_manager.go:291] "Container runtime initialized" containerRuntime="containerd" version="v2.2.5" apiVersion="v1" Jul 21 12:38:03.207629 kubelet[4002]: I0721 12:38:03.207595 4002 kubelet.go:940] "Not starting ClusterTrustBundle informer because we are in static kubelet mode or the ClusterTrustBundleProjection featuregate is disabled" Jul 21 12:38:03.207837 kubelet[4002]: I0721 12:38:03.207814 4002 kubelet.go:964] "Not starting PodCertificateRequest manager because we are in static kubelet mode or the PodCertificateProjection feature gate is disabled" Jul 21 12:38:03.223477 kubelet[4002]: I0721 12:38:03.222488 4002 server.go:1262] "Started kubelet" Jul 21 12:38:03.225094 kubelet[4002]: I0721 12:38:03.225065 4002 fs_resource_analyzer.go:67] "Starting FS ResourceAnalyzer" Jul 21 12:38:03.238915 kubelet[4002]: I0721 12:38:03.238853 4002 server.go:180] "Starting to listen" address="0.0.0.0" port=10250 Jul 21 12:38:03.273576 kubelet[4002]: I0721 12:38:03.273439 4002 server.go:310] "Adding debug handlers to kubelet server" Jul 21 12:38:03.278604 kubelet[4002]: I0721 12:38:03.252829 4002 dynamic_serving_content.go:135] "Starting controller" name="kubelet-server-cert-files::/var/lib/kubelet/pki/kubelet.crt::/var/lib/kubelet/pki/kubelet.key" Jul 21 12:38:03.286024 kubelet[4002]: I0721 12:38:03.284443 4002 factory.go:223] Registration of the systemd container factory successfully Jul 21 12:38:03.286024 kubelet[4002]: I0721 12:38:03.284739 4002 factory.go:221] Registration of the crio container factory failed: Get "http://%2Fvar%2Frun%2Fcrio%2Fcrio.sock/info": dial unix /var/run/crio/crio.sock: connect: no such file or directory Jul 21 12:38:03.287167 kubelet[4002]: I0721 12:38:03.266957 4002 desired_state_of_world_populator.go:146] "Desired state populator starts to run" Jul 21 12:38:03.287167 kubelet[4002]: E0721 12:38:03.267217 4002 kubelet_node_status.go:404] "Error getting the current node from lister" err="node \"ip-172-31-16-165\" not found" Jul 21 12:38:03.298649 kubelet[4002]: I0721 12:38:03.298586 4002 factory.go:223] Registration of the containerd container factory successfully Jul 21 12:38:03.303278 kubelet[4002]: I0721 12:38:03.240763 4002 ratelimit.go:56] "Setting rate limiting for endpoint" service="podresources" qps=100 burstTokens=10 Jul 21 12:38:03.309838 kubelet[4002]: I0721 12:38:03.309131 4002 server_v1.go:49] "podresources" method="list" useActivePods=true Jul 21 12:38:03.310527 kubelet[4002]: I0721 12:38:03.266873 4002 volume_manager.go:313] "Starting Kubelet Volume Manager" Jul 21 12:38:03.314265 kubelet[4002]: I0721 12:38:03.313407 4002 reconciler.go:29] "Reconciler: start to sync state" Jul 21 12:38:03.314265 kubelet[4002]: I0721 12:38:03.313654 4002 server.go:249] "Starting to serve the podresources API" endpoint="unix:/var/lib/kubelet/pod-resources/kubelet.sock" Jul 21 12:38:03.317650 kubelet[4002]: E0721 12:38:03.316433 4002 kubelet.go:1615] "Image garbage collection failed once. Stats initialization may not have completed yet" err="invalid capacity 0 on image filesystem" Jul 21 12:38:03.341839 kubelet[4002]: I0721 12:38:03.341575 4002 kubelet_network_linux.go:54] "Initialized iptables rules." protocol="IPv4" Jul 21 12:38:03.347598 kubelet[4002]: I0721 12:38:03.347498 4002 kubelet_network_linux.go:54] "Initialized iptables rules." protocol="IPv6" Jul 21 12:38:03.347598 kubelet[4002]: I0721 12:38:03.347553 4002 status_manager.go:244] "Starting to sync pod status with apiserver" Jul 21 12:38:03.348337 kubelet[4002]: I0721 12:38:03.347837 4002 kubelet.go:2428] "Starting kubelet main sync loop" Jul 21 12:38:03.348337 kubelet[4002]: E0721 12:38:03.347923 4002 kubelet.go:2452] "Skipping pod synchronization" err="[container runtime status check may not have completed yet, PLEG is not healthy: pleg has yet to be successful]" Jul 21 12:38:03.449687 kubelet[4002]: E0721 12:38:03.449122 4002 kubelet.go:2452] "Skipping pod synchronization" err="container runtime status check may not have completed yet" Jul 21 12:38:03.460958 kubelet[4002]: I0721 12:38:03.460906 4002 cpu_manager.go:221] "Starting CPU manager" policy="none" Jul 21 12:38:03.460958 kubelet[4002]: I0721 12:38:03.460941 4002 cpu_manager.go:222] "Reconciling" reconcilePeriod="10s" Jul 21 12:38:03.461159 kubelet[4002]: I0721 12:38:03.460982 4002 state_mem.go:36] "Initialized new in-memory state store" Jul 21 12:38:03.461546 kubelet[4002]: I0721 12:38:03.461242 4002 state_mem.go:88] "Updated default CPUSet" cpuSet="" Jul 21 12:38:03.461546 kubelet[4002]: I0721 12:38:03.461275 4002 state_mem.go:96] "Updated CPUSet assignments" assignments={} Jul 21 12:38:03.461546 kubelet[4002]: I0721 12:38:03.461309 4002 policy_none.go:49] "None policy: Start" Jul 21 12:38:03.461546 kubelet[4002]: I0721 12:38:03.461327 4002 memory_manager.go:187] "Starting memorymanager" policy="None" Jul 21 12:38:03.461546 kubelet[4002]: I0721 12:38:03.461349 4002 state_mem.go:36] "Initializing new in-memory state store" logger="Memory Manager state checkpoint" Jul 21 12:38:03.461546 kubelet[4002]: I0721 12:38:03.461525 4002 state_mem.go:77] "Updated machine memory state" logger="Memory Manager state checkpoint" Jul 21 12:38:03.461546 kubelet[4002]: I0721 12:38:03.461542 4002 policy_none.go:47] "Start" Jul 21 12:38:03.477642 kubelet[4002]: E0721 12:38:03.477161 4002 manager.go:513] "Failed to read data from checkpoint" err="checkpoint is not found" checkpoint="kubelet_internal_checkpoint" Jul 21 12:38:03.477642 kubelet[4002]: I0721 12:38:03.477486 4002 eviction_manager.go:189] "Eviction manager: starting control loop" Jul 21 12:38:03.478070 kubelet[4002]: I0721 12:38:03.478011 4002 container_log_manager.go:146] "Initializing container log rotate workers" workers=1 monitorPeriod="10s" Jul 21 12:38:03.483952 kubelet[4002]: E0721 12:38:03.483788 4002 eviction_manager.go:267] "eviction manager: failed to check if we have separate container filesystem. Ignoring." err="no imagefs label for configured runtime" Jul 21 12:38:03.497235 kubelet[4002]: I0721 12:38:03.483949 4002 plugin_manager.go:118] "Starting Kubelet Plugin Manager" Jul 21 12:38:03.613487 kubelet[4002]: I0721 12:38:03.612184 4002 kubelet_node_status.go:75] "Attempting to register node" node="ip-172-31-16-165" Jul 21 12:38:03.629265 kubelet[4002]: I0721 12:38:03.629105 4002 kubelet_node_status.go:124] "Node was previously registered" node="ip-172-31-16-165" Jul 21 12:38:03.630041 kubelet[4002]: I0721 12:38:03.630014 4002 kubelet_node_status.go:78] "Successfully registered node" node="ip-172-31-16-165" Jul 21 12:38:03.651708 kubelet[4002]: I0721 12:38:03.651373 4002 kubelet.go:3220] "Creating a mirror pod for static pod" pod="kube-system/kube-scheduler-ip-172-31-16-165" Jul 21 12:38:03.654292 kubelet[4002]: I0721 12:38:03.653915 4002 kubelet.go:3220] "Creating a mirror pod for static pod" pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:38:03.656361 kubelet[4002]: I0721 12:38:03.656324 4002 kubelet.go:3220] "Creating a mirror pod for static pod" pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:38:03.672751 kubelet[4002]: E0721 12:38:03.672665 4002 kubelet.go:3222] "Failed creating a mirror pod" err="pods \"kube-apiserver-ip-172-31-16-165\" already exists" pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:38:03.719224 kubelet[4002]: I0721 12:38:03.718721 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kubeconfig\" (UniqueName: \"kubernetes.io/host-path/070e974c580b4b82d9462a1a67e7f1dc-kubeconfig\") pod \"kube-scheduler-ip-172-31-16-165\" (UID: \"070e974c580b4b82d9462a1a67e7f1dc\") " pod="kube-system/kube-scheduler-ip-172-31-16-165" Jul 21 12:38:03.719224 kubelet[4002]: I0721 12:38:03.718788 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"k8s-certs\" (UniqueName: \"kubernetes.io/host-path/2cad5d234e9a82b90b8b7846ec7fa929-k8s-certs\") pod \"kube-apiserver-ip-172-31-16-165\" (UID: \"2cad5d234e9a82b90b8b7846ec7fa929\") " pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:38:03.719224 kubelet[4002]: I0721 12:38:03.718833 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"ca-certs\" (UniqueName: \"kubernetes.io/host-path/be13b97079a2d26b51850bcc02ff8d64-ca-certs\") pod \"kube-controller-manager-ip-172-31-16-165\" (UID: \"be13b97079a2d26b51850bcc02ff8d64\") " pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:38:03.719224 kubelet[4002]: I0721 12:38:03.718869 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"flexvolume-dir\" (UniqueName: \"kubernetes.io/host-path/be13b97079a2d26b51850bcc02ff8d64-flexvolume-dir\") pod \"kube-controller-manager-ip-172-31-16-165\" (UID: \"be13b97079a2d26b51850bcc02ff8d64\") " pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:38:03.719224 kubelet[4002]: I0721 12:38:03.718906 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"k8s-certs\" (UniqueName: \"kubernetes.io/host-path/be13b97079a2d26b51850bcc02ff8d64-k8s-certs\") pod \"kube-controller-manager-ip-172-31-16-165\" (UID: \"be13b97079a2d26b51850bcc02ff8d64\") " pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:38:03.719571 kubelet[4002]: I0721 12:38:03.718945 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"usr-share-ca-certificates\" (UniqueName: \"kubernetes.io/host-path/be13b97079a2d26b51850bcc02ff8d64-usr-share-ca-certificates\") pod \"kube-controller-manager-ip-172-31-16-165\" (UID: \"be13b97079a2d26b51850bcc02ff8d64\") " pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:38:03.719571 kubelet[4002]: I0721 12:38:03.718981 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"ca-certs\" (UniqueName: \"kubernetes.io/host-path/2cad5d234e9a82b90b8b7846ec7fa929-ca-certs\") pod \"kube-apiserver-ip-172-31-16-165\" (UID: \"2cad5d234e9a82b90b8b7846ec7fa929\") " pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:38:03.719571 kubelet[4002]: I0721 12:38:03.719017 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"usr-share-ca-certificates\" (UniqueName: \"kubernetes.io/host-path/2cad5d234e9a82b90b8b7846ec7fa929-usr-share-ca-certificates\") pod \"kube-apiserver-ip-172-31-16-165\" (UID: \"2cad5d234e9a82b90b8b7846ec7fa929\") " pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:38:03.719571 kubelet[4002]: I0721 12:38:03.719072 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kubeconfig\" (UniqueName: \"kubernetes.io/host-path/be13b97079a2d26b51850bcc02ff8d64-kubeconfig\") pod \"kube-controller-manager-ip-172-31-16-165\" (UID: \"be13b97079a2d26b51850bcc02ff8d64\") " pod="kube-system/kube-controller-manager-ip-172-31-16-165" Jul 21 12:38:04.204222 kubelet[4002]: I0721 12:38:04.203158 4002 apiserver.go:52] "Watching apiserver" Jul 21 12:38:04.287600 kubelet[4002]: I0721 12:38:04.287523 4002 desired_state_of_world_populator.go:154] "Finished populating initial desired state of world" Jul 21 12:38:04.408909 kubelet[4002]: I0721 12:38:04.408338 4002 kubelet.go:3220] "Creating a mirror pod for static pod" pod="kube-system/kube-scheduler-ip-172-31-16-165" Jul 21 12:38:04.408909 kubelet[4002]: I0721 12:38:04.408777 4002 kubelet.go:3220] "Creating a mirror pod for static pod" pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:38:04.419712 kubelet[4002]: E0721 12:38:04.419464 4002 kubelet.go:3222] "Failed creating a mirror pod" err="pods \"kube-scheduler-ip-172-31-16-165\" already exists" pod="kube-system/kube-scheduler-ip-172-31-16-165" Jul 21 12:38:04.426053 kubelet[4002]: E0721 12:38:04.425922 4002 kubelet.go:3222] "Failed creating a mirror pod" err="pods \"kube-apiserver-ip-172-31-16-165\" already exists" pod="kube-system/kube-apiserver-ip-172-31-16-165" Jul 21 12:38:04.461437 kubelet[4002]: I0721 12:38:04.460776 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="kube-system/kube-scheduler-ip-172-31-16-165" podStartSLOduration=1.460757524 podStartE2EDuration="1.460757524s" podCreationTimestamp="2026-07-21 12:38:03 +0000 UTC" firstStartedPulling="0001-01-01 00:00:00 +0000 UTC" lastFinishedPulling="0001-01-01 00:00:00 +0000 UTC" observedRunningTime="2026-07-21 12:38:04.457714768 +0000 UTC m=+1.410732140" watchObservedRunningTime="2026-07-21 12:38:04.460757524 +0000 UTC m=+1.413774872" Jul 21 12:38:04.479228 kubelet[4002]: I0721 12:38:04.479011 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="kube-system/kube-apiserver-ip-172-31-16-165" podStartSLOduration=3.478958176 podStartE2EDuration="3.478958176s" podCreationTimestamp="2026-07-21 12:38:01 +0000 UTC" firstStartedPulling="0001-01-01 00:00:00 +0000 UTC" lastFinishedPulling="0001-01-01 00:00:00 +0000 UTC" observedRunningTime="2026-07-21 12:38:04.477990568 +0000 UTC m=+1.431007904" watchObservedRunningTime="2026-07-21 12:38:04.478958176 +0000 UTC m=+1.431975500" Jul 21 12:38:04.503290 kubelet[4002]: I0721 12:38:04.503135 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="kube-system/kube-controller-manager-ip-172-31-16-165" podStartSLOduration=1.503112952 podStartE2EDuration="1.503112952s" podCreationTimestamp="2026-07-21 12:38:03 +0000 UTC" firstStartedPulling="0001-01-01 00:00:00 +0000 UTC" lastFinishedPulling="0001-01-01 00:00:00 +0000 UTC" observedRunningTime="2026-07-21 12:38:04.503087764 +0000 UTC m=+1.456105100" watchObservedRunningTime="2026-07-21 12:38:04.503112952 +0000 UTC m=+1.456130336" Jul 21 12:38:06.607602 kubelet[4002]: I0721 12:38:06.607519 4002 kuberuntime_manager.go:1828] "Updating runtime config through cri with podcidr" CIDR="192.168.0.0/24" Jul 21 12:38:06.608606 containerd[2389]: time="2026-07-21T12:38:06.608505150Z" level=info msg="No cni config template is specified, wait for other system components to drop the config." Jul 21 12:38:06.610474 kubelet[4002]: I0721 12:38:06.608838 4002 kubelet_network.go:47] "Updating Pod CIDR" originalPodCIDR="" newPodCIDR="192.168.0.0/24" Jul 21 12:38:07.541608 systemd[1]: Created slice kubepods-besteffort-podad8b1ac2_29e6_4abc_834d_3e6cf9a11d5c.slice - libcontainer container kubepods-besteffort-podad8b1ac2_29e6_4abc_834d_3e6cf9a11d5c.slice. Jul 21 12:38:07.644943 kubelet[4002]: I0721 12:38:07.644581 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-proxy\" (UniqueName: \"kubernetes.io/configmap/ad8b1ac2-29e6-4abc-834d-3e6cf9a11d5c-kube-proxy\") pod \"kube-proxy-tvlvz\" (UID: \"ad8b1ac2-29e6-4abc-834d-3e6cf9a11d5c\") " pod="kube-system/kube-proxy-tvlvz" Jul 21 12:38:07.646768 kubelet[4002]: I0721 12:38:07.645035 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"xtables-lock\" (UniqueName: \"kubernetes.io/host-path/ad8b1ac2-29e6-4abc-834d-3e6cf9a11d5c-xtables-lock\") pod \"kube-proxy-tvlvz\" (UID: \"ad8b1ac2-29e6-4abc-834d-3e6cf9a11d5c\") " pod="kube-system/kube-proxy-tvlvz" Jul 21 12:38:07.646768 kubelet[4002]: I0721 12:38:07.645085 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"lib-modules\" (UniqueName: \"kubernetes.io/host-path/ad8b1ac2-29e6-4abc-834d-3e6cf9a11d5c-lib-modules\") pod \"kube-proxy-tvlvz\" (UID: \"ad8b1ac2-29e6-4abc-834d-3e6cf9a11d5c\") " pod="kube-system/kube-proxy-tvlvz" Jul 21 12:38:07.646768 kubelet[4002]: I0721 12:38:07.645151 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-ml5gc\" (UniqueName: \"kubernetes.io/projected/ad8b1ac2-29e6-4abc-834d-3e6cf9a11d5c-kube-api-access-ml5gc\") pod \"kube-proxy-tvlvz\" (UID: \"ad8b1ac2-29e6-4abc-834d-3e6cf9a11d5c\") " pod="kube-system/kube-proxy-tvlvz" Jul 21 12:38:07.730339 systemd[1]: Created slice kubepods-besteffort-pod4cb1f859_715a_40d2_a0b5_02b36266dbf2.slice - libcontainer container kubepods-besteffort-pod4cb1f859_715a_40d2_a0b5_02b36266dbf2.slice. Jul 21 12:38:07.846546 kubelet[4002]: I0721 12:38:07.846342 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"var-lib-calico\" (UniqueName: \"kubernetes.io/host-path/4cb1f859-715a-40d2-a0b5-02b36266dbf2-var-lib-calico\") pod \"tigera-operator-55f97df97b-x6p46\" (UID: \"4cb1f859-715a-40d2-a0b5-02b36266dbf2\") " pod="tigera-operator/tigera-operator-55f97df97b-x6p46" Jul 21 12:38:07.846546 kubelet[4002]: I0721 12:38:07.846416 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-96wd7\" (UniqueName: \"kubernetes.io/projected/4cb1f859-715a-40d2-a0b5-02b36266dbf2-kube-api-access-96wd7\") pod \"tigera-operator-55f97df97b-x6p46\" (UID: \"4cb1f859-715a-40d2-a0b5-02b36266dbf2\") " pod="tigera-operator/tigera-operator-55f97df97b-x6p46" Jul 21 12:38:07.858691 containerd[2389]: time="2026-07-21T12:38:07.858600525Z" level=info msg="RunPodSandbox for name:\"kube-proxy-tvlvz\" uid:\"ad8b1ac2-29e6-4abc-834d-3e6cf9a11d5c\" namespace:\"kube-system\"" Jul 21 12:38:07.898058 containerd[2389]: time="2026-07-21T12:38:07.897323673Z" level=info msg="connecting to shim c89802d89294d79e2f655088bb9682edc3287ac99d271204fb6d7bd9e1d9bcdb" address="unix:///run/containerd/s/d281f7bd7c3396ad740da5600270ffab0c45bd0582852c07797d86e6b32cd97b" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:38:07.942735 systemd[1]: Started cri-containerd-c89802d89294d79e2f655088bb9682edc3287ac99d271204fb6d7bd9e1d9bcdb.scope - libcontainer container c89802d89294d79e2f655088bb9682edc3287ac99d271204fb6d7bd9e1d9bcdb. Jul 21 12:38:07.986000 audit: BPF prog-id=115 op=LOAD Jul 21 12:38:07.988512 kernel: kauditd_printk_skb: 44 callbacks suppressed Jul 21 12:38:07.988598 kernel: audit: type=1334 audit(1784637487.986:383): prog-id=115 op=LOAD Jul 21 12:38:07.989000 audit: BPF prog-id=116 op=LOAD Jul 21 12:38:07.992593 kernel: audit: type=1334 audit(1784637487.989:384): prog-id=116 op=LOAD Jul 21 12:38:07.989000 audit[4071]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1b9d8ba31f90 a2=98 a3=0 items=0 ppid=4057 pid=4071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:07.998937 kernel: audit: type=1300 audit(1784637487.989:384): arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1b9d8ba31f90 a2=98 a3=0 items=0 ppid=4057 pid=4071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:07.989000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6338393830326438393239346437396532663635353038386262393638 Jul 21 12:38:08.004902 kernel: audit: type=1327 audit(1784637487.989:384): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6338393830326438393239346437396532663635353038386262393638 Jul 21 12:38:07.989000 audit: BPF prog-id=116 op=UNLOAD Jul 21 12:38:08.006663 kernel: audit: type=1334 audit(1784637487.989:385): prog-id=116 op=UNLOAD Jul 21 12:38:07.989000 audit[4071]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4057 pid=4071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.012512 kernel: audit: type=1300 audit(1784637487.989:385): arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4057 pid=4071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:07.989000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6338393830326438393239346437396532663635353038386262393638 Jul 21 12:38:08.018411 kernel: audit: type=1327 audit(1784637487.989:385): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6338393830326438393239346437396532663635353038386262393638 Jul 21 12:38:07.989000 audit: BPF prog-id=117 op=LOAD Jul 21 12:38:08.020272 kernel: audit: type=1334 audit(1784637487.989:386): prog-id=117 op=LOAD Jul 21 12:38:07.989000 audit[4071]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1b9d8ba32268 a2=98 a3=0 items=0 ppid=4057 pid=4071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.026819 kernel: audit: type=1300 audit(1784637487.989:386): arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1b9d8ba32268 a2=98 a3=0 items=0 ppid=4057 pid=4071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:07.989000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6338393830326438393239346437396532663635353038386262393638 Jul 21 12:38:08.033607 kernel: audit: type=1327 audit(1784637487.989:386): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6338393830326438393239346437396532663635353038386262393638 Jul 21 12:38:07.991000 audit: BPF prog-id=118 op=LOAD Jul 21 12:38:07.991000 audit[4071]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=1b9d8ba31fa8 a2=98 a3=0 items=0 ppid=4057 pid=4071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:07.991000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6338393830326438393239346437396532663635353038386262393638 Jul 21 12:38:07.991000 audit: BPF prog-id=118 op=UNLOAD Jul 21 12:38:07.991000 audit[4071]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=4057 pid=4071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:07.991000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6338393830326438393239346437396532663635353038386262393638 Jul 21 12:38:07.991000 audit: BPF prog-id=117 op=UNLOAD Jul 21 12:38:07.991000 audit[4071]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4057 pid=4071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:07.991000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6338393830326438393239346437396532663635353038386262393638 Jul 21 12:38:07.991000 audit: BPF prog-id=119 op=LOAD Jul 21 12:38:07.991000 audit[4071]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1b9d8ba324b8 a2=98 a3=0 items=0 ppid=4057 pid=4071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:07.991000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6338393830326438393239346437396532663635353038386262393638 Jul 21 12:38:08.043635 containerd[2389]: time="2026-07-21T12:38:08.043569317Z" level=info msg="RunPodSandbox for name:\"tigera-operator-55f97df97b-x6p46\" uid:\"4cb1f859-715a-40d2-a0b5-02b36266dbf2\" namespace:\"tigera-operator\"" Jul 21 12:38:08.060589 containerd[2389]: time="2026-07-21T12:38:08.060521490Z" level=info msg="RunPodSandbox for name:\"kube-proxy-tvlvz\" uid:\"ad8b1ac2-29e6-4abc-834d-3e6cf9a11d5c\" namespace:\"kube-system\" returns sandbox id \"c89802d89294d79e2f655088bb9682edc3287ac99d271204fb6d7bd9e1d9bcdb\"" Jul 21 12:38:08.084862 containerd[2389]: time="2026-07-21T12:38:08.084795942Z" level=info msg="CreateContainer within sandbox \"c89802d89294d79e2f655088bb9682edc3287ac99d271204fb6d7bd9e1d9bcdb\" for container name:\"kube-proxy\"" Jul 21 12:38:08.089948 containerd[2389]: time="2026-07-21T12:38:08.089877006Z" level=info msg="connecting to shim b208cb9d0711e1f2a03ff644c8d838eaeccf8baba3b4289fbf7b49452b21150a" address="unix:///run/containerd/s/f6f8fbb44c7afa9f7bcbdf432bdcf5ef88e817f0958122465f64be11ade24d21" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:38:08.139620 systemd[1]: Started cri-containerd-b208cb9d0711e1f2a03ff644c8d838eaeccf8baba3b4289fbf7b49452b21150a.scope - libcontainer container b208cb9d0711e1f2a03ff644c8d838eaeccf8baba3b4289fbf7b49452b21150a. Jul 21 12:38:08.151421 containerd[2389]: time="2026-07-21T12:38:08.151100970Z" level=info msg="CreateContainer within sandbox \"c89802d89294d79e2f655088bb9682edc3287ac99d271204fb6d7bd9e1d9bcdb\" for name:\"kube-proxy\" returns container id \"bfc745b346a7702e0686ee28da5b1bda769612e2f2267fd6073c975193bb967a\"" Jul 21 12:38:08.156227 containerd[2389]: time="2026-07-21T12:38:08.154270686Z" level=info msg="StartContainer for \"bfc745b346a7702e0686ee28da5b1bda769612e2f2267fd6073c975193bb967a\"" Jul 21 12:38:08.158752 containerd[2389]: time="2026-07-21T12:38:08.158703066Z" level=info msg="connecting to shim bfc745b346a7702e0686ee28da5b1bda769612e2f2267fd6073c975193bb967a" address="unix:///run/containerd/s/d281f7bd7c3396ad740da5600270ffab0c45bd0582852c07797d86e6b32cd97b" protocol=ttrpc version=3 Jul 21 12:38:08.173000 audit: BPF prog-id=120 op=LOAD Jul 21 12:38:08.175000 audit: BPF prog-id=121 op=LOAD Jul 21 12:38:08.175000 audit[4117]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1dfbe7dbbf90 a2=98 a3=0 items=0 ppid=4106 pid=4117 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.175000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6232303863623964303731316531663261303366663634346338643833 Jul 21 12:38:08.176000 audit: BPF prog-id=121 op=UNLOAD Jul 21 12:38:08.176000 audit[4117]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4106 pid=4117 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.176000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6232303863623964303731316531663261303366663634346338643833 Jul 21 12:38:08.176000 audit: BPF prog-id=122 op=LOAD Jul 21 12:38:08.176000 audit[4117]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1dfbe7dbc268 a2=98 a3=0 items=0 ppid=4106 pid=4117 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.176000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6232303863623964303731316531663261303366663634346338643833 Jul 21 12:38:08.176000 audit: BPF prog-id=123 op=LOAD Jul 21 12:38:08.176000 audit[4117]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=1dfbe7dbbfa8 a2=98 a3=0 items=0 ppid=4106 pid=4117 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.176000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6232303863623964303731316531663261303366663634346338643833 Jul 21 12:38:08.176000 audit: BPF prog-id=123 op=UNLOAD Jul 21 12:38:08.176000 audit[4117]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=4106 pid=4117 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.176000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6232303863623964303731316531663261303366663634346338643833 Jul 21 12:38:08.176000 audit: BPF prog-id=122 op=UNLOAD Jul 21 12:38:08.176000 audit[4117]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4106 pid=4117 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.176000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6232303863623964303731316531663261303366663634346338643833 Jul 21 12:38:08.176000 audit: BPF prog-id=124 op=LOAD Jul 21 12:38:08.176000 audit[4117]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1dfbe7dbc4b8 a2=98 a3=0 items=0 ppid=4106 pid=4117 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.176000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6232303863623964303731316531663261303366663634346338643833 Jul 21 12:38:08.208619 systemd[1]: Started cri-containerd-bfc745b346a7702e0686ee28da5b1bda769612e2f2267fd6073c975193bb967a.scope - libcontainer container bfc745b346a7702e0686ee28da5b1bda769612e2f2267fd6073c975193bb967a. Jul 21 12:38:08.268894 containerd[2389]: time="2026-07-21T12:38:08.268825267Z" level=info msg="RunPodSandbox for name:\"tigera-operator-55f97df97b-x6p46\" uid:\"4cb1f859-715a-40d2-a0b5-02b36266dbf2\" namespace:\"tigera-operator\" returns sandbox id \"b208cb9d0711e1f2a03ff644c8d838eaeccf8baba3b4289fbf7b49452b21150a\"" Jul 21 12:38:08.275705 containerd[2389]: time="2026-07-21T12:38:08.275607907Z" level=info msg="PullImage \"quay.io/tigera/operator:v1.42.3\"" Jul 21 12:38:08.310000 audit: BPF prog-id=125 op=LOAD Jul 21 12:38:08.310000 audit[4136]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=6a2f13232268 a2=98 a3=0 items=0 ppid=4057 pid=4136 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.310000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6266633734356233343661373730326530363836656532386461356231 Jul 21 12:38:08.311000 audit: BPF prog-id=126 op=LOAD Jul 21 12:38:08.311000 audit[4136]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=6a2f13231fa8 a2=98 a3=0 items=0 ppid=4057 pid=4136 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.311000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6266633734356233343661373730326530363836656532386461356231 Jul 21 12:38:08.311000 audit: BPF prog-id=126 op=UNLOAD Jul 21 12:38:08.311000 audit[4136]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4057 pid=4136 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.311000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6266633734356233343661373730326530363836656532386461356231 Jul 21 12:38:08.312000 audit: BPF prog-id=125 op=UNLOAD Jul 21 12:38:08.312000 audit[4136]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=13 a1=0 a2=0 a3=0 items=0 ppid=4057 pid=4136 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.312000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6266633734356233343661373730326530363836656532386461356231 Jul 21 12:38:08.312000 audit: BPF prog-id=127 op=LOAD Jul 21 12:38:08.312000 audit[4136]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=6a2f132324b8 a2=98 a3=0 items=0 ppid=4057 pid=4136 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.312000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6266633734356233343661373730326530363836656532386461356231 Jul 21 12:38:08.351424 containerd[2389]: time="2026-07-21T12:38:08.351283723Z" level=info msg="StartContainer for \"bfc745b346a7702e0686ee28da5b1bda769612e2f2267fd6073c975193bb967a\" returns successfully" Jul 21 12:38:08.449123 kubelet[4002]: I0721 12:38:08.448591 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="kube-system/kube-proxy-tvlvz" podStartSLOduration=1.448544995 podStartE2EDuration="1.448544995s" podCreationTimestamp="2026-07-21 12:38:07 +0000 UTC" firstStartedPulling="0001-01-01 00:00:00 +0000 UTC" lastFinishedPulling="0001-01-01 00:00:00 +0000 UTC" observedRunningTime="2026-07-21 12:38:08.446601799 +0000 UTC m=+5.399619147" watchObservedRunningTime="2026-07-21 12:38:08.448544995 +0000 UTC m=+5.401562355" Jul 21 12:38:08.690000 audit[4205]: NETFILTER_CFG table=mangle:47 family=10 entries=1 op=nft_register_chain pid=4205 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:08.690000 audit[4205]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=104 a0=3 a1=ffffcbc47800 a2=0 a3=1 items=0 ppid=4148 pid=4205 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.690000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D50524F58592D43414E415259002D74006D616E676C65 Jul 21 12:38:08.695000 audit[4206]: NETFILTER_CFG table=nat:48 family=10 entries=1 op=nft_register_chain pid=4206 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:08.695000 audit[4206]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffc3d0ff70 a2=0 a3=1 items=0 ppid=4148 pid=4206 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.695000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D50524F58592D43414E415259002D74006E6174 Jul 21 12:38:08.706000 audit[4210]: NETFILTER_CFG table=filter:49 family=10 entries=1 op=nft_register_chain pid=4210 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:08.706000 audit[4210]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=104 a0=3 a1=ffffed947f10 a2=0 a3=1 items=0 ppid=4148 pid=4210 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.706000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D50524F58592D43414E415259002D740066696C746572 Jul 21 12:38:08.707000 audit[4208]: NETFILTER_CFG table=mangle:50 family=2 entries=1 op=nft_register_chain pid=4208 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.707000 audit[4208]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=104 a0=3 a1=ffffe5a689b0 a2=0 a3=1 items=0 ppid=4148 pid=4208 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.707000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D50524F58592D43414E415259002D74006D616E676C65 Jul 21 12:38:08.719000 audit[4213]: NETFILTER_CFG table=nat:51 family=2 entries=1 op=nft_register_chain pid=4213 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.719000 audit[4213]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=fffffd7c4d40 a2=0 a3=1 items=0 ppid=4148 pid=4213 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.719000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D50524F58592D43414E415259002D74006E6174 Jul 21 12:38:08.722000 audit[4214]: NETFILTER_CFG table=filter:52 family=2 entries=1 op=nft_register_chain pid=4214 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.722000 audit[4214]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=104 a0=3 a1=fffffb414150 a2=0 a3=1 items=0 ppid=4148 pid=4214 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.722000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D50524F58592D43414E415259002D740066696C746572 Jul 21 12:38:08.803000 audit[4215]: NETFILTER_CFG table=filter:53 family=2 entries=1 op=nft_register_chain pid=4215 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.803000 audit[4215]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=108 a0=3 a1=ffffe4678af0 a2=0 a3=1 items=0 ppid=4148 pid=4215 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.803000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D45585445524E414C2D5345525649434553002D740066696C746572 Jul 21 12:38:08.808000 audit[4217]: NETFILTER_CFG table=filter:54 family=2 entries=1 op=nft_register_rule pid=4217 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.808000 audit[4217]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=752 a0=3 a1=ffffe76b5fe0 a2=0 a3=1 items=0 ppid=4148 pid=4217 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.808000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4900494E505554002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E657465732065787465726E616C6C792D76697369626C65207365727669636520706F7274616C73002D Jul 21 12:38:08.817000 audit[4220]: NETFILTER_CFG table=filter:55 family=2 entries=1 op=nft_register_rule pid=4220 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.817000 audit[4220]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=752 a0=3 a1=ffffe8860e00 a2=0 a3=1 items=0 ppid=4148 pid=4220 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.817000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4900464F5257415244002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E657465732065787465726E616C6C792D76697369626C65207365727669636520706F7274616C73 Jul 21 12:38:08.819000 audit[4221]: NETFILTER_CFG table=filter:56 family=2 entries=1 op=nft_register_chain pid=4221 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.819000 audit[4221]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffc89b9fa0 a2=0 a3=1 items=0 ppid=4148 pid=4221 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.819000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D4E4F4445504F525453002D740066696C746572 Jul 21 12:38:08.824000 audit[4223]: NETFILTER_CFG table=filter:57 family=2 entries=1 op=nft_register_rule pid=4223 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.824000 audit[4223]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=528 a0=3 a1=ffffe61b7d70 a2=0 a3=1 items=0 ppid=4148 pid=4223 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.824000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4900494E505554002D740066696C746572002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573206865616C746820636865636B207365727669636520706F727473002D6A004B5542452D4E4F4445504F525453 Jul 21 12:38:08.827000 audit[4224]: NETFILTER_CFG table=filter:58 family=2 entries=1 op=nft_register_chain pid=4224 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.827000 audit[4224]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffd101b860 a2=0 a3=1 items=0 ppid=4148 pid=4224 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.827000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D5345525649434553002D740066696C746572 Jul 21 12:38:08.836000 audit[4226]: NETFILTER_CFG table=filter:59 family=2 entries=1 op=nft_register_rule pid=4226 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.836000 audit[4226]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=744 a0=3 a1=ffffc9f6c550 a2=0 a3=1 items=0 ppid=4148 pid=4226 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.836000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4900464F5257415244002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573207365727669636520706F7274616C73002D6A004B5542452D5345525649434553 Jul 21 12:38:08.843000 audit[4229]: NETFILTER_CFG table=filter:60 family=2 entries=1 op=nft_register_rule pid=4229 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.843000 audit[4229]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=744 a0=3 a1=ffffd2228b30 a2=0 a3=1 items=0 ppid=4148 pid=4229 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.843000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D49004F5554505554002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573207365727669636520706F7274616C73002D6A004B5542452D5345525649434553 Jul 21 12:38:08.846000 audit[4230]: NETFILTER_CFG table=filter:61 family=2 entries=1 op=nft_register_chain pid=4230 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.846000 audit[4230]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffeb183370 a2=0 a3=1 items=0 ppid=4148 pid=4230 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.846000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D464F5257415244002D740066696C746572 Jul 21 12:38:08.855000 audit[4232]: NETFILTER_CFG table=filter:62 family=2 entries=1 op=nft_register_rule pid=4232 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.855000 audit[4232]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=528 a0=3 a1=ffffd2a82340 a2=0 a3=1 items=0 ppid=4148 pid=4232 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.855000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4900464F5257415244002D740066696C746572002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E6574657320666F7277617264696E672072756C6573002D6A004B5542452D464F5257415244 Jul 21 12:38:08.858000 audit[4233]: NETFILTER_CFG table=filter:63 family=2 entries=1 op=nft_register_chain pid=4233 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.858000 audit[4233]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=104 a0=3 a1=ffffd5b70920 a2=0 a3=1 items=0 ppid=4148 pid=4233 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.858000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D50524F58592D4649524557414C4C002D740066696C746572 Jul 21 12:38:08.863000 audit[4235]: NETFILTER_CFG table=filter:64 family=2 entries=1 op=nft_register_rule pid=4235 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.863000 audit[4235]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=748 a0=3 a1=ffffd42563e0 a2=0 a3=1 items=0 ppid=4148 pid=4235 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.863000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4900494E505554002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573206C6F61642062616C616E636572206669726577616C6C002D6A004B5542452D50524F5859 Jul 21 12:38:08.872000 audit[4238]: NETFILTER_CFG table=filter:65 family=2 entries=1 op=nft_register_rule pid=4238 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.872000 audit[4238]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=748 a0=3 a1=fffff89d9070 a2=0 a3=1 items=0 ppid=4148 pid=4238 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.872000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D49004F5554505554002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573206C6F61642062616C616E636572206669726577616C6C002D6A004B5542452D50524F58 Jul 21 12:38:08.883000 audit[4241]: NETFILTER_CFG table=filter:66 family=2 entries=1 op=nft_register_rule pid=4241 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.883000 audit[4241]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=748 a0=3 a1=ffffeba3dbc0 a2=0 a3=1 items=0 ppid=4148 pid=4241 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.883000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4900464F5257415244002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573206C6F61642062616C616E636572206669726577616C6C002D6A004B5542452D50524F Jul 21 12:38:08.888000 audit[4242]: NETFILTER_CFG table=nat:67 family=2 entries=1 op=nft_register_chain pid=4242 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.888000 audit[4242]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=96 a0=3 a1=fffff9bbdcd0 a2=0 a3=1 items=0 ppid=4148 pid=4242 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.888000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D5345525649434553002D74006E6174 Jul 21 12:38:08.894000 audit[4244]: NETFILTER_CFG table=nat:68 family=2 entries=1 op=nft_register_rule pid=4244 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.894000 audit[4244]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=524 a0=3 a1=ffffd18bd3f0 a2=0 a3=1 items=0 ppid=4148 pid=4244 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.894000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D49004F5554505554002D74006E6174002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573207365727669636520706F7274616C73002D6A004B5542452D5345525649434553 Jul 21 12:38:08.903000 audit[4247]: NETFILTER_CFG table=nat:69 family=2 entries=1 op=nft_register_rule pid=4247 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.903000 audit[4247]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=528 a0=3 a1=fffff9833460 a2=0 a3=1 items=0 ppid=4148 pid=4247 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.903000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4900505245524F5554494E47002D74006E6174002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573207365727669636520706F7274616C73002D6A004B5542452D5345525649434553 Jul 21 12:38:08.905000 audit[4248]: NETFILTER_CFG table=nat:70 family=2 entries=1 op=nft_register_chain pid=4248 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.905000 audit[4248]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffe2a1bc80 a2=0 a3=1 items=0 ppid=4148 pid=4248 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.905000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4E004B5542452D504F5354524F5554494E47002D74006E6174 Jul 21 12:38:08.911000 audit[4250]: NETFILTER_CFG table=nat:71 family=2 entries=1 op=nft_register_rule pid=4250 subj=system_u:system_r:kernel_t:s0 comm="iptables" Jul 21 12:38:08.911000 audit[4250]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=532 a0=3 a1=fffff4541880 a2=0 a3=1 items=0 ppid=4148 pid=4250 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.911000 audit: PROCTITLE proctitle=69707461626C6573002D770035002D4900504F5354524F5554494E47002D74006E6174002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E6574657320706F7374726F7574696E672072756C6573002D6A004B5542452D504F5354524F5554494E47 Jul 21 12:38:08.953000 audit[4256]: NETFILTER_CFG table=filter:72 family=2 entries=8 op=nft_register_rule pid=4256 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:08.953000 audit[4256]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=5248 a0=3 a1=ffffc3a84000 a2=0 a3=1 items=0 ppid=4148 pid=4256 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.953000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:08.963000 audit[4256]: NETFILTER_CFG table=nat:73 family=2 entries=14 op=nft_register_chain pid=4256 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:08.963000 audit[4256]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=5508 a0=3 a1=ffffc3a84000 a2=0 a3=1 items=0 ppid=4148 pid=4256 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.963000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:08.967000 audit[4261]: NETFILTER_CFG table=filter:74 family=10 entries=1 op=nft_register_chain pid=4261 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:08.967000 audit[4261]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=108 a0=3 a1=ffffd4ce7d20 a2=0 a3=1 items=0 ppid=4148 pid=4261 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.967000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D45585445524E414C2D5345525649434553002D740066696C746572 Jul 21 12:38:08.972000 audit[4263]: NETFILTER_CFG table=filter:75 family=10 entries=2 op=nft_register_chain pid=4263 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:08.972000 audit[4263]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=836 a0=3 a1=ffffddd51be0 a2=0 a3=1 items=0 ppid=4148 pid=4263 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.972000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4900494E505554002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E657465732065787465726E616C6C792D76697369626C65207365727669636520706F7274616C73 Jul 21 12:38:08.980000 audit[4266]: NETFILTER_CFG table=filter:76 family=10 entries=1 op=nft_register_rule pid=4266 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:08.980000 audit[4266]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=752 a0=3 a1=fffffa048c40 a2=0 a3=1 items=0 ppid=4148 pid=4266 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.980000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4900464F5257415244002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E657465732065787465726E616C6C792D76697369626C65207365727669636520706F7274616C Jul 21 12:38:08.983000 audit[4267]: NETFILTER_CFG table=filter:77 family=10 entries=1 op=nft_register_chain pid=4267 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:08.983000 audit[4267]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffffb55740 a2=0 a3=1 items=0 ppid=4148 pid=4267 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.983000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D4E4F4445504F525453002D740066696C746572 Jul 21 12:38:08.989000 audit[4269]: NETFILTER_CFG table=filter:78 family=10 entries=1 op=nft_register_rule pid=4269 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:08.989000 audit[4269]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=528 a0=3 a1=ffffde71a770 a2=0 a3=1 items=0 ppid=4148 pid=4269 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.989000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4900494E505554002D740066696C746572002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573206865616C746820636865636B207365727669636520706F727473002D6A004B5542452D4E4F4445504F525453 Jul 21 12:38:08.991000 audit[4270]: NETFILTER_CFG table=filter:79 family=10 entries=1 op=nft_register_chain pid=4270 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:08.991000 audit[4270]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffe8caab10 a2=0 a3=1 items=0 ppid=4148 pid=4270 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.991000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D5345525649434553002D740066696C746572 Jul 21 12:38:08.997000 audit[4272]: NETFILTER_CFG table=filter:80 family=10 entries=1 op=nft_register_rule pid=4272 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:08.997000 audit[4272]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=744 a0=3 a1=fffffd47c8e0 a2=0 a3=1 items=0 ppid=4148 pid=4272 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:08.997000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4900464F5257415244002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573207365727669636520706F7274616C73002D6A004B5542452D5345525649434553 Jul 21 12:38:09.007000 audit[4275]: NETFILTER_CFG table=filter:81 family=10 entries=2 op=nft_register_chain pid=4275 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.007000 audit[4275]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=828 a0=3 a1=fffffdd97cf0 a2=0 a3=1 items=0 ppid=4148 pid=4275 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.007000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D49004F5554505554002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573207365727669636520706F7274616C73002D6A004B5542452D5345525649434553 Jul 21 12:38:09.010000 audit[4276]: NETFILTER_CFG table=filter:82 family=10 entries=1 op=nft_register_chain pid=4276 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.010000 audit[4276]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=fffff1023260 a2=0 a3=1 items=0 ppid=4148 pid=4276 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.010000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D464F5257415244002D740066696C746572 Jul 21 12:38:09.018000 audit[4278]: NETFILTER_CFG table=filter:83 family=10 entries=1 op=nft_register_rule pid=4278 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.018000 audit[4278]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=528 a0=3 a1=fffff8c55e80 a2=0 a3=1 items=0 ppid=4148 pid=4278 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.018000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4900464F5257415244002D740066696C746572002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E6574657320666F7277617264696E672072756C6573002D6A004B5542452D464F5257415244 Jul 21 12:38:09.021000 audit[4279]: NETFILTER_CFG table=filter:84 family=10 entries=1 op=nft_register_chain pid=4279 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.021000 audit[4279]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=104 a0=3 a1=ffffd69f57d0 a2=0 a3=1 items=0 ppid=4148 pid=4279 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.021000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D50524F58592D4649524557414C4C002D740066696C746572 Jul 21 12:38:09.028000 audit[4281]: NETFILTER_CFG table=filter:85 family=10 entries=1 op=nft_register_rule pid=4281 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.028000 audit[4281]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=748 a0=3 a1=ffffc9a4d410 a2=0 a3=1 items=0 ppid=4148 pid=4281 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.028000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4900494E505554002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573206C6F61642062616C616E636572206669726577616C6C002D6A004B5542452D50524F58 Jul 21 12:38:09.036000 audit[4284]: NETFILTER_CFG table=filter:86 family=10 entries=1 op=nft_register_rule pid=4284 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.036000 audit[4284]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=748 a0=3 a1=ffffdf963190 a2=0 a3=1 items=0 ppid=4148 pid=4284 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.036000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D49004F5554505554002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573206C6F61642062616C616E636572206669726577616C6C002D6A004B5542452D50524F Jul 21 12:38:09.046000 audit[4287]: NETFILTER_CFG table=filter:87 family=10 entries=1 op=nft_register_rule pid=4287 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.046000 audit[4287]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=748 a0=3 a1=ffffdd1bcf40 a2=0 a3=1 items=0 ppid=4148 pid=4287 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.046000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4900464F5257415244002D740066696C746572002D6D00636F6E6E747261636B002D2D63747374617465004E4557002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573206C6F61642062616C616E636572206669726577616C6C002D6A004B5542452D5052 Jul 21 12:38:09.049000 audit[4288]: NETFILTER_CFG table=nat:88 family=10 entries=1 op=nft_register_chain pid=4288 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.049000 audit[4288]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=96 a0=3 a1=ffffff1059f0 a2=0 a3=1 items=0 ppid=4148 pid=4288 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.049000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D5345525649434553002D74006E6174 Jul 21 12:38:09.055000 audit[4290]: NETFILTER_CFG table=nat:89 family=10 entries=1 op=nft_register_rule pid=4290 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.055000 audit[4290]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=524 a0=3 a1=fffff31fe000 a2=0 a3=1 items=0 ppid=4148 pid=4290 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.055000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D49004F5554505554002D74006E6174002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573207365727669636520706F7274616C73002D6A004B5542452D5345525649434553 Jul 21 12:38:09.063000 audit[4293]: NETFILTER_CFG table=nat:90 family=10 entries=1 op=nft_register_rule pid=4293 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.063000 audit[4293]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=528 a0=3 a1=ffffdddcc870 a2=0 a3=1 items=0 ppid=4148 pid=4293 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.063000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4900505245524F5554494E47002D74006E6174002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E65746573207365727669636520706F7274616C73002D6A004B5542452D5345525649434553 Jul 21 12:38:09.066000 audit[4294]: NETFILTER_CFG table=nat:91 family=10 entries=1 op=nft_register_chain pid=4294 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.066000 audit[4294]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffcd3a2a60 a2=0 a3=1 items=0 ppid=4148 pid=4294 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.066000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D504F5354524F5554494E47002D74006E6174 Jul 21 12:38:09.071000 audit[4296]: NETFILTER_CFG table=nat:92 family=10 entries=2 op=nft_register_chain pid=4296 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.071000 audit[4296]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=612 a0=3 a1=ffffe637ac10 a2=0 a3=1 items=0 ppid=4148 pid=4296 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.071000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4900504F5354524F5554494E47002D74006E6174002D6D00636F6D6D656E74002D2D636F6D6D656E74006B756265726E6574657320706F7374726F7574696E672072756C6573002D6A004B5542452D504F5354524F5554494E47 Jul 21 12:38:09.074000 audit[4297]: NETFILTER_CFG table=filter:93 family=10 entries=1 op=nft_register_chain pid=4297 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.074000 audit[4297]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=100 a0=3 a1=ffffca82de70 a2=0 a3=1 items=0 ppid=4148 pid=4297 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.074000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4E004B5542452D4649524557414C4C002D740066696C746572 Jul 21 12:38:09.080000 audit[4299]: NETFILTER_CFG table=filter:94 family=10 entries=1 op=nft_register_rule pid=4299 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.080000 audit[4299]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=228 a0=3 a1=ffffe002ec40 a2=0 a3=1 items=0 ppid=4148 pid=4299 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.080000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D4900494E505554002D740066696C746572002D6A004B5542452D4649524557414C4C Jul 21 12:38:09.087000 audit[4302]: NETFILTER_CFG table=filter:95 family=10 entries=1 op=nft_register_rule pid=4302 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Jul 21 12:38:09.087000 audit[4302]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=228 a0=3 a1=ffffdfc36f60 a2=0 a3=1 items=0 ppid=4148 pid=4302 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.087000 audit: PROCTITLE proctitle=6970367461626C6573002D770035002D49004F5554505554002D740066696C746572002D6A004B5542452D4649524557414C4C Jul 21 12:38:09.094000 audit[4304]: NETFILTER_CFG table=filter:96 family=10 entries=3 op=nft_register_rule pid=4304 subj=system_u:system_r:kernel_t:s0 comm="ip6tables-resto" Jul 21 12:38:09.094000 audit[4304]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=2088 a0=3 a1=ffffc0bcfc60 a2=0 a3=1 items=0 ppid=4148 pid=4304 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables-resto" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.094000 audit: PROCTITLE proctitle=6970367461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:09.095000 audit[4304]: NETFILTER_CFG table=nat:97 family=10 entries=7 op=nft_register_chain pid=4304 subj=system_u:system_r:kernel_t:s0 comm="ip6tables-resto" Jul 21 12:38:09.095000 audit[4304]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=2056 a0=3 a1=ffffc0bcfc60 a2=0 a3=1 items=0 ppid=4148 pid=4304 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables-resto" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:09.095000 audit: PROCTITLE proctitle=6970367461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:09.602873 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount445420473.mount: Deactivated successfully. Jul 21 12:38:11.612089 containerd[2389]: time="2026-07-21T12:38:11.612003947Z" level=info msg="ImageCreate event name:\"quay.io/tigera/operator:v1.42.3\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:11.613811 containerd[2389]: time="2026-07-21T12:38:11.613347707Z" level=info msg="stop pulling image quay.io/tigera/operator:v1.42.3: active requests=0, bytes read=23924794" Jul 21 12:38:11.615075 containerd[2389]: time="2026-07-21T12:38:11.615020375Z" level=info msg="ImageCreate event name:\"sha256:dca05dafd79d94d90f2ccb9a9839401434feda1267fec3d72742a6c90dc56a30\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:11.620139 containerd[2389]: time="2026-07-21T12:38:11.620088947Z" level=info msg="ImageCreate event name:\"quay.io/tigera/operator@sha256:4f32a054d5da52731f5f633816ac29cd98ffe97f69903cc04ec5ac60c86e6a02\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:11.621434 containerd[2389]: time="2026-07-21T12:38:11.621362015Z" level=info msg="Pulled image \"quay.io/tigera/operator:v1.42.3\" with image id \"sha256:dca05dafd79d94d90f2ccb9a9839401434feda1267fec3d72742a6c90dc56a30\", repo tag \"quay.io/tigera/operator:v1.42.3\", repo digest \"quay.io/tigera/operator@sha256:4f32a054d5da52731f5f633816ac29cd98ffe97f69903cc04ec5ac60c86e6a02\", size \"26505300\" in 3.345658972s" Jul 21 12:38:11.621578 containerd[2389]: time="2026-07-21T12:38:11.621548231Z" level=info msg="PullImage \"quay.io/tigera/operator:v1.42.3\" returns image reference \"sha256:dca05dafd79d94d90f2ccb9a9839401434feda1267fec3d72742a6c90dc56a30\"" Jul 21 12:38:11.629971 containerd[2389]: time="2026-07-21T12:38:11.629912879Z" level=info msg="CreateContainer within sandbox \"b208cb9d0711e1f2a03ff644c8d838eaeccf8baba3b4289fbf7b49452b21150a\" for container name:\"tigera-operator\"" Jul 21 12:38:11.659435 containerd[2389]: time="2026-07-21T12:38:11.659343155Z" level=info msg="CreateContainer within sandbox \"b208cb9d0711e1f2a03ff644c8d838eaeccf8baba3b4289fbf7b49452b21150a\" for name:\"tigera-operator\" returns container id \"524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe\"" Jul 21 12:38:11.661654 containerd[2389]: time="2026-07-21T12:38:11.661554407Z" level=info msg="StartContainer for \"524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe\"" Jul 21 12:38:11.665870 containerd[2389]: time="2026-07-21T12:38:11.665628491Z" level=info msg="connecting to shim 524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe" address="unix:///run/containerd/s/f6f8fbb44c7afa9f7bcbdf432bdcf5ef88e817f0958122465f64be11ade24d21" protocol=ttrpc version=3 Jul 21 12:38:11.710591 systemd[1]: Started cri-containerd-524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe.scope - libcontainer container 524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe. Jul 21 12:38:11.742000 audit: BPF prog-id=128 op=LOAD Jul 21 12:38:11.743000 audit: BPF prog-id=129 op=LOAD Jul 21 12:38:11.743000 audit[4314]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2385d640df90 a2=98 a3=0 items=0 ppid=4106 pid=4314 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:11.743000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3532346636613366636137383166653962396137363665316639303866 Jul 21 12:38:11.744000 audit: BPF prog-id=129 op=UNLOAD Jul 21 12:38:11.744000 audit[4314]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=4106 pid=4314 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:11.744000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3532346636613366636137383166653962396137363665316639303866 Jul 21 12:38:11.744000 audit: BPF prog-id=130 op=LOAD Jul 21 12:38:11.744000 audit[4314]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2385d640e268 a2=98 a3=0 items=0 ppid=4106 pid=4314 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:11.744000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3532346636613366636137383166653962396137363665316639303866 Jul 21 12:38:11.744000 audit: BPF prog-id=131 op=LOAD Jul 21 12:38:11.744000 audit[4314]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=2385d640dfa8 a2=98 a3=0 items=0 ppid=4106 pid=4314 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:11.744000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3532346636613366636137383166653962396137363665316639303866 Jul 21 12:38:11.744000 audit: BPF prog-id=131 op=UNLOAD Jul 21 12:38:11.744000 audit[4314]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=4106 pid=4314 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:11.744000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3532346636613366636137383166653962396137363665316639303866 Jul 21 12:38:11.744000 audit: BPF prog-id=130 op=UNLOAD Jul 21 12:38:11.744000 audit[4314]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=4106 pid=4314 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:11.744000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3532346636613366636137383166653962396137363665316639303866 Jul 21 12:38:11.745000 audit: BPF prog-id=132 op=LOAD Jul 21 12:38:11.745000 audit[4314]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2385d640e4b8 a2=98 a3=0 items=0 ppid=4106 pid=4314 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:11.745000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3532346636613366636137383166653962396137363665316639303866 Jul 21 12:38:11.788261 containerd[2389]: time="2026-07-21T12:38:11.788085096Z" level=info msg="StartContainer for \"524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe\" returns successfully" Jul 21 12:38:12.483426 kubelet[4002]: I0721 12:38:12.483246 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="tigera-operator/tigera-operator-55f97df97b-x6p46" podStartSLOduration=2.132651944 podStartE2EDuration="5.482467116s" podCreationTimestamp="2026-07-21 12:38:07 +0000 UTC" firstStartedPulling="2026-07-21 12:38:08.273144739 +0000 UTC m=+5.226162063" lastFinishedPulling="2026-07-21 12:38:11.622959899 +0000 UTC m=+8.575977235" observedRunningTime="2026-07-21 12:38:12.483162072 +0000 UTC m=+9.436179408" watchObservedRunningTime="2026-07-21 12:38:12.482467116 +0000 UTC m=+9.435484440" Jul 21 12:38:19.742603 sudo[2748]: pam_unix(sudo:session): session closed for user root Jul 21 12:38:19.741000 audit[2748]: AUDIT1106 pid=2748 uid=500 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:38:19.745235 kernel: kauditd_printk_skb: 224 callbacks suppressed Jul 21 12:38:19.745282 kernel: audit: type=1106 audit(1784637499.741:463): pid=2748 uid=500 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:38:19.741000 audit[2748]: AUDIT1104 pid=2748 uid=500 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:38:19.750484 kernel: audit: type=1104 audit(1784637499.741:464): pid=2748 uid=500 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Jul 21 12:38:19.903845 sshd[2747]: Connection closed by 20.76.1.115 port 37106 Jul 21 12:38:19.905520 sshd-session[2743]: pam_unix(sshd:session): session closed for user core Jul 21 12:38:19.905000 audit[2743]: AUDIT1106 pid=2743 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:38:19.905000 audit[2743]: AUDIT1104 pid=2743 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:38:19.916307 systemd[1]: sshd@6-4100-172.31.16.165:22-20.76.1.115:37106.service: Deactivated successfully. Jul 21 12:38:19.916000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@6-4100-172.31.16.165:22-20.76.1.115:37106 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:19.923142 systemd[1]: session-8.scope: Deactivated successfully. Jul 21 12:38:19.923604 kernel: audit: type=1106 audit(1784637499.905:465): pid=2743 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:38:19.923667 kernel: audit: type=1104 audit(1784637499.905:466): pid=2743 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:38:19.923700 kernel: audit: type=1131 audit(1784637499.916:467): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@6-4100-172.31.16.165:22-20.76.1.115:37106 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:19.924826 systemd[1]: session-8.scope: Consumed 13.332s CPU time over 55.609s wall clock time, 209.8M memory peak. Jul 21 12:38:19.930162 systemd-logind[2347]: Session 8 logged out. Waiting for processes to exit. Jul 21 12:38:19.934900 systemd-logind[2347]: Removed session 8. Jul 21 12:38:26.666000 audit[4394]: NETFILTER_CFG table=filter:98 family=2 entries=14 op=nft_register_rule pid=4394 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:26.666000 audit[4394]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=5248 a0=3 a1=ffffe1d7fb90 a2=0 a3=1 items=0 ppid=4148 pid=4394 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:26.678291 kernel: audit: type=1325 audit(1784637506.666:468): table=filter:98 family=2 entries=14 op=nft_register_rule pid=4394 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:26.678426 kernel: audit: type=1300 audit(1784637506.666:468): arch=c00000b7 syscall=211 success=yes exit=5248 a0=3 a1=ffffe1d7fb90 a2=0 a3=1 items=0 ppid=4148 pid=4394 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:26.666000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:26.684957 kernel: audit: type=1327 audit(1784637506.666:468): proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:26.672000 audit[4394]: NETFILTER_CFG table=nat:99 family=2 entries=12 op=nft_register_rule pid=4394 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:26.688338 kernel: audit: type=1325 audit(1784637506.672:469): table=nat:99 family=2 entries=12 op=nft_register_rule pid=4394 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:26.672000 audit[4394]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=2700 a0=3 a1=ffffe1d7fb90 a2=0 a3=1 items=0 ppid=4148 pid=4394 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:26.694972 kernel: audit: type=1300 audit(1784637506.672:469): arch=c00000b7 syscall=211 success=yes exit=2700 a0=3 a1=ffffe1d7fb90 a2=0 a3=1 items=0 ppid=4148 pid=4394 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:26.672000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:26.701886 kernel: audit: type=1327 audit(1784637506.672:469): proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:27.715000 audit[4396]: NETFILTER_CFG table=filter:100 family=2 entries=17 op=nft_register_rule pid=4396 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:27.715000 audit[4396]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=7480 a0=3 a1=ffffde2618c0 a2=0 a3=1 items=0 ppid=4148 pid=4396 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:27.727886 kernel: audit: type=1325 audit(1784637507.715:470): table=filter:100 family=2 entries=17 op=nft_register_rule pid=4396 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:27.728015 kernel: audit: type=1300 audit(1784637507.715:470): arch=c00000b7 syscall=211 success=yes exit=7480 a0=3 a1=ffffde2618c0 a2=0 a3=1 items=0 ppid=4148 pid=4396 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:27.715000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:27.730838 kernel: audit: type=1327 audit(1784637507.715:470): proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:27.726000 audit[4396]: NETFILTER_CFG table=nat:101 family=2 entries=12 op=nft_register_rule pid=4396 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:27.736381 kernel: audit: type=1325 audit(1784637507.726:471): table=nat:101 family=2 entries=12 op=nft_register_rule pid=4396 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:27.726000 audit[4396]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=2700 a0=3 a1=ffffde2618c0 a2=0 a3=1 items=0 ppid=4148 pid=4396 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:27.726000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:29.686000 audit[4398]: NETFILTER_CFG table=filter:102 family=2 entries=21 op=nft_register_rule pid=4398 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:29.686000 audit[4398]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=8224 a0=3 a1=ffffcac21d70 a2=0 a3=1 items=0 ppid=4148 pid=4398 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:29.686000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:29.696000 audit[4398]: NETFILTER_CFG table=nat:103 family=2 entries=12 op=nft_register_rule pid=4398 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:29.696000 audit[4398]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=2700 a0=3 a1=ffffcac21d70 a2=0 a3=1 items=0 ppid=4148 pid=4398 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:29.696000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:29.750455 systemd[1]: Created slice kubepods-besteffort-pod009f41cd_d1d0_44bd_a3c2_44b86858bbdc.slice - libcontainer container kubepods-besteffort-pod009f41cd_d1d0_44bd_a3c2_44b86858bbdc.slice. Jul 21 12:38:29.799289 kubelet[4002]: I0721 12:38:29.799223 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"tigera-ca-bundle\" (UniqueName: \"kubernetes.io/configmap/009f41cd-d1d0-44bd-a3c2-44b86858bbdc-tigera-ca-bundle\") pod \"calico-typha-7d9f989c4-jmmmv\" (UID: \"009f41cd-d1d0-44bd-a3c2-44b86858bbdc\") " pod="calico-system/calico-typha-7d9f989c4-jmmmv" Jul 21 12:38:29.799289 kubelet[4002]: I0721 12:38:29.799298 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-4hvld\" (UniqueName: \"kubernetes.io/projected/009f41cd-d1d0-44bd-a3c2-44b86858bbdc-kube-api-access-4hvld\") pod \"calico-typha-7d9f989c4-jmmmv\" (UID: \"009f41cd-d1d0-44bd-a3c2-44b86858bbdc\") " pod="calico-system/calico-typha-7d9f989c4-jmmmv" Jul 21 12:38:29.800551 kubelet[4002]: I0721 12:38:29.799342 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"typha-certs\" (UniqueName: \"kubernetes.io/secret/009f41cd-d1d0-44bd-a3c2-44b86858bbdc-typha-certs\") pod \"calico-typha-7d9f989c4-jmmmv\" (UID: \"009f41cd-d1d0-44bd-a3c2-44b86858bbdc\") " pod="calico-system/calico-typha-7d9f989c4-jmmmv" Jul 21 12:38:30.006363 systemd[1]: Created slice kubepods-besteffort-pod966fd328_b8e6_4fdf_bc0e_5eeda3a0163a.slice - libcontainer container kubepods-besteffort-pod966fd328_b8e6_4fdf_bc0e_5eeda3a0163a.slice. Jul 21 12:38:30.061556 containerd[2389]: time="2026-07-21T12:38:30.061275591Z" level=info msg="RunPodSandbox for name:\"calico-typha-7d9f989c4-jmmmv\" uid:\"009f41cd-d1d0-44bd-a3c2-44b86858bbdc\" namespace:\"calico-system\"" Jul 21 12:38:30.104388 kubelet[4002]: I0721 12:38:30.102759 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"xtables-lock\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-xtables-lock\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.104388 kubelet[4002]: I0721 12:38:30.102840 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"cni-bin-dir\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-cni-bin-dir\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.104388 kubelet[4002]: I0721 12:38:30.102942 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"cni-log-dir\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-cni-log-dir\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.104388 kubelet[4002]: I0721 12:38:30.103026 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"node-certs\" (UniqueName: \"kubernetes.io/secret/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-node-certs\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.104388 kubelet[4002]: I0721 12:38:30.103095 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"nodeproc\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-nodeproc\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.104778 kubelet[4002]: I0721 12:38:30.103253 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"policysync\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-policysync\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.104778 kubelet[4002]: I0721 12:38:30.103364 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"cni-net-dir\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-cni-net-dir\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.104778 kubelet[4002]: I0721 12:38:30.103535 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"var-run-calico\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-var-run-calico\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.104778 kubelet[4002]: I0721 12:38:30.103607 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-5szc8\" (UniqueName: \"kubernetes.io/projected/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-kube-api-access-5szc8\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.104778 kubelet[4002]: I0721 12:38:30.103659 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"tigera-ca-bundle\" (UniqueName: \"kubernetes.io/configmap/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-tigera-ca-bundle\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.105097 kubelet[4002]: I0721 12:38:30.103830 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"var-lib-calico\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-var-lib-calico\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.105097 kubelet[4002]: I0721 12:38:30.103905 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"flexvol-driver-host\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-flexvol-driver-host\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.105097 kubelet[4002]: I0721 12:38:30.104080 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"sys-fs\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-sys-fs\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.110373 kubelet[4002]: I0721 12:38:30.106334 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"lib-modules\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-lib-modules\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.110373 kubelet[4002]: I0721 12:38:30.106451 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"bpffs\" (UniqueName: \"kubernetes.io/host-path/966fd328-b8e6-4fdf-bc0e-5eeda3a0163a-bpffs\") pod \"calico-node-gm5s5\" (UID: \"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\") " pod="calico-system/calico-node-gm5s5" Jul 21 12:38:30.125472 containerd[2389]: time="2026-07-21T12:38:30.125398179Z" level=info msg="connecting to shim f026658de75ef4072f2e0aad947243fcf86831251ae2fb39bee91bc4e17f5975" address="unix:///run/containerd/s/035bbdefce68f037649265e292fbc560fed031c815ed5cca3fc117be2d4b4058" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:38:30.156229 kubelet[4002]: E0721 12:38:30.154182 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:30.214663 systemd[1]: Started cri-containerd-f026658de75ef4072f2e0aad947243fcf86831251ae2fb39bee91bc4e17f5975.scope - libcontainer container f026658de75ef4072f2e0aad947243fcf86831251ae2fb39bee91bc4e17f5975. Jul 21 12:38:30.225240 kubelet[4002]: E0721 12:38:30.223528 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.225240 kubelet[4002]: W0721 12:38:30.223568 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.225240 kubelet[4002]: E0721 12:38:30.223607 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.239023 kubelet[4002]: E0721 12:38:30.238967 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.239180 kubelet[4002]: W0721 12:38:30.239028 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.239180 kubelet[4002]: E0721 12:38:30.239068 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.250514 kubelet[4002]: E0721 12:38:30.249494 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.250514 kubelet[4002]: W0721 12:38:30.250278 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.250514 kubelet[4002]: E0721 12:38:30.250319 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.251545 kubelet[4002]: E0721 12:38:30.251379 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.253236 kubelet[4002]: W0721 12:38:30.251959 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.253761 kubelet[4002]: E0721 12:38:30.253521 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.254105 kubelet[4002]: E0721 12:38:30.254079 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.254283 kubelet[4002]: W0721 12:38:30.254254 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.254565 kubelet[4002]: E0721 12:38:30.254395 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.257328 kubelet[4002]: E0721 12:38:30.255658 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.257328 kubelet[4002]: W0721 12:38:30.255693 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.257328 kubelet[4002]: E0721 12:38:30.255724 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.257707 kubelet[4002]: E0721 12:38:30.257680 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.257824 kubelet[4002]: W0721 12:38:30.257797 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.257978 kubelet[4002]: E0721 12:38:30.257936 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.259266 kubelet[4002]: E0721 12:38:30.258706 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.259700 kubelet[4002]: W0721 12:38:30.259446 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.259700 kubelet[4002]: E0721 12:38:30.259493 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.261482 kubelet[4002]: E0721 12:38:30.261431 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.261482 kubelet[4002]: W0721 12:38:30.261471 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.261677 kubelet[4002]: E0721 12:38:30.261504 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.262317 kubelet[4002]: E0721 12:38:30.262271 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.262317 kubelet[4002]: W0721 12:38:30.262310 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.264098 kubelet[4002]: E0721 12:38:30.262341 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.264098 kubelet[4002]: E0721 12:38:30.263046 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.264098 kubelet[4002]: W0721 12:38:30.263068 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.264098 kubelet[4002]: E0721 12:38:30.263096 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.264098 kubelet[4002]: E0721 12:38:30.263581 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.264098 kubelet[4002]: W0721 12:38:30.263603 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.264098 kubelet[4002]: E0721 12:38:30.263626 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.264098 kubelet[4002]: E0721 12:38:30.264003 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.264098 kubelet[4002]: W0721 12:38:30.264021 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.264098 kubelet[4002]: E0721 12:38:30.264044 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.264648 kubelet[4002]: E0721 12:38:30.264444 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.264648 kubelet[4002]: W0721 12:38:30.264461 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.264648 kubelet[4002]: E0721 12:38:30.264483 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.265235 kubelet[4002]: E0721 12:38:30.264938 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.265235 kubelet[4002]: W0721 12:38:30.264967 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.265235 kubelet[4002]: E0721 12:38:30.264993 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.265451 kubelet[4002]: E0721 12:38:30.265315 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.265451 kubelet[4002]: W0721 12:38:30.265332 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.265451 kubelet[4002]: E0721 12:38:30.265353 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.266067 kubelet[4002]: E0721 12:38:30.266002 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.266067 kubelet[4002]: W0721 12:38:30.266035 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.266067 kubelet[4002]: E0721 12:38:30.266066 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.267500 kubelet[4002]: E0721 12:38:30.266401 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.267500 kubelet[4002]: W0721 12:38:30.266416 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.267500 kubelet[4002]: E0721 12:38:30.266435 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.267500 kubelet[4002]: E0721 12:38:30.266698 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.267500 kubelet[4002]: W0721 12:38:30.266712 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.267500 kubelet[4002]: E0721 12:38:30.266730 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.267500 kubelet[4002]: E0721 12:38:30.267427 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.267500 kubelet[4002]: W0721 12:38:30.267450 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.267500 kubelet[4002]: E0721 12:38:30.267477 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.271332 kubelet[4002]: E0721 12:38:30.268337 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.271332 kubelet[4002]: W0721 12:38:30.268400 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.271332 kubelet[4002]: E0721 12:38:30.268432 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.271332 kubelet[4002]: E0721 12:38:30.269587 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.271332 kubelet[4002]: W0721 12:38:30.269611 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.271332 kubelet[4002]: E0721 12:38:30.269659 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.284538 kubelet[4002]: E0721 12:38:30.284484 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.284703 kubelet[4002]: W0721 12:38:30.284525 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.284703 kubelet[4002]: E0721 12:38:30.284684 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.306000 audit: BPF prog-id=133 op=LOAD Jul 21 12:38:30.308000 audit: BPF prog-id=134 op=LOAD Jul 21 12:38:30.308000 audit[4420]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=3e1127779f90 a2=98 a3=0 items=0 ppid=4409 pid=4420 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.308000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6630323636353864653735656634303732663265306161643934373234 Jul 21 12:38:30.308000 audit: BPF prog-id=134 op=UNLOAD Jul 21 12:38:30.308000 audit[4420]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4409 pid=4420 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.308000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6630323636353864653735656634303732663265306161643934373234 Jul 21 12:38:30.308000 audit: BPF prog-id=135 op=LOAD Jul 21 12:38:30.308000 audit[4420]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=3e112777a268 a2=98 a3=0 items=0 ppid=4409 pid=4420 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.308000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6630323636353864653735656634303732663265306161643934373234 Jul 21 12:38:30.309000 audit: BPF prog-id=136 op=LOAD Jul 21 12:38:30.309000 audit[4420]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=3e1127779fa8 a2=98 a3=0 items=0 ppid=4409 pid=4420 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.309000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6630323636353864653735656634303732663265306161643934373234 Jul 21 12:38:30.309000 audit: BPF prog-id=136 op=UNLOAD Jul 21 12:38:30.309000 audit[4420]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=4409 pid=4420 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.309000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6630323636353864653735656634303732663265306161643934373234 Jul 21 12:38:30.310000 audit: BPF prog-id=135 op=UNLOAD Jul 21 12:38:30.310000 audit[4420]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4409 pid=4420 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.310000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6630323636353864653735656634303732663265306161643934373234 Jul 21 12:38:30.312529 kubelet[4002]: E0721 12:38:30.309443 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.310000 audit: BPF prog-id=137 op=LOAD Jul 21 12:38:30.310000 audit[4420]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=3e112777a4b8 a2=98 a3=0 items=0 ppid=4409 pid=4420 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.310000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6630323636353864653735656634303732663265306161643934373234 Jul 21 12:38:30.314976 kubelet[4002]: W0721 12:38:30.312680 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.314976 kubelet[4002]: E0721 12:38:30.312751 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.314976 kubelet[4002]: I0721 12:38:30.312813 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kubelet-dir\" (UniqueName: \"kubernetes.io/host-path/e8df5361-881a-429a-bf39-9bdb2f450187-kubelet-dir\") pod \"csi-node-driver-4np6n\" (UID: \"e8df5361-881a-429a-bf39-9bdb2f450187\") " pod="calico-system/csi-node-driver-4np6n" Jul 21 12:38:30.314976 kubelet[4002]: E0721 12:38:30.313225 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.314976 kubelet[4002]: W0721 12:38:30.313257 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.314976 kubelet[4002]: E0721 12:38:30.313282 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.314976 kubelet[4002]: I0721 12:38:30.313314 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"registration-dir\" (UniqueName: \"kubernetes.io/host-path/e8df5361-881a-429a-bf39-9bdb2f450187-registration-dir\") pod \"csi-node-driver-4np6n\" (UID: \"e8df5361-881a-429a-bf39-9bdb2f450187\") " pod="calico-system/csi-node-driver-4np6n" Jul 21 12:38:30.314976 kubelet[4002]: E0721 12:38:30.314410 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.317288 kubelet[4002]: W0721 12:38:30.314440 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.317288 kubelet[4002]: E0721 12:38:30.314471 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.317288 kubelet[4002]: I0721 12:38:30.314526 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-nsj48\" (UniqueName: \"kubernetes.io/projected/e8df5361-881a-429a-bf39-9bdb2f450187-kube-api-access-nsj48\") pod \"csi-node-driver-4np6n\" (UID: \"e8df5361-881a-429a-bf39-9bdb2f450187\") " pod="calico-system/csi-node-driver-4np6n" Jul 21 12:38:30.317288 kubelet[4002]: E0721 12:38:30.316037 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.317288 kubelet[4002]: W0721 12:38:30.316190 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.317288 kubelet[4002]: E0721 12:38:30.316402 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.317288 kubelet[4002]: E0721 12:38:30.319477 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.317288 kubelet[4002]: W0721 12:38:30.319513 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.317288 kubelet[4002]: E0721 12:38:30.319548 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.320698 kubelet[4002]: E0721 12:38:30.320440 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.320698 kubelet[4002]: W0721 12:38:30.320465 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.320698 kubelet[4002]: E0721 12:38:30.320493 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.320698 kubelet[4002]: I0721 12:38:30.320546 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"varrun\" (UniqueName: \"kubernetes.io/host-path/e8df5361-881a-429a-bf39-9bdb2f450187-varrun\") pod \"csi-node-driver-4np6n\" (UID: \"e8df5361-881a-429a-bf39-9bdb2f450187\") " pod="calico-system/csi-node-driver-4np6n" Jul 21 12:38:30.321187 kubelet[4002]: E0721 12:38:30.321142 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.321187 kubelet[4002]: W0721 12:38:30.321178 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.321380 kubelet[4002]: E0721 12:38:30.321329 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.322985 kubelet[4002]: E0721 12:38:30.322933 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.322985 kubelet[4002]: W0721 12:38:30.322981 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.323253 kubelet[4002]: E0721 12:38:30.323015 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.325012 containerd[2389]: time="2026-07-21T12:38:30.324880660Z" level=info msg="RunPodSandbox for name:\"calico-node-gm5s5\" uid:\"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\" namespace:\"calico-system\"" Jul 21 12:38:30.325357 kubelet[4002]: E0721 12:38:30.324918 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.325357 kubelet[4002]: W0721 12:38:30.324959 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.325357 kubelet[4002]: E0721 12:38:30.325111 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.326516 kubelet[4002]: I0721 12:38:30.325435 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"socket-dir\" (UniqueName: \"kubernetes.io/host-path/e8df5361-881a-429a-bf39-9bdb2f450187-socket-dir\") pod \"csi-node-driver-4np6n\" (UID: \"e8df5361-881a-429a-bf39-9bdb2f450187\") " pod="calico-system/csi-node-driver-4np6n" Jul 21 12:38:30.326913 kubelet[4002]: E0721 12:38:30.326855 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.326913 kubelet[4002]: W0721 12:38:30.326897 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.327094 kubelet[4002]: E0721 12:38:30.326936 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.329358 kubelet[4002]: E0721 12:38:30.329306 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.329358 kubelet[4002]: W0721 12:38:30.329348 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.329629 kubelet[4002]: E0721 12:38:30.329383 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.330364 kubelet[4002]: E0721 12:38:30.330316 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.330364 kubelet[4002]: W0721 12:38:30.330355 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.330596 kubelet[4002]: E0721 12:38:30.330387 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.333081 kubelet[4002]: E0721 12:38:30.333017 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.333081 kubelet[4002]: W0721 12:38:30.333064 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.333345 kubelet[4002]: E0721 12:38:30.333099 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.334493 kubelet[4002]: E0721 12:38:30.334448 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.336102 kubelet[4002]: W0721 12:38:30.334485 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.336277 kubelet[4002]: E0721 12:38:30.336119 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.337407 kubelet[4002]: E0721 12:38:30.337359 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.337407 kubelet[4002]: W0721 12:38:30.337398 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.337616 kubelet[4002]: E0721 12:38:30.337431 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.372617 containerd[2389]: time="2026-07-21T12:38:30.372185260Z" level=info msg="connecting to shim 5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09" address="unix:///run/containerd/s/40a333afa61a779671eddc82c3f5b50b9b0e8c216cdeaee0ce92b28c8929272f" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:38:30.434778 kubelet[4002]: E0721 12:38:30.434726 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.434778 kubelet[4002]: W0721 12:38:30.434765 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.435323 kubelet[4002]: E0721 12:38:30.434797 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.435444 kubelet[4002]: E0721 12:38:30.435393 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.435444 kubelet[4002]: W0721 12:38:30.435427 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.435645 kubelet[4002]: E0721 12:38:30.435455 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.436070 kubelet[4002]: E0721 12:38:30.436027 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.436070 kubelet[4002]: W0721 12:38:30.436061 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.436600 kubelet[4002]: E0721 12:38:30.436089 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.436865 kubelet[4002]: E0721 12:38:30.436836 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.437107 kubelet[4002]: W0721 12:38:30.436960 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.437107 kubelet[4002]: E0721 12:38:30.436997 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.440723 kubelet[4002]: E0721 12:38:30.440671 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.441054 kubelet[4002]: W0721 12:38:30.440872 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.441054 kubelet[4002]: E0721 12:38:30.440912 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.442557 kubelet[4002]: E0721 12:38:30.442447 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.444319 kubelet[4002]: W0721 12:38:30.442723 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.444319 kubelet[4002]: E0721 12:38:30.442764 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.445579 kubelet[4002]: E0721 12:38:30.445377 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.445579 kubelet[4002]: W0721 12:38:30.445411 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.445579 kubelet[4002]: E0721 12:38:30.445443 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.449563 kubelet[4002]: E0721 12:38:30.449265 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.449563 kubelet[4002]: W0721 12:38:30.449309 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.449563 kubelet[4002]: E0721 12:38:30.449343 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.451006 kubelet[4002]: E0721 12:38:30.450746 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.451006 kubelet[4002]: W0721 12:38:30.450814 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.451006 kubelet[4002]: E0721 12:38:30.450847 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.452670 kubelet[4002]: E0721 12:38:30.452633 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.452997 kubelet[4002]: W0721 12:38:30.452966 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.454224 kubelet[4002]: E0721 12:38:30.453125 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.455476 kubelet[4002]: E0721 12:38:30.455411 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.458018 kubelet[4002]: W0721 12:38:30.457647 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.458018 kubelet[4002]: E0721 12:38:30.457711 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.460532 kubelet[4002]: E0721 12:38:30.460301 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.460532 kubelet[4002]: W0721 12:38:30.460357 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.460532 kubelet[4002]: E0721 12:38:30.460395 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.465026 kubelet[4002]: E0721 12:38:30.464646 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.465026 kubelet[4002]: W0721 12:38:30.464681 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.465026 kubelet[4002]: E0721 12:38:30.464714 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.465851 kubelet[4002]: E0721 12:38:30.465453 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.465851 kubelet[4002]: W0721 12:38:30.465482 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.465851 kubelet[4002]: E0721 12:38:30.465511 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.466407 kubelet[4002]: E0721 12:38:30.466228 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.466407 kubelet[4002]: W0721 12:38:30.466257 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.466407 kubelet[4002]: E0721 12:38:30.466285 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.468302 kubelet[4002]: E0721 12:38:30.467845 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.468302 kubelet[4002]: W0721 12:38:30.467883 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.468302 kubelet[4002]: E0721 12:38:30.467915 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.470238 kubelet[4002]: E0721 12:38:30.469631 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.470238 kubelet[4002]: W0721 12:38:30.469677 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.470238 kubelet[4002]: E0721 12:38:30.469714 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.472270 kubelet[4002]: E0721 12:38:30.470373 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.472270 kubelet[4002]: W0721 12:38:30.470398 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.472270 kubelet[4002]: E0721 12:38:30.470426 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.472270 kubelet[4002]: E0721 12:38:30.471490 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.472270 kubelet[4002]: W0721 12:38:30.471515 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.472270 kubelet[4002]: E0721 12:38:30.471543 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.474401 kubelet[4002]: E0721 12:38:30.473498 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.474401 kubelet[4002]: W0721 12:38:30.473536 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.474401 kubelet[4002]: E0721 12:38:30.473569 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.474401 kubelet[4002]: E0721 12:38:30.473928 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.474401 kubelet[4002]: W0721 12:38:30.473964 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.474401 kubelet[4002]: E0721 12:38:30.473989 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.476987 kubelet[4002]: E0721 12:38:30.474466 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.476987 kubelet[4002]: W0721 12:38:30.474487 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.476987 kubelet[4002]: E0721 12:38:30.474511 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.476987 kubelet[4002]: E0721 12:38:30.476295 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.476987 kubelet[4002]: W0721 12:38:30.476323 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.476987 kubelet[4002]: E0721 12:38:30.476357 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.480313 kubelet[4002]: E0721 12:38:30.478467 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.480313 kubelet[4002]: W0721 12:38:30.478709 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.480313 kubelet[4002]: E0721 12:38:30.478745 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.480313 kubelet[4002]: E0721 12:38:30.480144 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.480313 kubelet[4002]: W0721 12:38:30.480174 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.480313 kubelet[4002]: E0721 12:38:30.480226 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.493601 systemd[1]: Started cri-containerd-5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09.scope - libcontainer container 5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09. Jul 21 12:38:30.514895 kubelet[4002]: E0721 12:38:30.514758 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:30.514895 kubelet[4002]: W0721 12:38:30.514820 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:30.514895 kubelet[4002]: E0721 12:38:30.514856 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:30.572000 audit: BPF prog-id=138 op=LOAD Jul 21 12:38:30.575000 audit: BPF prog-id=139 op=LOAD Jul 21 12:38:30.575000 audit[4506]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=5a120d15f90 a2=98 a3=0 items=0 ppid=4494 pid=4506 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.575000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3539373562633132633133623433646336633363366637386466643534 Jul 21 12:38:30.576000 audit: BPF prog-id=139 op=UNLOAD Jul 21 12:38:30.576000 audit[4506]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=4506 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.576000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3539373562633132633133623433646336633363366637386466643534 Jul 21 12:38:30.577000 audit: BPF prog-id=140 op=LOAD Jul 21 12:38:30.577000 audit[4506]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=5a120d16268 a2=98 a3=0 items=0 ppid=4494 pid=4506 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.577000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3539373562633132633133623433646336633363366637386466643534 Jul 21 12:38:30.577000 audit: BPF prog-id=141 op=LOAD Jul 21 12:38:30.577000 audit[4506]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=5a120d15fa8 a2=98 a3=0 items=0 ppid=4494 pid=4506 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.577000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3539373562633132633133623433646336633363366637386466643534 Jul 21 12:38:30.577000 audit: BPF prog-id=141 op=UNLOAD Jul 21 12:38:30.577000 audit[4506]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=4506 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.577000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3539373562633132633133623433646336633363366637386466643534 Jul 21 12:38:30.577000 audit: BPF prog-id=140 op=UNLOAD Jul 21 12:38:30.577000 audit[4506]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=4506 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.577000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3539373562633132633133623433646336633363366637386466643534 Jul 21 12:38:30.577000 audit: BPF prog-id=142 op=LOAD Jul 21 12:38:30.577000 audit[4506]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=5a120d164b8 a2=98 a3=0 items=0 ppid=4494 pid=4506 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.577000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3539373562633132633133623433646336633363366637386466643534 Jul 21 12:38:30.589290 containerd[2389]: time="2026-07-21T12:38:30.588631841Z" level=info msg="RunPodSandbox for name:\"calico-typha-7d9f989c4-jmmmv\" uid:\"009f41cd-d1d0-44bd-a3c2-44b86858bbdc\" namespace:\"calico-system\" returns sandbox id \"f026658de75ef4072f2e0aad947243fcf86831251ae2fb39bee91bc4e17f5975\"" Jul 21 12:38:30.600599 containerd[2389]: time="2026-07-21T12:38:30.600463698Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/typha:v3.32.1\"" Jul 21 12:38:30.643414 containerd[2389]: time="2026-07-21T12:38:30.643341114Z" level=info msg="RunPodSandbox for name:\"calico-node-gm5s5\" uid:\"966fd328-b8e6-4fdf-bc0e-5eeda3a0163a\" namespace:\"calico-system\" returns sandbox id \"5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09\"" Jul 21 12:38:30.743000 audit[4568]: NETFILTER_CFG table=filter:104 family=2 entries=22 op=nft_register_rule pid=4568 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:30.743000 audit[4568]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=8224 a0=3 a1=fffff3a4d090 a2=0 a3=1 items=0 ppid=4148 pid=4568 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.743000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:30.767000 audit[4568]: NETFILTER_CFG table=nat:105 family=2 entries=12 op=nft_register_rule pid=4568 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:30.767000 audit[4568]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=2700 a0=3 a1=fffff3a4d090 a2=0 a3=1 items=0 ppid=4148 pid=4568 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:30.767000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:31.350230 kubelet[4002]: E0721 12:38:31.348638 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:33.351175 kubelet[4002]: E0721 12:38:33.351069 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:33.943047 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount1763308519.mount: Deactivated successfully. Jul 21 12:38:35.289567 containerd[2389]: time="2026-07-21T12:38:35.289494921Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/typha:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:35.292889 containerd[2389]: time="2026-07-21T12:38:35.292787661Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/typha:v3.32.1: active requests=0, bytes read=35100198" Jul 21 12:38:35.294108 containerd[2389]: time="2026-07-21T12:38:35.294047145Z" level=info msg="ImageCreate event name:\"sha256:a499de17d4778d2f4a3bcb6d01340150975d4dda0471399fb1d3448fd09d70e7\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:35.301381 containerd[2389]: time="2026-07-21T12:38:35.301291053Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/typha@sha256:5dbcb01e1890ac3028b90397dadcbed9818f68b278354637e5b50a0b76db65e4\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:35.303705 containerd[2389]: time="2026-07-21T12:38:35.303617037Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/typha:v3.32.1\" with image id \"sha256:a499de17d4778d2f4a3bcb6d01340150975d4dda0471399fb1d3448fd09d70e7\", repo tag \"ghcr.io/flatcar/calico/typha:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/typha@sha256:5dbcb01e1890ac3028b90397dadcbed9818f68b278354637e5b50a0b76db65e4\", size \"37685122\" in 4.703068991s" Jul 21 12:38:35.303705 containerd[2389]: time="2026-07-21T12:38:35.303688545Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/typha:v3.32.1\" returns image reference \"sha256:a499de17d4778d2f4a3bcb6d01340150975d4dda0471399fb1d3448fd09d70e7\"" Jul 21 12:38:35.307527 containerd[2389]: time="2026-07-21T12:38:35.307461753Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/pod2daemon-flexvol:v3.32.1\"" Jul 21 12:38:35.351131 kubelet[4002]: E0721 12:38:35.349828 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:35.365185 containerd[2389]: time="2026-07-21T12:38:35.365115033Z" level=info msg="CreateContainer within sandbox \"f026658de75ef4072f2e0aad947243fcf86831251ae2fb39bee91bc4e17f5975\" for container name:\"calico-typha\"" Jul 21 12:38:35.419061 containerd[2389]: time="2026-07-21T12:38:35.418966389Z" level=info msg="CreateContainer within sandbox \"f026658de75ef4072f2e0aad947243fcf86831251ae2fb39bee91bc4e17f5975\" for name:\"calico-typha\" returns container id \"e2c8fe583ea802422e833257da529de280d6518d39726a5fa9b06513244f8f07\"" Jul 21 12:38:35.421094 containerd[2389]: time="2026-07-21T12:38:35.421023597Z" level=info msg="StartContainer for \"e2c8fe583ea802422e833257da529de280d6518d39726a5fa9b06513244f8f07\"" Jul 21 12:38:35.430014 containerd[2389]: time="2026-07-21T12:38:35.429935758Z" level=info msg="connecting to shim e2c8fe583ea802422e833257da529de280d6518d39726a5fa9b06513244f8f07" address="unix:///run/containerd/s/035bbdefce68f037649265e292fbc560fed031c815ed5cca3fc117be2d4b4058" protocol=ttrpc version=3 Jul 21 12:38:35.502588 systemd[1]: Started cri-containerd-e2c8fe583ea802422e833257da529de280d6518d39726a5fa9b06513244f8f07.scope - libcontainer container e2c8fe583ea802422e833257da529de280d6518d39726a5fa9b06513244f8f07. Jul 21 12:38:35.563000 audit: BPF prog-id=143 op=LOAD Jul 21 12:38:35.565993 kernel: kauditd_printk_skb: 58 callbacks suppressed Jul 21 12:38:35.566122 kernel: audit: type=1334 audit(1784637515.563:492): prog-id=143 op=LOAD Jul 21 12:38:35.568000 audit: BPF prog-id=144 op=LOAD Jul 21 12:38:35.571337 kernel: audit: type=1334 audit(1784637515.568:493): prog-id=144 op=LOAD Jul 21 12:38:35.568000 audit[4579]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=4e11bdafdf90 a2=98 a3=0 items=0 ppid=4409 pid=4579 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:35.568000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6532633866653538336561383032343232653833333235376461353239 Jul 21 12:38:35.584816 kernel: audit: type=1300 audit(1784637515.568:493): arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=4e11bdafdf90 a2=98 a3=0 items=0 ppid=4409 pid=4579 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:35.584984 kernel: audit: type=1327 audit(1784637515.568:493): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6532633866653538336561383032343232653833333235376461353239 Jul 21 12:38:35.570000 audit: BPF prog-id=144 op=UNLOAD Jul 21 12:38:35.587405 kernel: audit: type=1334 audit(1784637515.570:494): prog-id=144 op=UNLOAD Jul 21 12:38:35.570000 audit[4579]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=4409 pid=4579 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:35.587806 kernel: audit: type=1300 audit(1784637515.570:494): arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=4409 pid=4579 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:35.570000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6532633866653538336561383032343232653833333235376461353239 Jul 21 12:38:35.600258 kernel: audit: type=1327 audit(1784637515.570:494): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6532633866653538336561383032343232653833333235376461353239 Jul 21 12:38:35.570000 audit: BPF prog-id=145 op=LOAD Jul 21 12:38:35.601366 kernel: audit: type=1334 audit(1784637515.570:495): prog-id=145 op=LOAD Jul 21 12:38:35.570000 audit[4579]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=4e11bdafe268 a2=98 a3=0 items=0 ppid=4409 pid=4579 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:35.607823 kernel: audit: type=1300 audit(1784637515.570:495): arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=4e11bdafe268 a2=98 a3=0 items=0 ppid=4409 pid=4579 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:35.570000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6532633866653538336561383032343232653833333235376461353239 Jul 21 12:38:35.608319 kernel: audit: type=1327 audit(1784637515.570:495): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6532633866653538336561383032343232653833333235376461353239 Jul 21 12:38:35.570000 audit: BPF prog-id=146 op=LOAD Jul 21 12:38:35.570000 audit[4579]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=4e11bdafdfa8 a2=98 a3=0 items=0 ppid=4409 pid=4579 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:35.570000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6532633866653538336561383032343232653833333235376461353239 Jul 21 12:38:35.570000 audit: BPF prog-id=146 op=UNLOAD Jul 21 12:38:35.570000 audit[4579]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=4409 pid=4579 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:35.570000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6532633866653538336561383032343232653833333235376461353239 Jul 21 12:38:35.570000 audit: BPF prog-id=145 op=UNLOAD Jul 21 12:38:35.570000 audit[4579]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=4409 pid=4579 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:35.570000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6532633866653538336561383032343232653833333235376461353239 Jul 21 12:38:35.570000 audit: BPF prog-id=147 op=LOAD Jul 21 12:38:35.570000 audit[4579]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=4e11bdafe4b8 a2=98 a3=0 items=0 ppid=4409 pid=4579 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:35.570000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6532633866653538336561383032343232653833333235376461353239 Jul 21 12:38:35.697584 containerd[2389]: time="2026-07-21T12:38:35.697416299Z" level=info msg="StartContainer for \"e2c8fe583ea802422e833257da529de280d6518d39726a5fa9b06513244f8f07\" returns successfully" Jul 21 12:38:36.623306 kubelet[4002]: E0721 12:38:36.622958 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.623306 kubelet[4002]: W0721 12:38:36.622993 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.623306 kubelet[4002]: E0721 12:38:36.623023 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.625480 kubelet[4002]: E0721 12:38:36.625445 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.626124 kubelet[4002]: W0721 12:38:36.625585 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.626124 kubelet[4002]: E0721 12:38:36.625665 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.627635 kubelet[4002]: E0721 12:38:36.626507 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.627635 kubelet[4002]: W0721 12:38:36.626534 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.627635 kubelet[4002]: E0721 12:38:36.626563 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.629519 kubelet[4002]: E0721 12:38:36.628083 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.629519 kubelet[4002]: W0721 12:38:36.629290 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.629519 kubelet[4002]: E0721 12:38:36.629335 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.631253 kubelet[4002]: E0721 12:38:36.631094 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.631253 kubelet[4002]: W0721 12:38:36.631130 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.631253 kubelet[4002]: E0721 12:38:36.631176 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.632032 kubelet[4002]: E0721 12:38:36.632002 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.633061 kubelet[4002]: W0721 12:38:36.632147 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.633061 kubelet[4002]: E0721 12:38:36.632214 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.634191 kubelet[4002]: E0721 12:38:36.634122 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.634860 kubelet[4002]: W0721 12:38:36.634587 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.634860 kubelet[4002]: E0721 12:38:36.634631 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.637476 kubelet[4002]: E0721 12:38:36.637276 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.637476 kubelet[4002]: W0721 12:38:36.637309 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.637476 kubelet[4002]: E0721 12:38:36.637341 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.639311 kubelet[4002]: E0721 12:38:36.638921 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.639311 kubelet[4002]: W0721 12:38:36.638958 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.639311 kubelet[4002]: E0721 12:38:36.638990 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.640499 kubelet[4002]: E0721 12:38:36.639786 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.640499 kubelet[4002]: W0721 12:38:36.639811 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.640499 kubelet[4002]: E0721 12:38:36.639843 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.641579 kubelet[4002]: E0721 12:38:36.641544 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.642109 kubelet[4002]: W0721 12:38:36.641834 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.642109 kubelet[4002]: E0721 12:38:36.641883 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.643333 kubelet[4002]: E0721 12:38:36.643298 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.643865 kubelet[4002]: W0721 12:38:36.643494 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.643865 kubelet[4002]: E0721 12:38:36.643534 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.646051 kubelet[4002]: E0721 12:38:36.646013 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.646691 kubelet[4002]: W0721 12:38:36.646502 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.646691 kubelet[4002]: E0721 12:38:36.646548 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.648463 kubelet[4002]: E0721 12:38:36.647818 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.648463 kubelet[4002]: W0721 12:38:36.648285 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.648463 kubelet[4002]: E0721 12:38:36.648326 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.649155 kubelet[4002]: E0721 12:38:36.649094 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.649694 kubelet[4002]: W0721 12:38:36.649552 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.649694 kubelet[4002]: E0721 12:38:36.649600 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.719135 kubelet[4002]: E0721 12:38:36.718931 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.719135 kubelet[4002]: W0721 12:38:36.718965 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.719135 kubelet[4002]: E0721 12:38:36.718995 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.719992 kubelet[4002]: E0721 12:38:36.719961 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.719992 kubelet[4002]: W0721 12:38:36.720035 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.719992 kubelet[4002]: E0721 12:38:36.720071 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.720708 kubelet[4002]: E0721 12:38:36.720644 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.720708 kubelet[4002]: W0721 12:38:36.720669 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.720708 kubelet[4002]: E0721 12:38:36.720693 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.721357 kubelet[4002]: E0721 12:38:36.721251 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.721357 kubelet[4002]: W0721 12:38:36.721284 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.721357 kubelet[4002]: E0721 12:38:36.721315 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.721651 kubelet[4002]: E0721 12:38:36.721626 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.721804 kubelet[4002]: W0721 12:38:36.721651 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.721804 kubelet[4002]: E0721 12:38:36.721673 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.722273 kubelet[4002]: E0721 12:38:36.722240 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.722395 kubelet[4002]: W0721 12:38:36.722272 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.722395 kubelet[4002]: E0721 12:38:36.722297 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.722959 kubelet[4002]: E0721 12:38:36.722918 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.722959 kubelet[4002]: W0721 12:38:36.722949 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.723302 kubelet[4002]: E0721 12:38:36.722975 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.724291 kubelet[4002]: E0721 12:38:36.724179 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.724291 kubelet[4002]: W0721 12:38:36.724287 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.725288 kubelet[4002]: E0721 12:38:36.724319 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.725288 kubelet[4002]: E0721 12:38:36.724692 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.725288 kubelet[4002]: W0721 12:38:36.724712 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.725288 kubelet[4002]: E0721 12:38:36.724734 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.725288 kubelet[4002]: E0721 12:38:36.725004 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.725288 kubelet[4002]: W0721 12:38:36.725024 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.725288 kubelet[4002]: E0721 12:38:36.725048 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.726458 kubelet[4002]: E0721 12:38:36.726424 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.726580 kubelet[4002]: W0721 12:38:36.726455 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.726580 kubelet[4002]: E0721 12:38:36.726483 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.727132 kubelet[4002]: E0721 12:38:36.727104 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.727230 kubelet[4002]: W0721 12:38:36.727133 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.727230 kubelet[4002]: E0721 12:38:36.727158 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.727742 kubelet[4002]: E0721 12:38:36.727480 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.727742 kubelet[4002]: W0721 12:38:36.727498 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.727742 kubelet[4002]: E0721 12:38:36.727517 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.727887 kubelet[4002]: E0721 12:38:36.727786 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.727887 kubelet[4002]: W0721 12:38:36.727803 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.727887 kubelet[4002]: E0721 12:38:36.727823 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.728084 kubelet[4002]: E0721 12:38:36.728054 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.728165 kubelet[4002]: W0721 12:38:36.728082 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.728165 kubelet[4002]: E0721 12:38:36.728104 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.728563 kubelet[4002]: E0721 12:38:36.728536 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.728643 kubelet[4002]: W0721 12:38:36.728563 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.728643 kubelet[4002]: E0721 12:38:36.728586 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.730423 kubelet[4002]: E0721 12:38:36.730397 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.730690 kubelet[4002]: W0721 12:38:36.730537 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.730690 kubelet[4002]: E0721 12:38:36.730570 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:36.731979 kubelet[4002]: E0721 12:38:36.731760 4002 driver-call.go:262] Failed to unmarshal output for command: init, output: "", error: unexpected end of JSON input Jul 21 12:38:36.731979 kubelet[4002]: W0721 12:38:36.731790 4002 driver-call.go:149] FlexVolume: driver call failed: executable: /opt/libexec/kubernetes/kubelet-plugins/volume/exec/nodeagent~uds/uds, args: [init], error: executable file not found in $PATH, output: "" Jul 21 12:38:36.731979 kubelet[4002]: E0721 12:38:36.731818 4002 plugins.go:697] "Error dynamically probing plugins" err="error creating Flexvolume plugin from directory nodeagent~uds, skipping. Error: unexpected end of JSON input" Jul 21 12:38:37.240238 containerd[2389]: time="2026-07-21T12:38:37.239281786Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/pod2daemon-flexvol:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:37.243222 containerd[2389]: time="2026-07-21T12:38:37.243113123Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/pod2daemon-flexvol:v3.32.1: active requests=0, bytes read=0" Jul 21 12:38:37.245246 containerd[2389]: time="2026-07-21T12:38:37.244970951Z" level=info msg="ImageCreate event name:\"sha256:4f782c04a0ec4630601e4bfaff5be31a45bdef6236448ad7a3dfd7be2d722fd8\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:37.250903 containerd[2389]: time="2026-07-21T12:38:37.250803875Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/pod2daemon-flexvol@sha256:12fa272e02bc4978f783067367c33d6bcff9f2bf6ed5961e0e67244db96f96a9\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:37.254237 containerd[2389]: time="2026-07-21T12:38:37.254037227Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/pod2daemon-flexvol:v3.32.1\" with image id \"sha256:4f782c04a0ec4630601e4bfaff5be31a45bdef6236448ad7a3dfd7be2d722fd8\", repo tag \"ghcr.io/flatcar/calico/pod2daemon-flexvol:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/pod2daemon-flexvol@sha256:12fa272e02bc4978f783067367c33d6bcff9f2bf6ed5961e0e67244db96f96a9\", size \"6979768\" in 1.946506558s" Jul 21 12:38:37.254237 containerd[2389]: time="2026-07-21T12:38:37.254096819Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/pod2daemon-flexvol:v3.32.1\" returns image reference \"sha256:4f782c04a0ec4630601e4bfaff5be31a45bdef6236448ad7a3dfd7be2d722fd8\"" Jul 21 12:38:37.263268 containerd[2389]: time="2026-07-21T12:38:37.262742879Z" level=info msg="CreateContainer within sandbox \"5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09\" for container name:\"flexvol-driver\"" Jul 21 12:38:37.315632 containerd[2389]: time="2026-07-21T12:38:37.315537491Z" level=info msg="CreateContainer within sandbox \"5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09\" for name:\"flexvol-driver\" returns container id \"ff83bf0eabf2b15faf05d5557a39a48b658f4816021fbb2c8c8269131b3dc937\"" Jul 21 12:38:37.320274 containerd[2389]: time="2026-07-21T12:38:37.318229223Z" level=info msg="StartContainer for \"ff83bf0eabf2b15faf05d5557a39a48b658f4816021fbb2c8c8269131b3dc937\"" Jul 21 12:38:37.324167 containerd[2389]: time="2026-07-21T12:38:37.323717219Z" level=info msg="connecting to shim ff83bf0eabf2b15faf05d5557a39a48b658f4816021fbb2c8c8269131b3dc937" address="unix:///run/containerd/s/40a333afa61a779671eddc82c3f5b50b9b0e8c216cdeaee0ce92b28c8929272f" protocol=ttrpc version=3 Jul 21 12:38:37.350684 kubelet[4002]: E0721 12:38:37.349494 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:37.391910 systemd[1]: Started cri-containerd-ff83bf0eabf2b15faf05d5557a39a48b658f4816021fbb2c8c8269131b3dc937.scope - libcontainer container ff83bf0eabf2b15faf05d5557a39a48b658f4816021fbb2c8c8269131b3dc937. Jul 21 12:38:37.458000 audit: BPF prog-id=148 op=LOAD Jul 21 12:38:37.458000 audit[4652]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=41417be5c268 a2=98 a3=0 items=0 ppid=4494 pid=4652 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:37.458000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6666383362663065616266326231356661663035643535353761333961 Jul 21 12:38:37.458000 audit: BPF prog-id=149 op=LOAD Jul 21 12:38:37.458000 audit[4652]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=41417be5bfa8 a2=98 a3=0 items=0 ppid=4494 pid=4652 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:37.458000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6666383362663065616266326231356661663035643535353761333961 Jul 21 12:38:37.458000 audit: BPF prog-id=149 op=UNLOAD Jul 21 12:38:37.458000 audit[4652]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=4652 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:37.458000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6666383362663065616266326231356661663035643535353761333961 Jul 21 12:38:37.458000 audit: BPF prog-id=148 op=UNLOAD Jul 21 12:38:37.458000 audit[4652]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=4652 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:37.458000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6666383362663065616266326231356661663035643535353761333961 Jul 21 12:38:37.458000 audit: BPF prog-id=150 op=LOAD Jul 21 12:38:37.458000 audit[4652]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=41417be5c4b8 a2=98 a3=0 items=0 ppid=4494 pid=4652 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:37.458000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6666383362663065616266326231356661663035643535353761333961 Jul 21 12:38:37.524251 containerd[2389]: time="2026-07-21T12:38:37.523978716Z" level=info msg="StartContainer for \"ff83bf0eabf2b15faf05d5557a39a48b658f4816021fbb2c8c8269131b3dc937\" returns successfully" Jul 21 12:38:37.568589 kubelet[4002]: I0721 12:38:37.568538 4002 prober_manager.go:312] "Failed to trigger a manual run" probe="Readiness" Jul 21 12:38:37.598902 systemd[1]: cri-containerd-ff83bf0eabf2b15faf05d5557a39a48b658f4816021fbb2c8c8269131b3dc937.scope: Deactivated successfully. Jul 21 12:38:37.607260 kubelet[4002]: I0721 12:38:37.607114 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="calico-system/calico-typha-7d9f989c4-jmmmv" podStartSLOduration=3.900407361 podStartE2EDuration="8.607094352s" podCreationTimestamp="2026-07-21 12:38:29 +0000 UTC" firstStartedPulling="2026-07-21 12:38:30.599790906 +0000 UTC m=+27.552808242" lastFinishedPulling="2026-07-21 12:38:35.306477909 +0000 UTC m=+32.259495233" observedRunningTime="2026-07-21 12:38:36.611559575 +0000 UTC m=+33.564576947" watchObservedRunningTime="2026-07-21 12:38:37.607094352 +0000 UTC m=+34.560111700" Jul 21 12:38:37.615000 audit: BPF prog-id=150 op=UNLOAD Jul 21 12:38:37.621977 containerd[2389]: time="2026-07-21T12:38:37.621903168Z" level=info msg="received container exit event container_id:\"ff83bf0eabf2b15faf05d5557a39a48b658f4816021fbb2c8c8269131b3dc937\" id:\"ff83bf0eabf2b15faf05d5557a39a48b658f4816021fbb2c8c8269131b3dc937\" pid:4665 exited_at:{seconds:1784637517 nanos:620960328}" Jul 21 12:38:37.700193 systemd[1]: run-containerd-io.containerd.runtime.v2.task-k8s.io-ff83bf0eabf2b15faf05d5557a39a48b658f4816021fbb2c8c8269131b3dc937-rootfs.mount: Deactivated successfully. Jul 21 12:38:38.581380 containerd[2389]: time="2026-07-21T12:38:38.581295205Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/node:v3.32.1\"" Jul 21 12:38:39.349128 kubelet[4002]: E0721 12:38:39.349060 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:41.350537 kubelet[4002]: E0721 12:38:41.350463 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:41.903168 systemd[1]: Started sshd@7-4101-172.31.16.165:22-144.225.8.54:55362.service - OpenSSH per-connection server daemon (144.225.8.54:55362). Jul 21 12:38:41.902000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@7-4101-172.31.16.165:22-144.225.8.54:55362 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:41.905182 kernel: kauditd_printk_skb: 28 callbacks suppressed Jul 21 12:38:41.905281 kernel: audit: type=1130 audit(1784637521.902:506): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@7-4101-172.31.16.165:22-144.225.8.54:55362 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:42.239717 sshd[4707]: Connection closed by authenticating user root 144.225.8.54 port 55362 [preauth] Jul 21 12:38:42.240000 audit[4707]: AUDIT1109 pid=4707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:42.248013 systemd[1]: sshd@7-4101-172.31.16.165:22-144.225.8.54:55362.service: Deactivated successfully. Jul 21 12:38:42.247000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@7-4101-172.31.16.165:22-144.225.8.54:55362 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:42.253966 kernel: audit: type=1109 audit(1784637522.240:507): pid=4707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:42.254023 kernel: audit: type=1131 audit(1784637522.247:508): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@7-4101-172.31.16.165:22-144.225.8.54:55362 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:42.318000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@8-4102-172.31.16.165:22-144.225.8.54:55372 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:42.319061 systemd[1]: Started sshd@8-4102-172.31.16.165:22-144.225.8.54:55372.service - OpenSSH per-connection server daemon (144.225.8.54:55372). Jul 21 12:38:42.328266 kernel: audit: type=1130 audit(1784637522.318:509): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@8-4102-172.31.16.165:22-144.225.8.54:55372 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:42.555475 kubelet[4002]: I0721 12:38:42.555337 4002 prober_manager.go:312] "Failed to trigger a manual run" probe="Readiness" Jul 21 12:38:42.650768 sshd[4713]: Connection closed by authenticating user root 144.225.8.54 port 55372 [preauth] Jul 21 12:38:42.652000 audit[4713]: AUDIT1109 pid=4713 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:42.662459 systemd[1]: sshd@8-4102-172.31.16.165:22-144.225.8.54:55372.service: Deactivated successfully. Jul 21 12:38:42.660000 audit[4717]: NETFILTER_CFG table=filter:106 family=2 entries=21 op=nft_register_rule pid=4717 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:42.670843 kernel: audit: type=1109 audit(1784637522.652:510): pid=4713 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:42.670964 kernel: audit: type=1325 audit(1784637522.660:511): table=filter:106 family=2 entries=21 op=nft_register_rule pid=4717 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:42.660000 audit[4717]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=7480 a0=3 a1=ffffe6b6d210 a2=0 a3=1 items=0 ppid=4148 pid=4717 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:42.679565 kernel: audit: type=1300 audit(1784637522.660:511): arch=c00000b7 syscall=211 success=yes exit=7480 a0=3 a1=ffffe6b6d210 a2=0 a3=1 items=0 ppid=4148 pid=4717 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:42.660000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:42.684293 kernel: audit: type=1327 audit(1784637522.660:511): proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:42.662000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@8-4102-172.31.16.165:22-144.225.8.54:55372 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:42.690776 kernel: audit: type=1131 audit(1784637522.662:512): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@8-4102-172.31.16.165:22-144.225.8.54:55372 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:42.670000 audit[4717]: NETFILTER_CFG table=nat:107 family=2 entries=19 op=nft_register_chain pid=4717 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:42.693418 kernel: audit: type=1325 audit(1784637522.670:513): table=nat:107 family=2 entries=19 op=nft_register_chain pid=4717 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:38:42.670000 audit[4717]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=6276 a0=3 a1=ffffe6b6d210 a2=0 a3=1 items=0 ppid=4148 pid=4717 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:42.670000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:38:42.727788 systemd[1]: Started sshd@9-4103-172.31.16.165:22-144.225.8.54:55380.service - OpenSSH per-connection server daemon (144.225.8.54:55380). Jul 21 12:38:42.727000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@9-4103-172.31.16.165:22-144.225.8.54:55380 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:43.043075 sshd[4721]: Connection closed by authenticating user root 144.225.8.54 port 55380 [preauth] Jul 21 12:38:43.042000 audit[4721]: AUDIT1109 pid=4721 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:43.047939 systemd[1]: sshd@9-4103-172.31.16.165:22-144.225.8.54:55380.service: Deactivated successfully. Jul 21 12:38:43.047000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@9-4103-172.31.16.165:22-144.225.8.54:55380 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:43.120949 systemd[1]: Started sshd@10-4104-172.31.16.165:22-144.225.8.54:55392.service - OpenSSH per-connection server daemon (144.225.8.54:55392). Jul 21 12:38:43.119000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@10-4104-172.31.16.165:22-144.225.8.54:55392 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:43.350555 kubelet[4002]: E0721 12:38:43.348774 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:43.440438 sshd[4727]: Connection closed by authenticating user root 144.225.8.54 port 55392 [preauth] Jul 21 12:38:43.441000 audit[4727]: AUDIT1109 pid=4727 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:43.450000 systemd[1]: sshd@10-4104-172.31.16.165:22-144.225.8.54:55392.service: Deactivated successfully. Jul 21 12:38:43.450000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@10-4104-172.31.16.165:22-144.225.8.54:55392 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:43.517000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@11-4105-172.31.16.165:22-144.225.8.54:55394 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:43.518577 systemd[1]: Started sshd@11-4105-172.31.16.165:22-144.225.8.54:55394.service - OpenSSH per-connection server daemon (144.225.8.54:55394). Jul 21 12:38:43.835893 sshd[4733]: Connection closed by authenticating user root 144.225.8.54 port 55394 [preauth] Jul 21 12:38:43.836000 audit[4733]: AUDIT1109 pid=4733 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:43.842148 systemd[1]: sshd@11-4105-172.31.16.165:22-144.225.8.54:55394.service: Deactivated successfully. Jul 21 12:38:43.843000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@11-4105-172.31.16.165:22-144.225.8.54:55394 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:43.914685 systemd[1]: Started sshd@12-4106-172.31.16.165:22-144.225.8.54:55408.service - OpenSSH per-connection server daemon (144.225.8.54:55408). Jul 21 12:38:43.913000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@12-4106-172.31.16.165:22-144.225.8.54:55408 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:44.242880 sshd[4739]: Connection closed by authenticating user root 144.225.8.54 port 55408 [preauth] Jul 21 12:38:44.242000 audit[4739]: AUDIT1109 pid=4739 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:44.248370 systemd[1]: sshd@12-4106-172.31.16.165:22-144.225.8.54:55408.service: Deactivated successfully. Jul 21 12:38:44.248000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@12-4106-172.31.16.165:22-144.225.8.54:55408 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:44.320000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@13-4107-172.31.16.165:22-144.225.8.54:55420 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:44.321765 systemd[1]: Started sshd@13-4107-172.31.16.165:22-144.225.8.54:55420.service - OpenSSH per-connection server daemon (144.225.8.54:55420). Jul 21 12:38:44.648161 sshd[4745]: Connection closed by authenticating user root 144.225.8.54 port 55420 [preauth] Jul 21 12:38:44.648000 audit[4745]: AUDIT1109 pid=4745 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:44.658743 systemd[1]: sshd@13-4107-172.31.16.165:22-144.225.8.54:55420.service: Deactivated successfully. Jul 21 12:38:44.659000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@13-4107-172.31.16.165:22-144.225.8.54:55420 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:44.725000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@14-4108-172.31.16.165:22-144.225.8.54:55426 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:44.726281 systemd[1]: Started sshd@14-4108-172.31.16.165:22-144.225.8.54:55426.service - OpenSSH per-connection server daemon (144.225.8.54:55426). Jul 21 12:38:45.051394 sshd[4751]: Connection closed by authenticating user root 144.225.8.54 port 55426 [preauth] Jul 21 12:38:45.051000 audit[4751]: AUDIT1109 pid=4751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:45.056000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@14-4108-172.31.16.165:22-144.225.8.54:55426 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:45.057498 systemd[1]: sshd@14-4108-172.31.16.165:22-144.225.8.54:55426.service: Deactivated successfully. Jul 21 12:38:45.128601 systemd[1]: Started sshd@15-4109-172.31.16.165:22-144.225.8.54:55430.service - OpenSSH per-connection server daemon (144.225.8.54:55430). Jul 21 12:38:45.127000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@15-4109-172.31.16.165:22-144.225.8.54:55430 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:45.262160 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount3589442948.mount: Deactivated successfully. Jul 21 12:38:45.327271 containerd[2389]: time="2026-07-21T12:38:45.326750815Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/node:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:45.328878 containerd[2389]: time="2026-07-21T12:38:45.328527451Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/node:v3.32.1: active requests=1, bytes read=91226112" Jul 21 12:38:45.330548 containerd[2389]: time="2026-07-21T12:38:45.330489079Z" level=info msg="ImageCreate event name:\"sha256:f5dc73ff57bfbebfafbba78537dcc17d83901b50a48056090abc92a9547f055c\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:45.334229 containerd[2389]: time="2026-07-21T12:38:45.334161499Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/node@sha256:c28e53bacf533715259b894781cd255f6c07e9737584e5719e63015a8cd0e307\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:45.336033 containerd[2389]: time="2026-07-21T12:38:45.335933527Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/node:v3.32.1\" with image id \"sha256:f5dc73ff57bfbebfafbba78537dcc17d83901b50a48056090abc92a9547f055c\", repo tag \"ghcr.io/flatcar/calico/node:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/node@sha256:c28e53bacf533715259b894781cd255f6c07e9737584e5719e63015a8cd0e307\", size \"114998942\" in 6.75456655s" Jul 21 12:38:45.336174 containerd[2389]: time="2026-07-21T12:38:45.336030175Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/node:v3.32.1\" returns image reference \"sha256:f5dc73ff57bfbebfafbba78537dcc17d83901b50a48056090abc92a9547f055c\"" Jul 21 12:38:45.343998 containerd[2389]: time="2026-07-21T12:38:45.343930351Z" level=info msg="CreateContainer within sandbox \"5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09\" for container name:\"ebpf-bootstrap\"" Jul 21 12:38:45.350096 kubelet[4002]: E0721 12:38:45.349542 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:45.413701 containerd[2389]: time="2026-07-21T12:38:45.412981231Z" level=info msg="CreateContainer within sandbox \"5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09\" for name:\"ebpf-bootstrap\" returns container id \"bb0df465b41c6be69fd51b7f0a1a8684a4c1d25de3617d68360e0064f6502f40\"" Jul 21 12:38:45.419235 containerd[2389]: time="2026-07-21T12:38:45.418301071Z" level=info msg="StartContainer for \"bb0df465b41c6be69fd51b7f0a1a8684a4c1d25de3617d68360e0064f6502f40\"" Jul 21 12:38:45.422064 containerd[2389]: time="2026-07-21T12:38:45.421959331Z" level=info msg="connecting to shim bb0df465b41c6be69fd51b7f0a1a8684a4c1d25de3617d68360e0064f6502f40" address="unix:///run/containerd/s/40a333afa61a779671eddc82c3f5b50b9b0e8c216cdeaee0ce92b28c8929272f" protocol=ttrpc version=3 Jul 21 12:38:45.463768 sshd[4757]: Connection closed by authenticating user root 144.225.8.54 port 55430 [preauth] Jul 21 12:38:45.463000 audit[4757]: AUDIT1109 pid=4757 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:45.471300 systemd[1]: sshd@15-4109-172.31.16.165:22-144.225.8.54:55430.service: Deactivated successfully. Jul 21 12:38:45.471000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@15-4109-172.31.16.165:22-144.225.8.54:55430 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:45.496603 systemd[1]: Started cri-containerd-bb0df465b41c6be69fd51b7f0a1a8684a4c1d25de3617d68360e0064f6502f40.scope - libcontainer container bb0df465b41c6be69fd51b7f0a1a8684a4c1d25de3617d68360e0064f6502f40. Jul 21 12:38:45.539000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@16-4110-172.31.16.165:22-144.225.8.54:55438 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:45.540544 systemd[1]: Started sshd@16-4110-172.31.16.165:22-144.225.8.54:55438.service - OpenSSH per-connection server daemon (144.225.8.54:55438). Jul 21 12:38:45.571000 audit: BPF prog-id=151 op=LOAD Jul 21 12:38:45.571000 audit[4760]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=5940a32f0268 a2=98 a3=0 items=0 ppid=4494 pid=4760 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:45.571000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6262306466343635623431633662653639666435316237663061316138 Jul 21 12:38:45.572000 audit: BPF prog-id=152 op=LOAD Jul 21 12:38:45.572000 audit[4760]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=5940a32effa8 a2=98 a3=0 items=0 ppid=4494 pid=4760 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:45.572000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6262306466343635623431633662653639666435316237663061316138 Jul 21 12:38:45.573000 audit: BPF prog-id=152 op=UNLOAD Jul 21 12:38:45.573000 audit[4760]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=4760 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:45.573000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6262306466343635623431633662653639666435316237663061316138 Jul 21 12:38:45.574000 audit: BPF prog-id=151 op=UNLOAD Jul 21 12:38:45.574000 audit[4760]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=13 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=4760 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:45.574000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6262306466343635623431633662653639666435316237663061316138 Jul 21 12:38:45.574000 audit: BPF prog-id=153 op=LOAD Jul 21 12:38:45.574000 audit[4760]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=5940a32f04b8 a2=98 a3=0 items=0 ppid=4494 pid=4760 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:45.574000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6262306466343635623431633662653639666435316237663061316138 Jul 21 12:38:45.636376 containerd[2389]: time="2026-07-21T12:38:45.636325724Z" level=info msg="StartContainer for \"bb0df465b41c6be69fd51b7f0a1a8684a4c1d25de3617d68360e0064f6502f40\" returns successfully" Jul 21 12:38:45.845849 systemd[1]: cri-containerd-bb0df465b41c6be69fd51b7f0a1a8684a4c1d25de3617d68360e0064f6502f40.scope: Deactivated successfully. Jul 21 12:38:45.849867 containerd[2389]: time="2026-07-21T12:38:45.849785073Z" level=info msg="received container exit event container_id:\"bb0df465b41c6be69fd51b7f0a1a8684a4c1d25de3617d68360e0064f6502f40\" id:\"bb0df465b41c6be69fd51b7f0a1a8684a4c1d25de3617d68360e0064f6502f40\" pid:4776 exited_at:{seconds:1784637525 nanos:849192597}" Jul 21 12:38:45.850000 audit: BPF prog-id=153 op=UNLOAD Jul 21 12:38:45.868821 sshd[4782]: Connection closed by authenticating user root 144.225.8.54 port 55438 [preauth] Jul 21 12:38:45.868000 audit[4782]: AUDIT1109 pid=4782 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:45.874395 systemd[1]: sshd@16-4110-172.31.16.165:22-144.225.8.54:55438.service: Deactivated successfully. Jul 21 12:38:45.876000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@16-4110-172.31.16.165:22-144.225.8.54:55438 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:45.947000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@17-4-172.31.16.165:22-144.225.8.54:55452 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:45.948633 systemd[1]: Started sshd@17-4-172.31.16.165:22-144.225.8.54:55452.service - OpenSSH per-connection server daemon (144.225.8.54:55452). Jul 21 12:38:46.253591 sshd[4817]: Connection closed by authenticating user root 144.225.8.54 port 55452 [preauth] Jul 21 12:38:46.253000 audit[4817]: AUDIT1109 pid=4817 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:46.257183 systemd[1]: sshd@17-4-172.31.16.165:22-144.225.8.54:55452.service: Deactivated successfully. Jul 21 12:38:46.257000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@17-4-172.31.16.165:22-144.225.8.54:55452 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:46.266133 systemd[1]: run-containerd-io.containerd.runtime.v2.task-k8s.io-bb0df465b41c6be69fd51b7f0a1a8684a4c1d25de3617d68360e0064f6502f40-rootfs.mount: Deactivated successfully. Jul 21 12:38:46.331849 systemd[1]: Started sshd@18-4111-172.31.16.165:22-144.225.8.54:55460.service - OpenSSH per-connection server daemon (144.225.8.54:55460). Jul 21 12:38:46.331000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@18-4111-172.31.16.165:22-144.225.8.54:55460 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:46.650494 sshd[4823]: Connection closed by authenticating user root 144.225.8.54 port 55460 [preauth] Jul 21 12:38:46.651639 containerd[2389]: time="2026-07-21T12:38:46.651552441Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/cni:v3.32.1\"" Jul 21 12:38:46.652000 audit[4823]: AUDIT1109 pid=4823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:46.660968 systemd[1]: sshd@18-4111-172.31.16.165:22-144.225.8.54:55460.service: Deactivated successfully. Jul 21 12:38:46.662000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@18-4111-172.31.16.165:22-144.225.8.54:55460 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:46.728000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@19-5-172.31.16.165:22-144.225.8.54:55468 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:46.729448 systemd[1]: Started sshd@19-5-172.31.16.165:22-144.225.8.54:55468.service - OpenSSH per-connection server daemon (144.225.8.54:55468). Jul 21 12:38:47.030524 sshd[4829]: Connection closed by authenticating user root 144.225.8.54 port 55468 [preauth] Jul 21 12:38:47.029000 audit[4829]: AUDIT1109 pid=4829 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:47.032144 kernel: kauditd_printk_skb: 49 callbacks suppressed Jul 21 12:38:47.032247 kernel: audit: type=1109 audit(1784637527.029:551): pid=4829 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:47.036945 systemd[1]: sshd@19-5-172.31.16.165:22-144.225.8.54:55468.service: Deactivated successfully. Jul 21 12:38:47.036000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@19-5-172.31.16.165:22-144.225.8.54:55468 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.044273 kernel: audit: type=1131 audit(1784637527.036:552): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@19-5-172.31.16.165:22-144.225.8.54:55468 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.103000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@20-4112-172.31.16.165:22-144.225.8.54:55482 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.104392 systemd[1]: Started sshd@20-4112-172.31.16.165:22-144.225.8.54:55482.service - OpenSSH per-connection server daemon (144.225.8.54:55482). Jul 21 12:38:47.111258 kernel: audit: type=1130 audit(1784637527.103:553): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@20-4112-172.31.16.165:22-144.225.8.54:55482 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.348559 kubelet[4002]: E0721 12:38:47.348411 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:47.413178 sshd[4835]: Connection closed by authenticating user root 144.225.8.54 port 55482 [preauth] Jul 21 12:38:47.412000 audit[4835]: AUDIT1109 pid=4835 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:47.420346 systemd[1]: sshd@20-4112-172.31.16.165:22-144.225.8.54:55482.service: Deactivated successfully. Jul 21 12:38:47.419000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@20-4112-172.31.16.165:22-144.225.8.54:55482 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.426302 kernel: audit: type=1109 audit(1784637527.412:554): pid=4835 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:47.426429 kernel: audit: type=1131 audit(1784637527.419:555): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@20-4112-172.31.16.165:22-144.225.8.54:55482 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.488000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@21-6-172.31.16.165:22-144.225.8.54:55494 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.489350 systemd[1]: Started sshd@21-6-172.31.16.165:22-144.225.8.54:55494.service - OpenSSH per-connection server daemon (144.225.8.54:55494). Jul 21 12:38:47.496305 kernel: audit: type=1130 audit(1784637527.488:556): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@21-6-172.31.16.165:22-144.225.8.54:55494 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.795155 sshd[4841]: Connection closed by authenticating user root 144.225.8.54 port 55494 [preauth] Jul 21 12:38:47.795000 audit[4841]: AUDIT1109 pid=4841 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:47.802654 systemd[1]: sshd@21-6-172.31.16.165:22-144.225.8.54:55494.service: Deactivated successfully. Jul 21 12:38:47.803238 kernel: audit: type=1109 audit(1784637527.795:557): pid=4841 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:47.802000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@21-6-172.31.16.165:22-144.225.8.54:55494 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.810381 kernel: audit: type=1131 audit(1784637527.802:558): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@21-6-172.31.16.165:22-144.225.8.54:55494 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.873991 systemd[1]: Started sshd@22-7-172.31.16.165:22-144.225.8.54:34298.service - OpenSSH per-connection server daemon (144.225.8.54:34298). Jul 21 12:38:47.874000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@22-7-172.31.16.165:22-144.225.8.54:34298 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:47.883276 kernel: audit: type=1130 audit(1784637527.874:559): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@22-7-172.31.16.165:22-144.225.8.54:34298 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:48.195215 sshd[4847]: Connection closed by authenticating user root 144.225.8.54 port 34298 [preauth] Jul 21 12:38:48.194000 audit[4847]: AUDIT1109 pid=4847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:48.199365 systemd[1]: sshd@22-7-172.31.16.165:22-144.225.8.54:34298.service: Deactivated successfully. Jul 21 12:38:48.198000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@22-7-172.31.16.165:22-144.225.8.54:34298 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:48.204463 kernel: audit: type=1109 audit(1784637528.194:560): pid=4847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:48.273000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@23-8-172.31.16.165:22-144.225.8.54:34304 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:48.274494 systemd[1]: Started sshd@23-8-172.31.16.165:22-144.225.8.54:34304.service - OpenSSH per-connection server daemon (144.225.8.54:34304). Jul 21 12:38:48.591319 sshd[4853]: Connection closed by authenticating user root 144.225.8.54 port 34304 [preauth] Jul 21 12:38:48.591000 audit[4853]: AUDIT1109 pid=4853 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:48.595885 systemd[1]: sshd@23-8-172.31.16.165:22-144.225.8.54:34304.service: Deactivated successfully. Jul 21 12:38:48.595000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@23-8-172.31.16.165:22-144.225.8.54:34304 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:48.666066 systemd[1]: Started sshd@24-4113-172.31.16.165:22-144.225.8.54:34318.service - OpenSSH per-connection server daemon (144.225.8.54:34318). Jul 21 12:38:48.665000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@24-4113-172.31.16.165:22-144.225.8.54:34318 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:48.974784 sshd[4859]: Connection closed by authenticating user root 144.225.8.54 port 34318 [preauth] Jul 21 12:38:48.974000 audit[4859]: AUDIT1109 pid=4859 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:48.978774 systemd[1]: sshd@24-4113-172.31.16.165:22-144.225.8.54:34318.service: Deactivated successfully. Jul 21 12:38:48.978000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@24-4113-172.31.16.165:22-144.225.8.54:34318 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:49.051000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@25-4114-172.31.16.165:22-144.225.8.54:34328 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:49.052734 systemd[1]: Started sshd@25-4114-172.31.16.165:22-144.225.8.54:34328.service - OpenSSH per-connection server daemon (144.225.8.54:34328). Jul 21 12:38:49.356387 kubelet[4002]: E0721 12:38:49.356309 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:49.396051 sshd[4865]: Connection closed by authenticating user root 144.225.8.54 port 34328 [preauth] Jul 21 12:38:49.395000 audit[4865]: AUDIT1109 pid=4865 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:49.401880 systemd[1]: sshd@25-4114-172.31.16.165:22-144.225.8.54:34328.service: Deactivated successfully. Jul 21 12:38:49.402000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@25-4114-172.31.16.165:22-144.225.8.54:34328 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:49.474366 systemd[1]: Started sshd@26-4115-172.31.16.165:22-144.225.8.54:34338.service - OpenSSH per-connection server daemon (144.225.8.54:34338). Jul 21 12:38:49.473000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@26-4115-172.31.16.165:22-144.225.8.54:34338 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:49.804573 sshd[4875]: Connection closed by authenticating user root 144.225.8.54 port 34338 [preauth] Jul 21 12:38:49.805000 audit[4875]: AUDIT1109 pid=4875 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:49.812403 systemd[1]: sshd@26-4115-172.31.16.165:22-144.225.8.54:34338.service: Deactivated successfully. Jul 21 12:38:49.813000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@26-4115-172.31.16.165:22-144.225.8.54:34338 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:49.879863 systemd[1]: Started sshd@27-4116-172.31.16.165:22-144.225.8.54:34342.service - OpenSSH per-connection server daemon (144.225.8.54:34342). Jul 21 12:38:49.878000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@27-4116-172.31.16.165:22-144.225.8.54:34342 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:50.213186 sshd[4881]: Connection closed by authenticating user root 144.225.8.54 port 34342 [preauth] Jul 21 12:38:50.212000 audit[4881]: AUDIT1109 pid=4881 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:50.218877 systemd[1]: sshd@27-4116-172.31.16.165:22-144.225.8.54:34342.service: Deactivated successfully. Jul 21 12:38:50.218000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@27-4116-172.31.16.165:22-144.225.8.54:34342 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:50.293159 systemd[1]: Started sshd@28-9-172.31.16.165:22-144.225.8.54:34346.service - OpenSSH per-connection server daemon (144.225.8.54:34346). Jul 21 12:38:50.292000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@28-9-172.31.16.165:22-144.225.8.54:34346 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:50.615434 sshd[4887]: Connection closed by authenticating user root 144.225.8.54 port 34346 [preauth] Jul 21 12:38:50.615000 audit[4887]: AUDIT1109 pid=4887 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:50.620297 systemd[1]: sshd@28-9-172.31.16.165:22-144.225.8.54:34346.service: Deactivated successfully. Jul 21 12:38:50.620000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@28-9-172.31.16.165:22-144.225.8.54:34346 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:50.696502 systemd[1]: Started sshd@29-10-172.31.16.165:22-144.225.8.54:34356.service - OpenSSH per-connection server daemon (144.225.8.54:34356). Jul 21 12:38:50.695000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@29-10-172.31.16.165:22-144.225.8.54:34356 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:51.035746 sshd[4893]: Connection closed by authenticating user root 144.225.8.54 port 34356 [preauth] Jul 21 12:38:51.036000 audit[4893]: AUDIT1109 pid=4893 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:51.041246 systemd[1]: sshd@29-10-172.31.16.165:22-144.225.8.54:34356.service: Deactivated successfully. Jul 21 12:38:51.042000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@29-10-172.31.16.165:22-144.225.8.54:34356 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:51.084287 containerd[2389]: time="2026-07-21T12:38:51.084041723Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/cni:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:51.087156 containerd[2389]: time="2026-07-21T12:38:51.087072491Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/cni:v3.32.1: active requests=1, bytes read=54525952" Jul 21 12:38:51.089227 containerd[2389]: time="2026-07-21T12:38:51.088270823Z" level=info msg="ImageCreate event name:\"sha256:f441a5d9bf072a407c2325ebd77325cd0035c10b1f79005179d0933f8f6b2724\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:51.095866 containerd[2389]: time="2026-07-21T12:38:51.095771771Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/cni@sha256:2ff4d5f249910a9861f893c83f77e2228d355650f4c0fc07bdbfa92a198b77f2\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:51.098729 containerd[2389]: time="2026-07-21T12:38:51.098664875Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/cni:v3.32.1\" with image id \"sha256:f441a5d9bf072a407c2325ebd77325cd0035c10b1f79005179d0933f8f6b2724\", repo tag \"ghcr.io/flatcar/calico/cni:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/cni@sha256:2ff4d5f249910a9861f893c83f77e2228d355650f4c0fc07bdbfa92a198b77f2\", size \"63917712\" in 4.447019614s" Jul 21 12:38:51.098729 containerd[2389]: time="2026-07-21T12:38:51.098724995Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/cni:v3.32.1\" returns image reference \"sha256:f441a5d9bf072a407c2325ebd77325cd0035c10b1f79005179d0933f8f6b2724\"" Jul 21 12:38:51.112159 systemd[1]: Started sshd@30-11-172.31.16.165:22-144.225.8.54:34360.service - OpenSSH per-connection server daemon (144.225.8.54:34360). Jul 21 12:38:51.112000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@30-11-172.31.16.165:22-144.225.8.54:34360 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:51.115516 containerd[2389]: time="2026-07-21T12:38:51.115442219Z" level=info msg="CreateContainer within sandbox \"5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09\" for container name:\"install-cni\"" Jul 21 12:38:51.195043 containerd[2389]: time="2026-07-21T12:38:51.194980332Z" level=info msg="CreateContainer within sandbox \"5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09\" for name:\"install-cni\" returns container id \"156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f\"" Jul 21 12:38:51.197065 containerd[2389]: time="2026-07-21T12:38:51.197002968Z" level=info msg="StartContainer for \"156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f\"" Jul 21 12:38:51.201968 containerd[2389]: time="2026-07-21T12:38:51.201711984Z" level=info msg="connecting to shim 156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f" address="unix:///run/containerd/s/40a333afa61a779671eddc82c3f5b50b9b0e8c216cdeaee0ce92b28c8929272f" protocol=ttrpc version=3 Jul 21 12:38:51.256978 systemd[1]: Started cri-containerd-156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f.scope - libcontainer container 156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f. Jul 21 12:38:51.323000 audit: BPF prog-id=154 op=LOAD Jul 21 12:38:51.323000 audit[4906]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=64d0af0aa268 a2=98 a3=0 items=0 ppid=4494 pid=4906 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:51.323000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3135366334393630353964613631646335626165306634623761636462 Jul 21 12:38:51.324000 audit: BPF prog-id=155 op=LOAD Jul 21 12:38:51.324000 audit[4906]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=64d0af0a9fa8 a2=98 a3=0 items=0 ppid=4494 pid=4906 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:51.324000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3135366334393630353964613631646335626165306634623761636462 Jul 21 12:38:51.325000 audit: BPF prog-id=155 op=UNLOAD Jul 21 12:38:51.325000 audit[4906]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=4906 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:51.325000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3135366334393630353964613631646335626165306634623761636462 Jul 21 12:38:51.325000 audit: BPF prog-id=154 op=UNLOAD Jul 21 12:38:51.325000 audit[4906]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=13 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=4906 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:51.325000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3135366334393630353964613631646335626165306634623761636462 Jul 21 12:38:51.326000 audit: BPF prog-id=156 op=LOAD Jul 21 12:38:51.326000 audit[4906]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=64d0af0aa4b8 a2=98 a3=0 items=0 ppid=4494 pid=4906 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:51.326000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3135366334393630353964613631646335626165306634623761636462 Jul 21 12:38:51.349640 kubelet[4002]: E0721 12:38:51.349551 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="network is not ready: container runtime network not ready: NetworkReady=false reason:NetworkPluginNotReady message:Network plugin returns error: cni plugin not initialized" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:51.379233 containerd[2389]: time="2026-07-21T12:38:51.378618061Z" level=info msg="StartContainer for \"156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f\" returns successfully" Jul 21 12:38:51.451866 sshd[4903]: Connection closed by authenticating user root 144.225.8.54 port 34360 [preauth] Jul 21 12:38:51.457000 audit[4903]: AUDIT1109 pid=4903 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:51.471774 systemd[1]: sshd@30-11-172.31.16.165:22-144.225.8.54:34360.service: Deactivated successfully. Jul 21 12:38:51.474000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@30-11-172.31.16.165:22-144.225.8.54:34360 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:51.536132 systemd[1]: Started sshd@31-4117-172.31.16.165:22-144.225.8.54:34368.service - OpenSSH per-connection server daemon (144.225.8.54:34368). Jul 21 12:38:51.535000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@31-4117-172.31.16.165:22-144.225.8.54:34368 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:51.918909 sshd[4938]: Connection closed by authenticating user root 144.225.8.54 port 34368 [preauth] Jul 21 12:38:51.918000 audit[4938]: AUDIT1109 pid=4938 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:51.923860 systemd[1]: sshd@31-4117-172.31.16.165:22-144.225.8.54:34368.service: Deactivated successfully. Jul 21 12:38:51.923000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@31-4117-172.31.16.165:22-144.225.8.54:34368 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:51.994000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@32-4118-172.31.16.165:22-144.225.8.54:34382 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:51.995821 systemd[1]: Started sshd@32-4118-172.31.16.165:22-144.225.8.54:34382.service - OpenSSH per-connection server daemon (144.225.8.54:34382). Jul 21 12:38:52.372144 sshd[4945]: Connection closed by authenticating user root 144.225.8.54 port 34382 [preauth] Jul 21 12:38:52.374000 audit[4945]: AUDIT1109 pid=4945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:52.377597 kernel: kauditd_printk_skb: 44 callbacks suppressed Jul 21 12:38:52.377674 kernel: audit: type=1109 audit(1784637532.374:595): pid=4945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:52.383486 systemd[1]: sshd@32-4118-172.31.16.165:22-144.225.8.54:34382.service: Deactivated successfully. Jul 21 12:38:52.384000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@32-4118-172.31.16.165:22-144.225.8.54:34382 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:52.395248 kernel: audit: type=1131 audit(1784637532.384:596): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@32-4118-172.31.16.165:22-144.225.8.54:34382 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:52.458000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@33-4119-172.31.16.165:22-144.225.8.54:34390 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:52.459295 systemd[1]: Started sshd@33-4119-172.31.16.165:22-144.225.8.54:34390.service - OpenSSH per-connection server daemon (144.225.8.54:34390). Jul 21 12:38:52.466359 kernel: audit: type=1130 audit(1784637532.458:597): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@33-4119-172.31.16.165:22-144.225.8.54:34390 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:52.784497 containerd[2389]: time="2026-07-21T12:38:52.783633220Z" level=error msg="failed to reload cni configuration after receiving fs change event(WRITE \"/etc/cni/net.d/calico-kubeconfig\")" error="cni config load failed: no network config found in /etc/cni/net.d: cni plugin not initialized: failed to load cni config" Jul 21 12:38:52.787794 systemd[1]: cri-containerd-156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f.scope: Deactivated successfully. Jul 21 12:38:52.788441 systemd[1]: cri-containerd-156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f.scope: Consumed 1.217s CPU time over 1.530s wall clock time, 205.6M memory peak, 1.5M read from disk, 191.7M written to disk. Jul 21 12:38:52.793334 sshd[4951]: Connection closed by authenticating user root 144.225.8.54 port 34390 [preauth] Jul 21 12:38:52.792000 audit: BPF prog-id=156 op=UNLOAD Jul 21 12:38:52.792000 audit[4951]: AUDIT1109 pid=4951 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:52.800621 kernel: audit: type=1334 audit(1784637532.792:598): prog-id=156 op=UNLOAD Jul 21 12:38:52.800731 kernel: audit: type=1109 audit(1784637532.792:599): pid=4951 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:52.802365 containerd[2389]: time="2026-07-21T12:38:52.802186300Z" level=info msg="received container exit event container_id:\"156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f\" id:\"156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f\" pid:4920 exited_at:{seconds:1784637532 nanos:801464212}" Jul 21 12:38:52.802430 systemd[1]: sshd@33-4119-172.31.16.165:22-144.225.8.54:34390.service: Deactivated successfully. Jul 21 12:38:52.801000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@33-4119-172.31.16.165:22-144.225.8.54:34390 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:52.811367 kernel: audit: type=1131 audit(1784637532.801:600): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@33-4119-172.31.16.165:22-144.225.8.54:34390 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:52.851481 systemd[1]: run-containerd-io.containerd.runtime.v2.task-k8s.io-156c496059da61dc5bae0f4b7acdb3f0a243498710fc45fa764dd0bd676ed14f-rootfs.mount: Deactivated successfully. Jul 21 12:38:52.870170 systemd[1]: Started sshd@34-4120-172.31.16.165:22-144.225.8.54:34404.service - OpenSSH per-connection server daemon (144.225.8.54:34404). Jul 21 12:38:52.870000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@34-4120-172.31.16.165:22-144.225.8.54:34404 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:52.877954 kubelet[4002]: I0721 12:38:52.877389 4002 kubelet_node_status.go:439] "Fast updating node status as it just became ready" Jul 21 12:38:52.882697 kernel: audit: type=1130 audit(1784637532.870:601): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@34-4120-172.31.16.165:22-144.225.8.54:34404 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:52.990356 systemd[1]: Created slice kubepods-besteffort-pod0f387b73_51f8_48e1_9153_5bdf9a5d18b4.slice - libcontainer container kubepods-besteffort-pod0f387b73_51f8_48e1_9153_5bdf9a5d18b4.slice. Jul 21 12:38:53.055488 systemd[1]: Created slice kubepods-burstable-pod325210e6_833a_406c_b0cc_a5a598a42634.slice - libcontainer container kubepods-burstable-pod325210e6_833a_406c_b0cc_a5a598a42634.slice. Jul 21 12:38:53.079596 systemd[1]: Created slice kubepods-burstable-pod115029ad_1967_4a5d_8486_f0f9b1d4dbb5.slice - libcontainer container kubepods-burstable-pod115029ad_1967_4a5d_8486_f0f9b1d4dbb5.slice. Jul 21 12:38:53.082930 kubelet[4002]: I0721 12:38:53.082870 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"config-volume\" (UniqueName: \"kubernetes.io/configmap/115029ad-1967-4a5d-8486-f0f9b1d4dbb5-config-volume\") pod \"coredns-66bc5c9577-6bgj5\" (UID: \"115029ad-1967-4a5d-8486-f0f9b1d4dbb5\") " pod="kube-system/coredns-66bc5c9577-6bgj5" Jul 21 12:38:53.083085 kubelet[4002]: I0721 12:38:53.082941 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-jwd2k\" (UniqueName: \"kubernetes.io/projected/0f387b73-51f8-48e1-9153-5bdf9a5d18b4-kube-api-access-jwd2k\") pod \"calico-kube-controllers-cbf695f-b4zcr\" (UID: \"0f387b73-51f8-48e1-9153-5bdf9a5d18b4\") " pod="calico-system/calico-kube-controllers-cbf695f-b4zcr" Jul 21 12:38:53.083085 kubelet[4002]: I0721 12:38:53.082994 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"tigera-ca-bundle\" (UniqueName: \"kubernetes.io/configmap/0f387b73-51f8-48e1-9153-5bdf9a5d18b4-tigera-ca-bundle\") pod \"calico-kube-controllers-cbf695f-b4zcr\" (UID: \"0f387b73-51f8-48e1-9153-5bdf9a5d18b4\") " pod="calico-system/calico-kube-controllers-cbf695f-b4zcr" Jul 21 12:38:53.083085 kubelet[4002]: I0721 12:38:53.083040 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-n7kmf\" (UniqueName: \"kubernetes.io/projected/325210e6-833a-406c-b0cc-a5a598a42634-kube-api-access-n7kmf\") pod \"coredns-66bc5c9577-hjfjb\" (UID: \"325210e6-833a-406c-b0cc-a5a598a42634\") " pod="kube-system/coredns-66bc5c9577-hjfjb" Jul 21 12:38:53.083085 kubelet[4002]: I0721 12:38:53.083081 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-l2rtz\" (UniqueName: \"kubernetes.io/projected/115029ad-1967-4a5d-8486-f0f9b1d4dbb5-kube-api-access-l2rtz\") pod \"coredns-66bc5c9577-6bgj5\" (UID: \"115029ad-1967-4a5d-8486-f0f9b1d4dbb5\") " pod="kube-system/coredns-66bc5c9577-6bgj5" Jul 21 12:38:53.083342 kubelet[4002]: I0721 12:38:53.083116 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"config-volume\" (UniqueName: \"kubernetes.io/configmap/325210e6-833a-406c-b0cc-a5a598a42634-config-volume\") pod \"coredns-66bc5c9577-hjfjb\" (UID: \"325210e6-833a-406c-b0cc-a5a598a42634\") " pod="kube-system/coredns-66bc5c9577-hjfjb" Jul 21 12:38:53.103699 systemd[1]: Created slice kubepods-besteffort-pod7c47583c_939d_48bf_b62a_b656ab8fb6a5.slice - libcontainer container kubepods-besteffort-pod7c47583c_939d_48bf_b62a_b656ab8fb6a5.slice. Jul 21 12:38:53.128752 systemd[1]: Created slice kubepods-besteffort-pod9ad91eae_2d77_41fd_a210_1ddd3bf4e62a.slice - libcontainer container kubepods-besteffort-pod9ad91eae_2d77_41fd_a210_1ddd3bf4e62a.slice. Jul 21 12:38:53.146045 systemd[1]: Created slice kubepods-besteffort-pod0b7ec60e_2413_45ca_95d4_82567a28dfd4.slice - libcontainer container kubepods-besteffort-pod0b7ec60e_2413_45ca_95d4_82567a28dfd4.slice. Jul 21 12:38:53.170147 systemd[1]: Created slice kubepods-besteffort-pod8b660833_58e5_4f31_ba07_2a53a00be574.slice - libcontainer container kubepods-besteffort-pod8b660833_58e5_4f31_ba07_2a53a00be574.slice. Jul 21 12:38:53.185247 kubelet[4002]: I0721 12:38:53.184129 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-psscf\" (UniqueName: \"kubernetes.io/projected/9ad91eae-2d77-41fd-a210-1ddd3bf4e62a-kube-api-access-psscf\") pod \"calico-apiserver-6b46596bdc-djqpg\" (UID: \"9ad91eae-2d77-41fd-a210-1ddd3bf4e62a\") " pod="calico-system/calico-apiserver-6b46596bdc-djqpg" Jul 21 12:38:53.185520 kubelet[4002]: I0721 12:38:53.184281 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"nginx-config\" (UniqueName: \"kubernetes.io/configmap/7c47583c-939d-48bf-b62a-b656ab8fb6a5-nginx-config\") pod \"whisker-5485cf5dc5-sc58t\" (UID: \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\") " pod="calico-system/whisker-5485cf5dc5-sc58t" Jul 21 12:38:53.185815 kubelet[4002]: I0721 12:38:53.185739 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-zx95w\" (UniqueName: \"kubernetes.io/projected/7c47583c-939d-48bf-b62a-b656ab8fb6a5-kube-api-access-zx95w\") pod \"whisker-5485cf5dc5-sc58t\" (UID: \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\") " pod="calico-system/whisker-5485cf5dc5-sc58t" Jul 21 12:38:53.188763 kubelet[4002]: I0721 12:38:53.187388 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"config\" (UniqueName: \"kubernetes.io/configmap/8b660833-58e5-4f31-ba07-2a53a00be574-config\") pod \"goldmane-6ccc4cdfd5-djlw8\" (UID: \"8b660833-58e5-4f31-ba07-2a53a00be574\") " pod="calico-system/goldmane-6ccc4cdfd5-djlw8" Jul 21 12:38:53.188763 kubelet[4002]: I0721 12:38:53.187494 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"calico-apiserver-certs\" (UniqueName: \"kubernetes.io/secret/9ad91eae-2d77-41fd-a210-1ddd3bf4e62a-calico-apiserver-certs\") pod \"calico-apiserver-6b46596bdc-djqpg\" (UID: \"9ad91eae-2d77-41fd-a210-1ddd3bf4e62a\") " pod="calico-system/calico-apiserver-6b46596bdc-djqpg" Jul 21 12:38:53.188763 kubelet[4002]: I0721 12:38:53.187542 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"calico-apiserver-certs\" (UniqueName: \"kubernetes.io/secret/0b7ec60e-2413-45ca-95d4-82567a28dfd4-calico-apiserver-certs\") pod \"calico-apiserver-6b46596bdc-qpmql\" (UID: \"0b7ec60e-2413-45ca-95d4-82567a28dfd4\") " pod="calico-system/calico-apiserver-6b46596bdc-qpmql" Jul 21 12:38:53.188763 kubelet[4002]: I0721 12:38:53.187583 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"goldmane-ca-bundle\" (UniqueName: \"kubernetes.io/configmap/8b660833-58e5-4f31-ba07-2a53a00be574-goldmane-ca-bundle\") pod \"goldmane-6ccc4cdfd5-djlw8\" (UID: \"8b660833-58e5-4f31-ba07-2a53a00be574\") " pod="calico-system/goldmane-6ccc4cdfd5-djlw8" Jul 21 12:38:53.188763 kubelet[4002]: I0721 12:38:53.187622 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"whisker-backend-key-pair\" (UniqueName: \"kubernetes.io/secret/7c47583c-939d-48bf-b62a-b656ab8fb6a5-whisker-backend-key-pair\") pod \"whisker-5485cf5dc5-sc58t\" (UID: \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\") " pod="calico-system/whisker-5485cf5dc5-sc58t" Jul 21 12:38:53.189145 kubelet[4002]: I0721 12:38:53.187658 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"whisker-ca-bundle\" (UniqueName: \"kubernetes.io/configmap/7c47583c-939d-48bf-b62a-b656ab8fb6a5-whisker-ca-bundle\") pod \"whisker-5485cf5dc5-sc58t\" (UID: \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\") " pod="calico-system/whisker-5485cf5dc5-sc58t" Jul 21 12:38:53.189145 kubelet[4002]: I0721 12:38:53.187749 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-4k2lm\" (UniqueName: \"kubernetes.io/projected/0b7ec60e-2413-45ca-95d4-82567a28dfd4-kube-api-access-4k2lm\") pod \"calico-apiserver-6b46596bdc-qpmql\" (UID: \"0b7ec60e-2413-45ca-95d4-82567a28dfd4\") " pod="calico-system/calico-apiserver-6b46596bdc-qpmql" Jul 21 12:38:53.189145 kubelet[4002]: I0721 12:38:53.187791 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"goldmane-key-pair\" (UniqueName: \"kubernetes.io/secret/8b660833-58e5-4f31-ba07-2a53a00be574-goldmane-key-pair\") pod \"goldmane-6ccc4cdfd5-djlw8\" (UID: \"8b660833-58e5-4f31-ba07-2a53a00be574\") " pod="calico-system/goldmane-6ccc4cdfd5-djlw8" Jul 21 12:38:53.189145 kubelet[4002]: I0721 12:38:53.187833 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-4fd6d\" (UniqueName: \"kubernetes.io/projected/8b660833-58e5-4f31-ba07-2a53a00be574-kube-api-access-4fd6d\") pod \"goldmane-6ccc4cdfd5-djlw8\" (UID: \"8b660833-58e5-4f31-ba07-2a53a00be574\") " pod="calico-system/goldmane-6ccc4cdfd5-djlw8" Jul 21 12:38:53.224600 sshd[4969]: Connection closed by authenticating user root 144.225.8.54 port 34404 [preauth] Jul 21 12:38:53.223000 audit[4969]: AUDIT1109 pid=4969 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:53.231711 systemd[1]: sshd@34-4120-172.31.16.165:22-144.225.8.54:34404.service: Deactivated successfully. Jul 21 12:38:53.230000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@34-4120-172.31.16.165:22-144.225.8.54:34404 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:53.249717 kernel: audit: type=1109 audit(1784637533.223:602): pid=4969 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:53.249843 kernel: audit: type=1131 audit(1784637533.230:603): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@34-4120-172.31.16.165:22-144.225.8.54:34404 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:53.305000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@35-4121-172.31.16.165:22-144.225.8.54:34410 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:53.306114 systemd[1]: Started sshd@35-4121-172.31.16.165:22-144.225.8.54:34410.service - OpenSSH per-connection server daemon (144.225.8.54:34410). Jul 21 12:38:53.319526 kernel: audit: type=1130 audit(1784637533.305:604): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@35-4121-172.31.16.165:22-144.225.8.54:34410 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:53.335628 containerd[2389]: time="2026-07-21T12:38:53.335566874Z" level=info msg="RunPodSandbox for name:\"calico-kube-controllers-cbf695f-b4zcr\" uid:\"0f387b73-51f8-48e1-9153-5bdf9a5d18b4\" namespace:\"calico-system\"" Jul 21 12:38:53.409869 containerd[2389]: time="2026-07-21T12:38:53.409821099Z" level=info msg="RunPodSandbox for name:\"coredns-66bc5c9577-hjfjb\" uid:\"325210e6-833a-406c-b0cc-a5a598a42634\" namespace:\"kube-system\"" Jul 21 12:38:53.414991 containerd[2389]: time="2026-07-21T12:38:53.414940959Z" level=info msg="RunPodSandbox for name:\"coredns-66bc5c9577-6bgj5\" uid:\"115029ad-1967-4a5d-8486-f0f9b1d4dbb5\" namespace:\"kube-system\"" Jul 21 12:38:53.437774 systemd[1]: Created slice kubepods-besteffort-pode8df5361_881a_429a_bf39_9bdb2f450187.slice - libcontainer container kubepods-besteffort-pode8df5361_881a_429a_bf39_9bdb2f450187.slice. Jul 21 12:38:53.446774 containerd[2389]: time="2026-07-21T12:38:53.446722179Z" level=info msg="RunPodSandbox for name:\"calico-apiserver-6b46596bdc-djqpg\" uid:\"9ad91eae-2d77-41fd-a210-1ddd3bf4e62a\" namespace:\"calico-system\"" Jul 21 12:38:53.462719 containerd[2389]: time="2026-07-21T12:38:53.462668127Z" level=info msg="RunPodSandbox for name:\"csi-node-driver-4np6n\" uid:\"e8df5361-881a-429a-bf39-9bdb2f450187\" namespace:\"calico-system\"" Jul 21 12:38:53.476319 containerd[2389]: time="2026-07-21T12:38:53.475704975Z" level=info msg="RunPodSandbox for name:\"calico-apiserver-6b46596bdc-qpmql\" uid:\"0b7ec60e-2413-45ca-95d4-82567a28dfd4\" namespace:\"calico-system\"" Jul 21 12:38:53.486368 containerd[2389]: time="2026-07-21T12:38:53.486288831Z" level=info msg="RunPodSandbox for name:\"goldmane-6ccc4cdfd5-djlw8\" uid:\"8b660833-58e5-4f31-ba07-2a53a00be574\" namespace:\"calico-system\"" Jul 21 12:38:53.711983 sshd[4982]: Connection closed by authenticating user root 144.225.8.54 port 34410 [preauth] Jul 21 12:38:53.711000 audit[4982]: AUDIT1109 pid=4982 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:53.716936 systemd[1]: sshd@35-4121-172.31.16.165:22-144.225.8.54:34410.service: Deactivated successfully. Jul 21 12:38:53.719000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@35-4121-172.31.16.165:22-144.225.8.54:34410 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:53.723662 containerd[2389]: time="2026-07-21T12:38:53.722043592Z" level=info msg="RunPodSandbox for name:\"whisker-5485cf5dc5-sc58t\" uid:\"7c47583c-939d-48bf-b62a-b656ab8fb6a5\" namespace:\"calico-system\"" Jul 21 12:38:53.799000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@36-4122-172.31.16.165:22-144.225.8.54:34414 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:53.799422 systemd[1]: Started sshd@36-4122-172.31.16.165:22-144.225.8.54:34414.service - OpenSSH per-connection server daemon (144.225.8.54:34414). Jul 21 12:38:53.916610 containerd[2389]: time="2026-07-21T12:38:53.911070965Z" level=info msg="CreateContainer within sandbox \"5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09\" for container name:\"calico-node\"" Jul 21 12:38:54.050754 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount79288725.mount: Deactivated successfully. Jul 21 12:38:54.147153 containerd[2389]: time="2026-07-21T12:38:54.146573978Z" level=info msg="CreateContainer within sandbox \"5975bc12c13b43dc6c3c6f78dfd54231331c6e2a720674d352c88df2afe20f09\" for name:\"calico-node\" returns container id \"7343afd118f9f33e75a22213dcb244a1ff7ad2c8a1ada2064d660c6c7163c585\"" Jul 21 12:38:54.148610 containerd[2389]: time="2026-07-21T12:38:54.148459142Z" level=info msg="StartContainer for \"7343afd118f9f33e75a22213dcb244a1ff7ad2c8a1ada2064d660c6c7163c585\"" Jul 21 12:38:54.182931 containerd[2389]: time="2026-07-21T12:38:54.182501235Z" level=info msg="connecting to shim 7343afd118f9f33e75a22213dcb244a1ff7ad2c8a1ada2064d660c6c7163c585" address="unix:///run/containerd/s/40a333afa61a779671eddc82c3f5b50b9b0e8c216cdeaee0ce92b28c8929272f" protocol=ttrpc version=3 Jul 21 12:38:54.216245 sshd[5076]: Connection closed by authenticating user root 144.225.8.54 port 34414 [preauth] Jul 21 12:38:54.219000 audit[5076]: AUDIT1109 pid=5076 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:54.236913 systemd[1]: sshd@36-4122-172.31.16.165:22-144.225.8.54:34414.service: Deactivated successfully. Jul 21 12:38:54.238000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@36-4122-172.31.16.165:22-144.225.8.54:34414 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:54.294000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@37-4123-172.31.16.165:22-144.225.8.54:34420 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:54.295554 systemd[1]: Started sshd@37-4123-172.31.16.165:22-144.225.8.54:34420.service - OpenSSH per-connection server daemon (144.225.8.54:34420). Jul 21 12:38:54.368031 containerd[2389]: time="2026-07-21T12:38:54.367953844Z" level=error msg="Failed to destroy network for sandbox \"a50c8580606a3b23bb04243c9e24a406708851eac24fa1fc98f1b76e712535f2\"" error="plugin type=\"calico\" failed (delete): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.375337 systemd[1]: run-netns-cni\x2dc420ce7a\x2d76bc\x2ddaad\x2d478e\x2dc36597821559.mount: Deactivated successfully. Jul 21 12:38:54.390222 containerd[2389]: time="2026-07-21T12:38:54.390108232Z" level=error msg="Failed to destroy network for sandbox \"4fef6e60fdd7fda356aadcd592c046fd0fad1fe5845cf9c388a1983c2a79defa\"" error="plugin type=\"calico\" failed (delete): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.412613 containerd[2389]: time="2026-07-21T12:38:54.412496812Z" level=error msg="RunPodSandbox for name:\"coredns-66bc5c9577-hjfjb\" uid:\"325210e6-833a-406c-b0cc-a5a598a42634\" namespace:\"kube-system\" failed, error" error="rpc error: code = Unknown desc = failed to setup network for sandbox \"4fef6e60fdd7fda356aadcd592c046fd0fad1fe5845cf9c388a1983c2a79defa\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.413411 kubelet[4002]: E0721 12:38:54.413239 4002 log.go:32] "RunPodSandbox from runtime service failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"4fef6e60fdd7fda356aadcd592c046fd0fad1fe5845cf9c388a1983c2a79defa\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.413411 kubelet[4002]: E0721 12:38:54.413392 4002 kuberuntime_sandbox.go:71] "Failed to create sandbox for pod" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"4fef6e60fdd7fda356aadcd592c046fd0fad1fe5845cf9c388a1983c2a79defa\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="kube-system/coredns-66bc5c9577-hjfjb" Jul 21 12:38:54.414242 kubelet[4002]: E0721 12:38:54.413434 4002 kuberuntime_manager.go:1343] "CreatePodSandbox for pod failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"4fef6e60fdd7fda356aadcd592c046fd0fad1fe5845cf9c388a1983c2a79defa\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="kube-system/coredns-66bc5c9577-hjfjb" Jul 21 12:38:54.414242 kubelet[4002]: E0721 12:38:54.413518 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="failed to \"CreatePodSandbox\" for \"coredns-66bc5c9577-hjfjb_kube-system(325210e6-833a-406c-b0cc-a5a598a42634)\" with CreatePodSandboxError: \"Failed to create sandbox for pod \\\"coredns-66bc5c9577-hjfjb_kube-system(325210e6-833a-406c-b0cc-a5a598a42634)\\\": rpc error: code = Unknown desc = failed to setup network for sandbox \\\"4fef6e60fdd7fda356aadcd592c046fd0fad1fe5845cf9c388a1983c2a79defa\\\": plugin type=\\\"calico\\\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/\"" pod="kube-system/coredns-66bc5c9577-hjfjb" podUID="325210e6-833a-406c-b0cc-a5a598a42634" Jul 21 12:38:54.433243 containerd[2389]: time="2026-07-21T12:38:54.431021080Z" level=error msg="RunPodSandbox for name:\"csi-node-driver-4np6n\" uid:\"e8df5361-881a-429a-bf39-9bdb2f450187\" namespace:\"calico-system\" failed, error" error="rpc error: code = Unknown desc = failed to setup network for sandbox \"a50c8580606a3b23bb04243c9e24a406708851eac24fa1fc98f1b76e712535f2\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.435125 kubelet[4002]: E0721 12:38:54.434663 4002 log.go:32] "RunPodSandbox from runtime service failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"a50c8580606a3b23bb04243c9e24a406708851eac24fa1fc98f1b76e712535f2\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.435125 kubelet[4002]: E0721 12:38:54.434773 4002 kuberuntime_sandbox.go:71] "Failed to create sandbox for pod" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"a50c8580606a3b23bb04243c9e24a406708851eac24fa1fc98f1b76e712535f2\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/csi-node-driver-4np6n" Jul 21 12:38:54.435125 kubelet[4002]: E0721 12:38:54.434820 4002 kuberuntime_manager.go:1343] "CreatePodSandbox for pod failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"a50c8580606a3b23bb04243c9e24a406708851eac24fa1fc98f1b76e712535f2\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/csi-node-driver-4np6n" Jul 21 12:38:54.437555 kubelet[4002]: E0721 12:38:54.434899 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="failed to \"CreatePodSandbox\" for \"csi-node-driver-4np6n_calico-system(e8df5361-881a-429a-bf39-9bdb2f450187)\" with CreatePodSandboxError: \"Failed to create sandbox for pod \\\"csi-node-driver-4np6n_calico-system(e8df5361-881a-429a-bf39-9bdb2f450187)\\\": rpc error: code = Unknown desc = failed to setup network for sandbox \\\"a50c8580606a3b23bb04243c9e24a406708851eac24fa1fc98f1b76e712535f2\\\": plugin type=\\\"calico\\\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/\"" pod="calico-system/csi-node-driver-4np6n" podUID="e8df5361-881a-429a-bf39-9bdb2f450187" Jul 21 12:38:54.440933 systemd[1]: Started cri-containerd-7343afd118f9f33e75a22213dcb244a1ff7ad2c8a1ada2064d660c6c7163c585.scope - libcontainer container 7343afd118f9f33e75a22213dcb244a1ff7ad2c8a1ada2064d660c6c7163c585. Jul 21 12:38:54.457096 containerd[2389]: time="2026-07-21T12:38:54.456966424Z" level=error msg="Failed to destroy network for sandbox \"180acf82d7f2835681443f7622eb39d73be3baa99078c328102d06f8ba93ce09\"" error="plugin type=\"calico\" failed (delete): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.468094 containerd[2389]: time="2026-07-21T12:38:54.467985520Z" level=error msg="Failed to destroy network for sandbox \"6949d7839451810851607cc62ede916a68588eb6d6369d52f86bd2310403f91c\"" error="plugin type=\"calico\" failed (delete): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.469522 containerd[2389]: time="2026-07-21T12:38:54.469254616Z" level=error msg="RunPodSandbox for name:\"calico-kube-controllers-cbf695f-b4zcr\" uid:\"0f387b73-51f8-48e1-9153-5bdf9a5d18b4\" namespace:\"calico-system\" failed, error" error="rpc error: code = Unknown desc = failed to setup network for sandbox \"180acf82d7f2835681443f7622eb39d73be3baa99078c328102d06f8ba93ce09\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.470810 kubelet[4002]: E0721 12:38:54.470641 4002 log.go:32] "RunPodSandbox from runtime service failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"180acf82d7f2835681443f7622eb39d73be3baa99078c328102d06f8ba93ce09\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.470810 kubelet[4002]: E0721 12:38:54.470730 4002 kuberuntime_sandbox.go:71] "Failed to create sandbox for pod" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"180acf82d7f2835681443f7622eb39d73be3baa99078c328102d06f8ba93ce09\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/calico-kube-controllers-cbf695f-b4zcr" Jul 21 12:38:54.470810 kubelet[4002]: E0721 12:38:54.470765 4002 kuberuntime_manager.go:1343] "CreatePodSandbox for pod failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"180acf82d7f2835681443f7622eb39d73be3baa99078c328102d06f8ba93ce09\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/calico-kube-controllers-cbf695f-b4zcr" Jul 21 12:38:54.471083 kubelet[4002]: E0721 12:38:54.470841 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="failed to \"CreatePodSandbox\" for \"calico-kube-controllers-cbf695f-b4zcr_calico-system(0f387b73-51f8-48e1-9153-5bdf9a5d18b4)\" with CreatePodSandboxError: \"Failed to create sandbox for pod \\\"calico-kube-controllers-cbf695f-b4zcr_calico-system(0f387b73-51f8-48e1-9153-5bdf9a5d18b4)\\\": rpc error: code = Unknown desc = failed to setup network for sandbox \\\"180acf82d7f2835681443f7622eb39d73be3baa99078c328102d06f8ba93ce09\\\": plugin type=\\\"calico\\\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/\"" pod="calico-system/calico-kube-controllers-cbf695f-b4zcr" podUID="0f387b73-51f8-48e1-9153-5bdf9a5d18b4" Jul 21 12:38:54.483412 containerd[2389]: time="2026-07-21T12:38:54.483249328Z" level=error msg="RunPodSandbox for name:\"calico-apiserver-6b46596bdc-qpmql\" uid:\"0b7ec60e-2413-45ca-95d4-82567a28dfd4\" namespace:\"calico-system\" failed, error" error="rpc error: code = Unknown desc = failed to setup network for sandbox \"6949d7839451810851607cc62ede916a68588eb6d6369d52f86bd2310403f91c\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.485288 kubelet[4002]: E0721 12:38:54.484373 4002 log.go:32] "RunPodSandbox from runtime service failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"6949d7839451810851607cc62ede916a68588eb6d6369d52f86bd2310403f91c\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.485738 kubelet[4002]: E0721 12:38:54.485523 4002 kuberuntime_sandbox.go:71] "Failed to create sandbox for pod" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"6949d7839451810851607cc62ede916a68588eb6d6369d52f86bd2310403f91c\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/calico-apiserver-6b46596bdc-qpmql" Jul 21 12:38:54.485738 kubelet[4002]: E0721 12:38:54.485575 4002 kuberuntime_manager.go:1343] "CreatePodSandbox for pod failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"6949d7839451810851607cc62ede916a68588eb6d6369d52f86bd2310403f91c\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/calico-apiserver-6b46596bdc-qpmql" Jul 21 12:38:54.485738 kubelet[4002]: E0721 12:38:54.485672 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="failed to \"CreatePodSandbox\" for \"calico-apiserver-6b46596bdc-qpmql_calico-system(0b7ec60e-2413-45ca-95d4-82567a28dfd4)\" with CreatePodSandboxError: \"Failed to create sandbox for pod \\\"calico-apiserver-6b46596bdc-qpmql_calico-system(0b7ec60e-2413-45ca-95d4-82567a28dfd4)\\\": rpc error: code = Unknown desc = failed to setup network for sandbox \\\"6949d7839451810851607cc62ede916a68588eb6d6369d52f86bd2310403f91c\\\": plugin type=\\\"calico\\\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/\"" pod="calico-system/calico-apiserver-6b46596bdc-qpmql" podUID="0b7ec60e-2413-45ca-95d4-82567a28dfd4" Jul 21 12:38:54.576660 containerd[2389]: time="2026-07-21T12:38:54.576583721Z" level=error msg="Failed to destroy network for sandbox \"b22d269cef03abe20bdd6062ed8448519fa5e4905c3d95fb8fe152649d338458\"" error="plugin type=\"calico\" failed (delete): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.581000 audit: BPF prog-id=157 op=LOAD Jul 21 12:38:54.581000 audit[5184]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=31ba6ef6c268 a2=98 a3=0 items=0 ppid=4494 pid=5184 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:54.581000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3733343361666431313866396633336537356132323231336463623234 Jul 21 12:38:54.584000 audit: BPF prog-id=158 op=LOAD Jul 21 12:38:54.584000 audit[5184]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=31ba6ef6bfa8 a2=98 a3=0 items=0 ppid=4494 pid=5184 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:54.584000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3733343361666431313866396633336537356132323231336463623234 Jul 21 12:38:54.586000 audit: BPF prog-id=158 op=UNLOAD Jul 21 12:38:54.586000 audit[5184]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=5184 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:54.586000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3733343361666431313866396633336537356132323231336463623234 Jul 21 12:38:54.586000 audit: BPF prog-id=157 op=UNLOAD Jul 21 12:38:54.586000 audit[5184]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=13 a1=0 a2=0 a3=0 items=0 ppid=4494 pid=5184 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:54.586000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3733343361666431313866396633336537356132323231336463623234 Jul 21 12:38:54.587000 audit: BPF prog-id=159 op=LOAD Jul 21 12:38:54.587000 audit[5184]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=31ba6ef6c4b8 a2=98 a3=0 items=0 ppid=4494 pid=5184 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:54.587000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3733343361666431313866396633336537356132323231336463623234 Jul 21 12:38:54.590795 containerd[2389]: time="2026-07-21T12:38:54.590455349Z" level=error msg="RunPodSandbox for name:\"calico-apiserver-6b46596bdc-djqpg\" uid:\"9ad91eae-2d77-41fd-a210-1ddd3bf4e62a\" namespace:\"calico-system\" failed, error" error="rpc error: code = Unknown desc = failed to setup network for sandbox \"b22d269cef03abe20bdd6062ed8448519fa5e4905c3d95fb8fe152649d338458\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.593729 containerd[2389]: time="2026-07-21T12:38:54.593544365Z" level=error msg="Failed to destroy network for sandbox \"7329fd1d0b07970705dd2ca4f19fde16a96e652d73d9e746ebc36b9ccf042866\"" error="plugin type=\"calico\" failed (delete): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.594072 kubelet[4002]: E0721 12:38:54.593708 4002 log.go:32] "RunPodSandbox from runtime service failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"b22d269cef03abe20bdd6062ed8448519fa5e4905c3d95fb8fe152649d338458\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.594072 kubelet[4002]: E0721 12:38:54.593798 4002 kuberuntime_sandbox.go:71] "Failed to create sandbox for pod" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"b22d269cef03abe20bdd6062ed8448519fa5e4905c3d95fb8fe152649d338458\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/calico-apiserver-6b46596bdc-djqpg" Jul 21 12:38:54.594072 kubelet[4002]: E0721 12:38:54.593833 4002 kuberuntime_manager.go:1343] "CreatePodSandbox for pod failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"b22d269cef03abe20bdd6062ed8448519fa5e4905c3d95fb8fe152649d338458\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/calico-apiserver-6b46596bdc-djqpg" Jul 21 12:38:54.594689 kubelet[4002]: E0721 12:38:54.593938 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="failed to \"CreatePodSandbox\" for \"calico-apiserver-6b46596bdc-djqpg_calico-system(9ad91eae-2d77-41fd-a210-1ddd3bf4e62a)\" with CreatePodSandboxError: \"Failed to create sandbox for pod \\\"calico-apiserver-6b46596bdc-djqpg_calico-system(9ad91eae-2d77-41fd-a210-1ddd3bf4e62a)\\\": rpc error: code = Unknown desc = failed to setup network for sandbox \\\"b22d269cef03abe20bdd6062ed8448519fa5e4905c3d95fb8fe152649d338458\\\": plugin type=\\\"calico\\\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/\"" pod="calico-system/calico-apiserver-6b46596bdc-djqpg" podUID="9ad91eae-2d77-41fd-a210-1ddd3bf4e62a" Jul 21 12:38:54.601895 containerd[2389]: time="2026-07-21T12:38:54.601735493Z" level=error msg="RunPodSandbox for name:\"goldmane-6ccc4cdfd5-djlw8\" uid:\"8b660833-58e5-4f31-ba07-2a53a00be574\" namespace:\"calico-system\" failed, error" error="rpc error: code = Unknown desc = failed to setup network for sandbox \"7329fd1d0b07970705dd2ca4f19fde16a96e652d73d9e746ebc36b9ccf042866\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.603417 kubelet[4002]: E0721 12:38:54.603259 4002 log.go:32] "RunPodSandbox from runtime service failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"7329fd1d0b07970705dd2ca4f19fde16a96e652d73d9e746ebc36b9ccf042866\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.604174 kubelet[4002]: E0721 12:38:54.603373 4002 kuberuntime_sandbox.go:71] "Failed to create sandbox for pod" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"7329fd1d0b07970705dd2ca4f19fde16a96e652d73d9e746ebc36b9ccf042866\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/goldmane-6ccc4cdfd5-djlw8" Jul 21 12:38:54.604174 kubelet[4002]: E0721 12:38:54.603688 4002 kuberuntime_manager.go:1343] "CreatePodSandbox for pod failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"7329fd1d0b07970705dd2ca4f19fde16a96e652d73d9e746ebc36b9ccf042866\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/goldmane-6ccc4cdfd5-djlw8" Jul 21 12:38:54.604619 kubelet[4002]: E0721 12:38:54.604073 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="failed to \"CreatePodSandbox\" for \"goldmane-6ccc4cdfd5-djlw8_calico-system(8b660833-58e5-4f31-ba07-2a53a00be574)\" with CreatePodSandboxError: \"Failed to create sandbox for pod \\\"goldmane-6ccc4cdfd5-djlw8_calico-system(8b660833-58e5-4f31-ba07-2a53a00be574)\\\": rpc error: code = Unknown desc = failed to setup network for sandbox \\\"7329fd1d0b07970705dd2ca4f19fde16a96e652d73d9e746ebc36b9ccf042866\\\": plugin type=\\\"calico\\\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/\"" pod="calico-system/goldmane-6ccc4cdfd5-djlw8" podUID="8b660833-58e5-4f31-ba07-2a53a00be574" Jul 21 12:38:54.637905 containerd[2389]: time="2026-07-21T12:38:54.635264549Z" level=error msg="Failed to destroy network for sandbox \"1d20a241f1b62f68d9def8ca9942c87bac23977c147a564df493ce22d87821d1\"" error="plugin type=\"calico\" failed (delete): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.643313 containerd[2389]: time="2026-07-21T12:38:54.643067117Z" level=error msg="RunPodSandbox for name:\"coredns-66bc5c9577-6bgj5\" uid:\"115029ad-1967-4a5d-8486-f0f9b1d4dbb5\" namespace:\"kube-system\" failed, error" error="rpc error: code = Unknown desc = failed to setup network for sandbox \"1d20a241f1b62f68d9def8ca9942c87bac23977c147a564df493ce22d87821d1\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.644137 kubelet[4002]: E0721 12:38:54.644065 4002 log.go:32] "RunPodSandbox from runtime service failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"1d20a241f1b62f68d9def8ca9942c87bac23977c147a564df493ce22d87821d1\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.644315 kubelet[4002]: E0721 12:38:54.644184 4002 kuberuntime_sandbox.go:71] "Failed to create sandbox for pod" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"1d20a241f1b62f68d9def8ca9942c87bac23977c147a564df493ce22d87821d1\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="kube-system/coredns-66bc5c9577-6bgj5" Jul 21 12:38:54.644315 kubelet[4002]: E0721 12:38:54.644283 4002 kuberuntime_manager.go:1343] "CreatePodSandbox for pod failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"1d20a241f1b62f68d9def8ca9942c87bac23977c147a564df493ce22d87821d1\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="kube-system/coredns-66bc5c9577-6bgj5" Jul 21 12:38:54.644671 kubelet[4002]: E0721 12:38:54.644440 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="failed to \"CreatePodSandbox\" for \"coredns-66bc5c9577-6bgj5_kube-system(115029ad-1967-4a5d-8486-f0f9b1d4dbb5)\" with CreatePodSandboxError: \"Failed to create sandbox for pod \\\"coredns-66bc5c9577-6bgj5_kube-system(115029ad-1967-4a5d-8486-f0f9b1d4dbb5)\\\": rpc error: code = Unknown desc = failed to setup network for sandbox \\\"1d20a241f1b62f68d9def8ca9942c87bac23977c147a564df493ce22d87821d1\\\": plugin type=\\\"calico\\\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/\"" pod="kube-system/coredns-66bc5c9577-6bgj5" podUID="115029ad-1967-4a5d-8486-f0f9b1d4dbb5" Jul 21 12:38:54.647243 sshd[5197]: Connection closed by authenticating user root 144.225.8.54 port 34420 [preauth] Jul 21 12:38:54.647000 audit[5197]: AUDIT1109 pid=5197 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:54.653060 systemd[1]: sshd@37-4123-172.31.16.165:22-144.225.8.54:34420.service: Deactivated successfully. Jul 21 12:38:54.653000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@37-4123-172.31.16.165:22-144.225.8.54:34420 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:54.664075 containerd[2389]: time="2026-07-21T12:38:54.663898769Z" level=error msg="Failed to destroy network for sandbox \"9d68a05d4ec4586808f803ce95b75fc316217368bfa33cf6f5c478f04a17da5d\"" error="plugin type=\"calico\" failed (delete): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.669436 containerd[2389]: time="2026-07-21T12:38:54.669271109Z" level=error msg="RunPodSandbox for name:\"whisker-5485cf5dc5-sc58t\" uid:\"7c47583c-939d-48bf-b62a-b656ab8fb6a5\" namespace:\"calico-system\" failed, error" error="rpc error: code = Unknown desc = failed to setup network for sandbox \"9d68a05d4ec4586808f803ce95b75fc316217368bfa33cf6f5c478f04a17da5d\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.671049 kubelet[4002]: E0721 12:38:54.670394 4002 log.go:32] "RunPodSandbox from runtime service failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"9d68a05d4ec4586808f803ce95b75fc316217368bfa33cf6f5c478f04a17da5d\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" Jul 21 12:38:54.671049 kubelet[4002]: E0721 12:38:54.670487 4002 kuberuntime_sandbox.go:71] "Failed to create sandbox for pod" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"9d68a05d4ec4586808f803ce95b75fc316217368bfa33cf6f5c478f04a17da5d\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/whisker-5485cf5dc5-sc58t" Jul 21 12:38:54.671049 kubelet[4002]: E0721 12:38:54.670554 4002 kuberuntime_manager.go:1343] "CreatePodSandbox for pod failed" err="rpc error: code = Unknown desc = failed to setup network for sandbox \"9d68a05d4ec4586808f803ce95b75fc316217368bfa33cf6f5c478f04a17da5d\": plugin type=\"calico\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/" pod="calico-system/whisker-5485cf5dc5-sc58t" Jul 21 12:38:54.671568 kubelet[4002]: E0721 12:38:54.670639 4002 pod_workers.go:1324] "Error syncing pod, skipping" err="failed to \"CreatePodSandbox\" for \"whisker-5485cf5dc5-sc58t_calico-system(7c47583c-939d-48bf-b62a-b656ab8fb6a5)\" with CreatePodSandboxError: \"Failed to create sandbox for pod \\\"whisker-5485cf5dc5-sc58t_calico-system(7c47583c-939d-48bf-b62a-b656ab8fb6a5)\\\": rpc error: code = Unknown desc = failed to setup network for sandbox \\\"9d68a05d4ec4586808f803ce95b75fc316217368bfa33cf6f5c478f04a17da5d\\\": plugin type=\\\"calico\\\" failed (add): stat /var/lib/calico/nodename: no such file or directory: check that the calico/node container is running and has mounted /var/lib/calico/\"" pod="calico-system/whisker-5485cf5dc5-sc58t" podUID="7c47583c-939d-48bf-b62a-b656ab8fb6a5" Jul 21 12:38:54.686722 containerd[2389]: time="2026-07-21T12:38:54.686532917Z" level=info msg="StartContainer for \"7343afd118f9f33e75a22213dcb244a1ff7ad2c8a1ada2064d660c6c7163c585\" returns successfully" Jul 21 12:38:54.723557 systemd[1]: Started sshd@38-12-172.31.16.165:22-144.225.8.54:34434.service - OpenSSH per-connection server daemon (144.225.8.54:34434). Jul 21 12:38:54.722000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@38-12-172.31.16.165:22-144.225.8.54:34434 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:54.854119 systemd[1]: run-netns-cni\x2dad0628b1\x2d04c3\x2dd48a\x2da781\x2dda0654f6aaaa.mount: Deactivated successfully. Jul 21 12:38:54.854638 systemd[1]: run-netns-cni\x2d1454b64c\x2d9975\x2db4e9\x2dad14\x2d0c657c66ef1a.mount: Deactivated successfully. Jul 21 12:38:54.854748 systemd[1]: run-netns-cni\x2d7547eaac\x2d8b66\x2d9bbd\x2d74e9\x2dc1a00e8e61fe.mount: Deactivated successfully. Jul 21 12:38:54.854842 systemd[1]: run-netns-cni\x2d761bc714\x2d19d7\x2dbaf8\x2dc5d0\x2d01ba7eaf6988.mount: Deactivated successfully. Jul 21 12:38:54.855448 systemd[1]: run-netns-cni\x2d0f3a214f\x2d009c\x2deb03\x2dd210\x2db8ebf5410f36.mount: Deactivated successfully. Jul 21 12:38:54.855547 systemd[1]: run-netns-cni\x2dfb4560cc\x2d711b\x2d767d\x2d6d17\x2defc6a7aca06c.mount: Deactivated successfully. Jul 21 12:38:54.855658 systemd[1]: run-netns-cni\x2dfc3c9bac\x2dcf94\x2d3776\x2d3517\x2d15ecd085fb03.mount: Deactivated successfully. Jul 21 12:38:55.060350 sshd[5249]: Connection closed by authenticating user root 144.225.8.54 port 34434 [preauth] Jul 21 12:38:55.061000 audit[5249]: AUDIT1109 pid=5249 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:55.067713 systemd[1]: sshd@38-12-172.31.16.165:22-144.225.8.54:34434.service: Deactivated successfully. Jul 21 12:38:55.067000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@38-12-172.31.16.165:22-144.225.8.54:34434 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:55.141888 systemd[1]: Started sshd@39-4124-172.31.16.165:22-144.225.8.54:34440.service - OpenSSH per-connection server daemon (144.225.8.54:34440). Jul 21 12:38:55.140000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@39-4124-172.31.16.165:22-144.225.8.54:34440 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:55.460231 sshd[5284]: Connection closed by authenticating user root 144.225.8.54 port 34440 [preauth] Jul 21 12:38:55.459000 audit[5284]: AUDIT1109 pid=5284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:55.463864 systemd[1]: sshd@39-4124-172.31.16.165:22-144.225.8.54:34440.service: Deactivated successfully. Jul 21 12:38:55.464000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@39-4124-172.31.16.165:22-144.225.8.54:34440 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:55.540000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@40-4125-172.31.16.165:22-144.225.8.54:34454 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:55.541882 systemd[1]: Started sshd@40-4125-172.31.16.165:22-144.225.8.54:34454.service - OpenSSH per-connection server daemon (144.225.8.54:34454). Jul 21 12:38:55.594837 kubelet[4002]: I0721 12:38:55.594737 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="calico-system/calico-node-gm5s5" podStartSLOduration=6.139278441 podStartE2EDuration="26.594710598s" podCreationTimestamp="2026-07-21 12:38:29 +0000 UTC" firstStartedPulling="2026-07-21 12:38:30.647367162 +0000 UTC m=+27.600384498" lastFinishedPulling="2026-07-21 12:38:51.102799319 +0000 UTC m=+48.055816655" observedRunningTime="2026-07-21 12:38:54.830506446 +0000 UTC m=+51.783523794" watchObservedRunningTime="2026-07-21 12:38:55.594710598 +0000 UTC m=+52.547727970" Jul 21 12:38:55.628649 kubelet[4002]: I0721 12:38:55.628557 4002 reconciler_common.go:163] "operationExecutor.UnmountVolume started for volume \"whisker-backend-key-pair\" (UniqueName: \"kubernetes.io/secret/7c47583c-939d-48bf-b62a-b656ab8fb6a5-whisker-backend-key-pair\") pod \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\" (UID: \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\") " Jul 21 12:38:55.629088 kubelet[4002]: I0721 12:38:55.628660 4002 reconciler_common.go:163] "operationExecutor.UnmountVolume started for volume \"whisker-ca-bundle\" (UniqueName: \"kubernetes.io/configmap/7c47583c-939d-48bf-b62a-b656ab8fb6a5-whisker-ca-bundle\") pod \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\" (UID: \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\") " Jul 21 12:38:55.629088 kubelet[4002]: I0721 12:38:55.628705 4002 reconciler_common.go:163] "operationExecutor.UnmountVolume started for volume \"nginx-config\" (UniqueName: \"kubernetes.io/configmap/7c47583c-939d-48bf-b62a-b656ab8fb6a5-nginx-config\") pod \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\" (UID: \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\") " Jul 21 12:38:55.629088 kubelet[4002]: I0721 12:38:55.628748 4002 reconciler_common.go:163] "operationExecutor.UnmountVolume started for volume \"kube-api-access-zx95w\" (UniqueName: \"kubernetes.io/projected/7c47583c-939d-48bf-b62a-b656ab8fb6a5-kube-api-access-zx95w\") pod \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\" (UID: \"7c47583c-939d-48bf-b62a-b656ab8fb6a5\") " Jul 21 12:38:55.630974 kubelet[4002]: I0721 12:38:55.630902 4002 operation_generator.go:781] UnmountVolume.TearDown succeeded for volume "kubernetes.io/configmap/7c47583c-939d-48bf-b62a-b656ab8fb6a5-whisker-ca-bundle" (OuterVolumeSpecName: "whisker-ca-bundle") pod "7c47583c-939d-48bf-b62a-b656ab8fb6a5" (UID: "7c47583c-939d-48bf-b62a-b656ab8fb6a5"). InnerVolumeSpecName "whisker-ca-bundle". PluginName "kubernetes.io/configmap", VolumeGIDValue "" Jul 21 12:38:55.646799 kubelet[4002]: I0721 12:38:55.646470 4002 operation_generator.go:781] UnmountVolume.TearDown succeeded for volume "kubernetes.io/configmap/7c47583c-939d-48bf-b62a-b656ab8fb6a5-nginx-config" (OuterVolumeSpecName: "nginx-config") pod "7c47583c-939d-48bf-b62a-b656ab8fb6a5" (UID: "7c47583c-939d-48bf-b62a-b656ab8fb6a5"). InnerVolumeSpecName "nginx-config". PluginName "kubernetes.io/configmap", VolumeGIDValue "" Jul 21 12:38:55.661754 kubelet[4002]: I0721 12:38:55.661704 4002 operation_generator.go:781] UnmountVolume.TearDown succeeded for volume "kubernetes.io/projected/7c47583c-939d-48bf-b62a-b656ab8fb6a5-kube-api-access-zx95w" (OuterVolumeSpecName: "kube-api-access-zx95w") pod "7c47583c-939d-48bf-b62a-b656ab8fb6a5" (UID: "7c47583c-939d-48bf-b62a-b656ab8fb6a5"). InnerVolumeSpecName "kube-api-access-zx95w". PluginName "kubernetes.io/projected", VolumeGIDValue "" Jul 21 12:38:55.662626 systemd[1]: var-lib-kubelet-pods-7c47583c\x2d939d\x2d48bf\x2db62a\x2db656ab8fb6a5-volumes-kubernetes.io\x7eprojected-kube\x2dapi\x2daccess\x2dzx95w.mount: Deactivated successfully. Jul 21 12:38:55.668252 kubelet[4002]: I0721 12:38:55.664553 4002 operation_generator.go:781] UnmountVolume.TearDown succeeded for volume "kubernetes.io/secret/7c47583c-939d-48bf-b62a-b656ab8fb6a5-whisker-backend-key-pair" (OuterVolumeSpecName: "whisker-backend-key-pair") pod "7c47583c-939d-48bf-b62a-b656ab8fb6a5" (UID: "7c47583c-939d-48bf-b62a-b656ab8fb6a5"). InnerVolumeSpecName "whisker-backend-key-pair". PluginName "kubernetes.io/secret", VolumeGIDValue "" Jul 21 12:38:55.672177 systemd[1]: var-lib-kubelet-pods-7c47583c\x2d939d\x2d48bf\x2db62a\x2db656ab8fb6a5-volumes-kubernetes.io\x7esecret-whisker\x2dbackend\x2dkey\x2dpair.mount: Deactivated successfully. Jul 21 12:38:55.729885 kubelet[4002]: I0721 12:38:55.729678 4002 reconciler_common.go:299] "Volume detached for volume \"whisker-backend-key-pair\" (UniqueName: \"kubernetes.io/secret/7c47583c-939d-48bf-b62a-b656ab8fb6a5-whisker-backend-key-pair\") on node \"ip-172-31-16-165\" DevicePath \"\"" Jul 21 12:38:55.729885 kubelet[4002]: I0721 12:38:55.729731 4002 reconciler_common.go:299] "Volume detached for volume \"whisker-ca-bundle\" (UniqueName: \"kubernetes.io/configmap/7c47583c-939d-48bf-b62a-b656ab8fb6a5-whisker-ca-bundle\") on node \"ip-172-31-16-165\" DevicePath \"\"" Jul 21 12:38:55.729885 kubelet[4002]: I0721 12:38:55.729757 4002 reconciler_common.go:299] "Volume detached for volume \"nginx-config\" (UniqueName: \"kubernetes.io/configmap/7c47583c-939d-48bf-b62a-b656ab8fb6a5-nginx-config\") on node \"ip-172-31-16-165\" DevicePath \"\"" Jul 21 12:38:55.729885 kubelet[4002]: I0721 12:38:55.729797 4002 reconciler_common.go:299] "Volume detached for volume \"kube-api-access-zx95w\" (UniqueName: \"kubernetes.io/projected/7c47583c-939d-48bf-b62a-b656ab8fb6a5-kube-api-access-zx95w\") on node \"ip-172-31-16-165\" DevicePath \"\"" Jul 21 12:38:55.812952 systemd[1]: Removed slice kubepods-besteffort-pod7c47583c_939d_48bf_b62a_b656ab8fb6a5.slice - libcontainer container kubepods-besteffort-pod7c47583c_939d_48bf_b62a_b656ab8fb6a5.slice. Jul 21 12:38:55.924516 sshd[5292]: Connection closed by authenticating user root 144.225.8.54 port 34454 [preauth] Jul 21 12:38:55.926000 audit[5292]: AUDIT1109 pid=5292 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:55.934144 systemd[1]: sshd@40-4125-172.31.16.165:22-144.225.8.54:34454.service: Deactivated successfully. Jul 21 12:38:55.935000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@40-4125-172.31.16.165:22-144.225.8.54:34454 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:55.959960 systemd[1]: Created slice kubepods-besteffort-podf7761f55_d7ad_478f_aaa5_3aeed356a0d9.slice - libcontainer container kubepods-besteffort-podf7761f55_d7ad_478f_aaa5_3aeed356a0d9.slice. Jul 21 12:38:56.007000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@41-4126-172.31.16.165:22-144.225.8.54:34466 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:56.008031 systemd[1]: Started sshd@41-4126-172.31.16.165:22-144.225.8.54:34466.service - OpenSSH per-connection server daemon (144.225.8.54:34466). Jul 21 12:38:56.037334 kubelet[4002]: I0721 12:38:56.035946 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"whisker-backend-key-pair\" (UniqueName: \"kubernetes.io/secret/f7761f55-d7ad-478f-aaa5-3aeed356a0d9-whisker-backend-key-pair\") pod \"whisker-6555bfc866-rglrt\" (UID: \"f7761f55-d7ad-478f-aaa5-3aeed356a0d9\") " pod="calico-system/whisker-6555bfc866-rglrt" Jul 21 12:38:56.038192 kubelet[4002]: I0721 12:38:56.037665 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"kube-api-access-hlr6d\" (UniqueName: \"kubernetes.io/projected/f7761f55-d7ad-478f-aaa5-3aeed356a0d9-kube-api-access-hlr6d\") pod \"whisker-6555bfc866-rglrt\" (UID: \"f7761f55-d7ad-478f-aaa5-3aeed356a0d9\") " pod="calico-system/whisker-6555bfc866-rglrt" Jul 21 12:38:56.040227 kubelet[4002]: I0721 12:38:56.039764 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"nginx-config\" (UniqueName: \"kubernetes.io/configmap/f7761f55-d7ad-478f-aaa5-3aeed356a0d9-nginx-config\") pod \"whisker-6555bfc866-rglrt\" (UID: \"f7761f55-d7ad-478f-aaa5-3aeed356a0d9\") " pod="calico-system/whisker-6555bfc866-rglrt" Jul 21 12:38:56.040227 kubelet[4002]: I0721 12:38:56.039867 4002 reconciler_common.go:251] "operationExecutor.VerifyControllerAttachedVolume started for volume \"whisker-ca-bundle\" (UniqueName: \"kubernetes.io/configmap/f7761f55-d7ad-478f-aaa5-3aeed356a0d9-whisker-ca-bundle\") pod \"whisker-6555bfc866-rglrt\" (UID: \"f7761f55-d7ad-478f-aaa5-3aeed356a0d9\") " pod="calico-system/whisker-6555bfc866-rglrt" Jul 21 12:38:56.280556 containerd[2389]: time="2026-07-21T12:38:56.279070985Z" level=info msg="RunPodSandbox for name:\"whisker-6555bfc866-rglrt\" uid:\"f7761f55-d7ad-478f-aaa5-3aeed356a0d9\" namespace:\"calico-system\"" Jul 21 12:38:56.380089 sshd[5325]: Connection closed by authenticating user root 144.225.8.54 port 34466 [preauth] Jul 21 12:38:56.383000 audit[5325]: AUDIT1109 pid=5325 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:56.393079 systemd[1]: sshd@41-4126-172.31.16.165:22-144.225.8.54:34466.service: Deactivated successfully. Jul 21 12:38:56.393000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@41-4126-172.31.16.165:22-144.225.8.54:34466 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:56.462080 systemd[1]: Started sshd@42-4127-172.31.16.165:22-144.225.8.54:34470.service - OpenSSH per-connection server daemon (144.225.8.54:34470). Jul 21 12:38:56.461000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@42-4127-172.31.16.165:22-144.225.8.54:34470 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:56.839718 sshd[5349]: Connection closed by authenticating user root 144.225.8.54 port 34470 [preauth] Jul 21 12:38:56.840000 audit[5349]: AUDIT1109 pid=5349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:56.845894 systemd[1]: sshd@42-4127-172.31.16.165:22-144.225.8.54:34470.service: Deactivated successfully. Jul 21 12:38:56.845000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@42-4127-172.31.16.165:22-144.225.8.54:34470 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:56.905079 systemd-networkd[2075]: califfe15e350b2: Link UP Jul 21 12:38:56.908042 systemd-networkd[2075]: califfe15e350b2: Gained carrier Jul 21 12:38:56.929000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@43-4128-172.31.16.165:22-144.225.8.54:34476 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:56.930450 systemd[1]: Started sshd@43-4128-172.31.16.165:22-144.225.8.54:34476.service - OpenSSH per-connection server daemon (144.225.8.54:34476). Jul 21 12:38:56.978093 (udev-worker)[5373]: Network interface NamePolicy= disabled on kernel command line. Jul 21 12:38:57.004334 containerd[2389]: 2026-07-21 12:38:56.429 [ERROR][5336] cni-plugin/utils.go 116: File does not exist, skipping the error since RequireMTUFile is false error=open /var/lib/calico/mtu: no such file or directory filename="/var/lib/calico/mtu" Jul 21 12:38:57.004334 containerd[2389]: 2026-07-21 12:38:56.431 [INFO][5336] cni-plugin/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:38:57.004334 containerd[2389]: 2026-07-21 12:38:56.523 [INFO][5336] cni-plugin/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:38:57.004334 containerd[2389]: 2026-07-21 12:38:56.523 [INFO][5336] cni-plugin/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:38:57.004334 containerd[2389]: 2026-07-21 12:38:56.581 [INFO][5336] cni-plugin/plugin.go 343: Calico CNI found existing endpoint: &{{WorkloadEndpoint projectcalico.org/v3} {ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0 whisker-6555bfc866- calico-system f7761f55-d7ad-478f-aaa5-3aeed356a0d9 945 0 2026-07-21 12:38:55 +0000 UTC map[app.kubernetes.io/component:Whisker.operator.tigera.io app.kubernetes.io/instance:default app.kubernetes.io/managed-by:tigera-operator app.kubernetes.io/name:whisker app.kubernetes.io/part-of:Calico k8s-app:whisker pod-template-hash:6555bfc866 projectcalico.org/namespace:calico-system projectcalico.org/orchestrator:k8s projectcalico.org/serviceaccount:whisker] map[] [] [] []} {k8s ip-172-31-16-165 whisker-6555bfc866-rglrt eth0 whisker [] [] [kns.calico-system ksa.calico-system.whisker] califfe15e350b2 [] [] }} ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Namespace="calico-system" Pod="whisker-6555bfc866-rglrt" WorkloadEndpoint="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-" Jul 21 12:38:57.004334 containerd[2389]: 2026-07-21 12:38:56.581 [INFO][5336] cni-plugin/k8s.go 76: Extracted identifiers for CmdAddK8s ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Namespace="calico-system" Pod="whisker-6555bfc866-rglrt" WorkloadEndpoint="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" Jul 21 12:38:57.004803 containerd[2389]: 2026-07-21 12:38:56.738 [INFO][5354] ipam/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:38:57.004803 containerd[2389]: 2026-07-21 12:38:56.796 [INFO][5354] ipam/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:38:57.004803 containerd[2389]: 2026-07-21 12:38:56.796 [INFO][5354] ipam/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:38:57.004803 containerd[2389]: 2026-07-21 12:38:56.800 [INFO][5354] ipam/ipam_plugin.go 307: Calico CNI IPAM request count IPv4=1 IPv6=0 ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" HandleID="k8s-pod-network.13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Workload="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" Jul 21 12:38:57.004803 containerd[2389]: 2026-07-21 12:38:56.806 [INFO][5354] ipam/ipam_plugin.go 379: Auto assigning IP ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" HandleID="k8s-pod-network.13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Workload="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" assignArgs=ipam.AutoAssignArgs{Num4:1, Num6:0, HandleID:(*string)(0x400004ee30), Attrs:map[string]string{"namespace":"calico-system", "node":"ip-172-31-16-165", "pod":"whisker-6555bfc866-rglrt", "timestamp":"2026-07-21 12:38:56.800396216 +0000 UTC"}, Hostname:"ip-172-31-16-165", IPv4Pools:[]net.IPNet{}, IPv6Pools:[]net.IPNet{}, MaxBlocksPerHost:0, HostReservedAttrIPv4s:(*ipam.HostReservedAttr)(nil), HostReservedAttrIPv6s:(*ipam.HostReservedAttr)(nil), IntendedUse:"Workload", MaxAllocToHandlePerIPVersion:0, Namespace:(*v1.Namespace)(0x40002522c0)} Jul 21 12:38:57.004803 containerd[2389]: 2026-07-21 12:38:56.806 [INFO][5354] ipam/ipam_plugin.go 526: About to acquire host-wide IPAM lock. Jul 21 12:38:57.004803 containerd[2389]: 2026-07-21 12:38:56.806 [INFO][5354] ipam/ipam_plugin.go 541: Acquired host-wide IPAM lock. Jul 21 12:38:57.004803 containerd[2389]: 2026-07-21 12:38:56.807 [INFO][5354] ipam/ipam.go 118: Auto-assign 1 ipv4, 0 ipv6 addrs for host 'ip-172-31-16-165' Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.812 [INFO][5354] ipam/ipam.go 723: Looking up existing affinities for host handle="k8s-pod-network.13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" host="ip-172-31-16-165" Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.822 [INFO][5354] ipam/ipam.go 415: Looking up existing affinities for host host="ip-172-31-16-165" Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.831 [INFO][5354] ipam/ipam.go 531: Trying affinity for 192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.836 [INFO][5354] ipam/ipam.go 166: Attempting to load block cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.842 [INFO][5354] ipam/ipam.go 243: Affinity is confirmed and block has been loaded cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.843 [INFO][5354] ipam/ipam.go 1392: Attempting to assign 1 addresses from block block=192.168.27.128/26 handle="k8s-pod-network.13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" host="ip-172-31-16-165" Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.849 [INFO][5354] ipam/ipam.go 1974: Creating new handle: k8s-pod-network.13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.858 [INFO][5354] ipam/ipam.go 1422: Writing block in order to claim IPs block=192.168.27.128/26 handle="k8s-pod-network.13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" host="ip-172-31-16-165" Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.876 [INFO][5354] ipam/ipam.go 1438: Successfully claimed IPs: [192.168.27.129/26] block=192.168.27.128/26 handle="k8s-pod-network.13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" host="ip-172-31-16-165" Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.876 [INFO][5354] ipam/ipam.go 947: Auto-assigned 1 out of 1 IPv4s: [192.168.27.129/26] handle="k8s-pod-network.13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" host="ip-172-31-16-165" Jul 21 12:38:57.006464 containerd[2389]: 2026-07-21 12:38:56.876 [INFO][5354] ipam/ipam_plugin.go 547: Released host-wide IPAM lock. Jul 21 12:38:57.007029 containerd[2389]: 2026-07-21 12:38:56.876 [INFO][5354] ipam/ipam_plugin.go 403: Calico CNI IPAM assigned addresses IPv4=[192.168.27.129/26] IPv6=[] ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" HandleID="k8s-pod-network.13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Workload="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" Jul 21 12:38:57.007090 containerd[2389]: 2026-07-21 12:38:56.889 [INFO][5336] cni-plugin/k8s.go 422: Populated endpoint ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Namespace="calico-system" Pod="whisker-6555bfc866-rglrt" WorkloadEndpoint="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0", GenerateName:"whisker-6555bfc866-", Namespace:"calico-system", SelfLink:"", UID:"f7761f55-d7ad-478f-aaa5-3aeed356a0d9", ResourceVersion:"945", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 55, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"app.kubernetes.io/component":"Whisker.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"whisker", "app.kubernetes.io/part-of":"Calico", "k8s-app":"whisker", "pod-template-hash":"6555bfc866", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"whisker"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"", Pod:"whisker-6555bfc866-rglrt", Endpoint:"eth0", ServiceAccountName:"whisker", IPNetworks:[]string{"192.168.27.129/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.whisker"}, InterfaceName:"califfe15e350b2", MAC:"", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:38:57.007090 containerd[2389]: 2026-07-21 12:38:56.889 [INFO][5336] cni-plugin/k8s.go 423: Calico CNI using IPs: [192.168.27.129/32] ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Namespace="calico-system" Pod="whisker-6555bfc866-rglrt" WorkloadEndpoint="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" Jul 21 12:38:57.007090 containerd[2389]: 2026-07-21 12:38:56.890 [INFO][5336] cni-plugin/dataplane_linux.go 77: Setting the host side veth name to califfe15e350b2 ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Namespace="calico-system" Pod="whisker-6555bfc866-rglrt" WorkloadEndpoint="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" Jul 21 12:38:57.007090 containerd[2389]: 2026-07-21 12:38:56.903 [INFO][5336] cni-plugin/dataplane_linux.go 179: Read back correct host-side MAC. ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Namespace="calico-system" Pod="whisker-6555bfc866-rglrt" WorkloadEndpoint="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" Jul 21 12:38:57.007090 containerd[2389]: 2026-07-21 12:38:56.907 [INFO][5336] cni-plugin/dataplane_linux.go 292: Adding IPv4 route (inside container) ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Namespace="calico-system" Pod="whisker-6555bfc866-rglrt" WorkloadEndpoint="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" route=0.0.0.0/0 Jul 21 12:38:57.007090 containerd[2389]: 2026-07-21 12:38:56.910 [INFO][5336] cni-plugin/dataplane_linux.go 570: Disabling IPv4 forwarding ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Namespace="calico-system" Pod="whisker-6555bfc866-rglrt" WorkloadEndpoint="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" Jul 21 12:38:57.010592 containerd[2389]: 2026-07-21 12:38:56.916 [INFO][5336] cni-plugin/k8s.go 458: Added Mac, interface name, and active container ID to endpoint ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Namespace="calico-system" Pod="whisker-6555bfc866-rglrt" WorkloadEndpoint="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0", GenerateName:"whisker-6555bfc866-", Namespace:"calico-system", SelfLink:"", UID:"f7761f55-d7ad-478f-aaa5-3aeed356a0d9", ResourceVersion:"945", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 55, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"app.kubernetes.io/component":"Whisker.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"whisker", "app.kubernetes.io/part-of":"Calico", "k8s-app":"whisker", "pod-template-hash":"6555bfc866", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"whisker"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c", Pod:"whisker-6555bfc866-rglrt", Endpoint:"eth0", ServiceAccountName:"whisker", IPNetworks:[]string{"192.168.27.129/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.whisker"}, InterfaceName:"califfe15e350b2", MAC:"22:26:a8:3d:4a:4e", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:38:57.010592 containerd[2389]: 2026-07-21 12:38:56.985 [INFO][5336] cni-plugin/k8s.go 544: Wrote updated endpoint to datastore ContainerID="13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" Namespace="calico-system" Pod="whisker-6555bfc866-rglrt" WorkloadEndpoint="ip--172--31--16--165-k8s-whisker--6555bfc866--rglrt-eth0" Jul 21 12:38:57.107446 containerd[2389]: time="2026-07-21T12:38:57.107368529Z" level=info msg="connecting to shim 13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c" address="unix:///run/containerd/s/18e4bbb4d5c16b8d7d8aa3f28f79ddcf72483723f6f9aa9b97d6c7555ce78e47" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:38:57.208965 systemd[1]: Started cri-containerd-13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c.scope - libcontainer container 13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c. Jul 21 12:38:57.290000 audit: BPF prog-id=160 op=LOAD Jul 21 12:38:57.292000 audit: BPF prog-id=161 op=LOAD Jul 21 12:38:57.292000 audit[5402]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=7777f5d29f90 a2=98 a3=0 items=0 ppid=5391 pid=5402 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:57.292000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3133363531663062636561633435643764653532376536633835636232 Jul 21 12:38:57.294000 audit: BPF prog-id=161 op=UNLOAD Jul 21 12:38:57.294000 audit[5402]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=5391 pid=5402 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:57.294000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3133363531663062636561633435643764653532376536633835636232 Jul 21 12:38:57.294000 audit: BPF prog-id=162 op=LOAD Jul 21 12:38:57.294000 audit[5402]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=7777f5d2a268 a2=98 a3=0 items=0 ppid=5391 pid=5402 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:57.294000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3133363531663062636561633435643764653532376536633835636232 Jul 21 12:38:57.294000 audit: BPF prog-id=163 op=LOAD Jul 21 12:38:57.294000 audit[5402]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=7777f5d29fa8 a2=98 a3=0 items=0 ppid=5391 pid=5402 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:57.294000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3133363531663062636561633435643764653532376536633835636232 Jul 21 12:38:57.294000 audit: BPF prog-id=163 op=UNLOAD Jul 21 12:38:57.294000 audit[5402]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=5391 pid=5402 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:57.294000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3133363531663062636561633435643764653532376536633835636232 Jul 21 12:38:57.295000 audit: BPF prog-id=162 op=UNLOAD Jul 21 12:38:57.295000 audit[5402]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=5391 pid=5402 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:57.295000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3133363531663062636561633435643764653532376536633835636232 Jul 21 12:38:57.295000 audit: BPF prog-id=164 op=LOAD Jul 21 12:38:57.295000 audit[5402]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=7777f5d2a4b8 a2=98 a3=0 items=0 ppid=5391 pid=5402 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:57.295000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3133363531663062636561633435643764653532376536633835636232 Jul 21 12:38:57.351397 sshd[5371]: Connection closed by authenticating user root 144.225.8.54 port 34476 [preauth] Jul 21 12:38:57.353000 audit[5371]: AUDIT1109 pid=5371 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:57.359897 systemd[1]: sshd@43-4128-172.31.16.165:22-144.225.8.54:34476.service: Deactivated successfully. Jul 21 12:38:57.365000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@43-4128-172.31.16.165:22-144.225.8.54:34476 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:57.368992 kubelet[4002]: I0721 12:38:57.368484 4002 kubelet_volumes.go:163] "Cleaned up orphaned pod volumes dir" podUID="7c47583c-939d-48bf-b62a-b656ab8fb6a5" path="/var/lib/kubelet/pods/7c47583c-939d-48bf-b62a-b656ab8fb6a5/volumes" Jul 21 12:38:57.432000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@44-13-172.31.16.165:22-144.225.8.54:34480 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:57.436541 kernel: kauditd_printk_skb: 63 callbacks suppressed Jul 21 12:38:57.433843 systemd[1]: Started sshd@44-13-172.31.16.165:22-144.225.8.54:34480.service - OpenSSH per-connection server daemon (144.225.8.54:34480). Jul 21 12:38:57.436806 kernel: audit: type=1130 audit(1784637537.432:644): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@44-13-172.31.16.165:22-144.225.8.54:34480 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:57.595420 containerd[2389]: time="2026-07-21T12:38:57.594638792Z" level=info msg="RunPodSandbox for name:\"whisker-6555bfc866-rglrt\" uid:\"f7761f55-d7ad-478f-aaa5-3aeed356a0d9\" namespace:\"calico-system\" returns sandbox id \"13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c\"" Jul 21 12:38:57.601717 containerd[2389]: time="2026-07-21T12:38:57.601584068Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/whisker:v3.32.1\"" Jul 21 12:38:57.840420 sshd[5463]: Connection closed by authenticating user root 144.225.8.54 port 34480 [preauth] Jul 21 12:38:57.840000 audit[5463]: AUDIT1109 pid=5463 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:57.849358 systemd[1]: sshd@44-13-172.31.16.165:22-144.225.8.54:34480.service: Deactivated successfully. Jul 21 12:38:57.850000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@44-13-172.31.16.165:22-144.225.8.54:34480 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:57.858297 kernel: audit: type=1109 audit(1784637537.840:645): pid=5463 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:57.858445 kernel: audit: type=1131 audit(1784637537.850:646): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@44-13-172.31.16.165:22-144.225.8.54:34480 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:57.919000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@45-14-172.31.16.165:22-144.225.8.54:58406 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:57.920833 systemd[1]: Started sshd@45-14-172.31.16.165:22-144.225.8.54:58406.service - OpenSSH per-connection server daemon (144.225.8.54:58406). Jul 21 12:38:57.931245 kernel: audit: type=1130 audit(1784637537.919:647): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@45-14-172.31.16.165:22-144.225.8.54:58406 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:58.269622 sshd[5495]: Connection closed by authenticating user root 144.225.8.54 port 58406 [preauth] Jul 21 12:38:58.270000 audit[5495]: AUDIT1109 pid=5495 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:58.274989 systemd[1]: sshd@45-14-172.31.16.165:22-144.225.8.54:58406.service: Deactivated successfully. Jul 21 12:38:58.270000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@45-14-172.31.16.165:22-144.225.8.54:58406 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:58.286145 kernel: audit: type=1109 audit(1784637538.270:648): pid=5495 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:58.286863 kernel: audit: type=1131 audit(1784637538.270:649): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@45-14-172.31.16.165:22-144.225.8.54:58406 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:58.351662 systemd[1]: Started sshd@46-15-172.31.16.165:22-144.225.8.54:58410.service - OpenSSH per-connection server daemon (144.225.8.54:58410). Jul 21 12:38:58.353000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@46-15-172.31.16.165:22-144.225.8.54:58410 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:58.368252 kernel: audit: type=1130 audit(1784637538.353:650): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@46-15-172.31.16.165:22-144.225.8.54:58410 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:58.563000 audit: BPF prog-id=165 op=LOAD Jul 21 12:38:58.563000 audit[5430]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=13 a0=5 a1=ffffdb65eaf8 a2=94 a3=200000001 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.574067 kernel: audit: type=1334 audit(1784637538.563:651): prog-id=165 op=LOAD Jul 21 12:38:58.574436 kernel: audit: type=1300 audit(1784637538.563:651): arch=c00000b7 syscall=280 success=yes exit=13 a0=5 a1=ffffdb65eaf8 a2=94 a3=200000001 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.563000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.577676 kernel: audit: type=1327 audit(1784637538.563:651): proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.563000 audit: BPF prog-id=165 op=UNLOAD Jul 21 12:38:58.563000 audit[5430]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=d a1=0 a2=ffff8eba0548 a3=200000001 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.563000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.563000 audit: BPF prog-id=166 op=LOAD Jul 21 12:38:58.563000 audit[5430]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=13 a0=5 a1=ffffdb65eb68 a2=98 a3=ffffdb65ed78 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.563000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.565000 audit: BPF prog-id=166 op=UNLOAD Jul 21 12:38:58.565000 audit[5430]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=d a1=0 a2=ffff8eba0548 a3=ffffdb65ed78 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.565000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.565000 audit: BPF prog-id=167 op=LOAD Jul 21 12:38:58.565000 audit[5430]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=32 a0=5 a1=ffffdb65e818 a2=94 a3=200000001 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.565000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.565000 audit: BPF prog-id=167 op=UNLOAD Jul 21 12:38:58.565000 audit[5430]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=20 a1=0 a2=ffff8eba0548 a3=200000001 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.565000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.565000 audit: BPF prog-id=168 op=LOAD Jul 21 12:38:58.565000 audit[5430]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=32 a0=5 a1=ffffdb65e978 a2=98 a3=ffffdb65e9b3 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.565000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.565000 audit: BPF prog-id=168 op=UNLOAD Jul 21 12:38:58.565000 audit[5430]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=20 a1=0 a2=ffff8eba0548 a3=ffffdb65e9b3 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.565000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.637387 systemd-networkd[2075]: califfe15e350b2: Gained IPv6LL Jul 21 12:38:58.716572 sshd[5527]: Connection closed by authenticating user root 144.225.8.54 port 58410 [preauth] Jul 21 12:38:58.717000 audit[5527]: AUDIT1109 pid=5527 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:58.726964 systemd[1]: sshd@46-15-172.31.16.165:22-144.225.8.54:58410.service: Deactivated successfully. Jul 21 12:38:58.728000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@46-15-172.31.16.165:22-144.225.8.54:58410 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:58.811000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@47-16-172.31.16.165:22-144.225.8.54:58412 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:58.812493 systemd[1]: Started sshd@47-16-172.31.16.165:22-144.225.8.54:58412.service - OpenSSH per-connection server daemon (144.225.8.54:58412). Jul 21 12:38:58.835000 audit: BPF prog-id=169 op=LOAD Jul 21 12:38:58.835000 audit[5430]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=32 a0=5 a1=ffffdb65e1c8 a2=98 a3=ffffdb65e308 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.835000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.841000 audit: BPF prog-id=169 op=UNLOAD Jul 21 12:38:58.841000 audit[5430]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=20 a1=0 a2=ffff8eba0548 a3=ffffdb65e308 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.841000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.841000 audit: BPF prog-id=170 op=LOAD Jul 21 12:38:58.841000 audit[5430]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=32 a0=5 a1=ffffdb65e388 a2=98 a3=ffffdb65e3c0 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.841000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.851000 audit: BPF prog-id=170 op=UNLOAD Jul 21 12:38:58.851000 audit[5430]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=20 a1=0 a2=ffff8eba0548 a3=1f items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.851000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.877000 audit: BPF prog-id=171 op=LOAD Jul 21 12:38:58.877000 audit[5430]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=13 a0=5 a1=ffffdb65eb68 a2=98 a3=ffffdb65ed78 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.877000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:58.877000 audit: BPF prog-id=171 op=UNLOAD Jul 21 12:38:58.877000 audit[5430]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=d a1=0 a2=ffff8eba0548 a3=ffffdb65ed78 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:58.877000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:59.103000 audit: BPF prog-id=172 op=LOAD Jul 21 12:38:59.103000 audit[5430]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=32 a0=5 a1=ffffdb65e388 a2=98 a3=ffffdb65e3c0 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.103000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:59.123000 audit: BPF prog-id=172 op=UNLOAD Jul 21 12:38:59.123000 audit[5430]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=20 a1=0 a2=ffff8eba0548 a3=1f items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.123000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:59.125000 audit: BPF prog-id=173 op=LOAD Jul 21 12:38:59.125000 audit[5430]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=13 a0=5 a1=ffffdb65eb68 a2=98 a3=ffffdb65ed78 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.125000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:59.125000 audit: BPF prog-id=173 op=UNLOAD Jul 21 12:38:59.125000 audit[5430]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=d a1=0 a2=ffff8eba0548 a3=ffffdb65ed78 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.125000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:59.231781 sshd[5546]: Connection closed by authenticating user root 144.225.8.54 port 58412 [preauth] Jul 21 12:38:59.231000 audit[5546]: AUDIT1109 pid=5546 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:59.240135 systemd[1]: sshd@47-16-172.31.16.165:22-144.225.8.54:58412.service: Deactivated successfully. Jul 21 12:38:59.240000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@47-16-172.31.16.165:22-144.225.8.54:58412 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:59.317535 containerd[2389]: time="2026-07-21T12:38:59.317425040Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/whisker:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:59.321458 containerd[2389]: time="2026-07-21T12:38:59.321093296Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/whisker:v3.32.1: active requests=0, bytes read=5934723" Jul 21 12:38:59.322178 systemd[1]: Started sshd@48-17-172.31.16.165:22-144.225.8.54:58418.service - OpenSSH per-connection server daemon (144.225.8.54:58418). Jul 21 12:38:59.321000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@48-17-172.31.16.165:22-144.225.8.54:58418 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:59.326256 containerd[2389]: time="2026-07-21T12:38:59.324801428Z" level=info msg="ImageCreate event name:\"sha256:26e2ef81cb6ae8177d7ddc2708eedc80380f091bc68752a4b832042828755ed9\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:59.342307 containerd[2389]: time="2026-07-21T12:38:59.342033740Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/whisker@sha256:c15b4b3f4b5e82b89f287a4dabd1c90dce8189334c05616afd346d73cd4f92ed\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:38:59.350806 containerd[2389]: time="2026-07-21T12:38:59.350296328Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/whisker:v3.32.1\" with image id \"sha256:26e2ef81cb6ae8177d7ddc2708eedc80380f091bc68752a4b832042828755ed9\", repo tag \"ghcr.io/flatcar/calico/whisker:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/whisker@sha256:c15b4b3f4b5e82b89f287a4dabd1c90dce8189334c05616afd346d73cd4f92ed\", size \"8519611\" in 1.748650748s" Jul 21 12:38:59.351057 containerd[2389]: time="2026-07-21T12:38:59.351022652Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/whisker:v3.32.1\" returns image reference \"sha256:26e2ef81cb6ae8177d7ddc2708eedc80380f091bc68752a4b832042828755ed9\"" Jul 21 12:38:59.379534 containerd[2389]: time="2026-07-21T12:38:59.377552876Z" level=info msg="CreateContainer within sandbox \"13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c\" for container name:\"whisker\"" Jul 21 12:38:59.394000 audit: BPF prog-id=174 op=LOAD Jul 21 12:38:59.394000 audit[5430]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=32 a0=5 a1=ffffdb65e388 a2=98 a3=ffffdb65e3c0 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.394000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:59.403000 audit: BPF prog-id=174 op=UNLOAD Jul 21 12:38:59.403000 audit[5430]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=20 a1=0 a2=ffff8eba0548 a3=1f items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.403000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:38:59.426000 audit: BPF prog-id=175 op=LOAD Jul 21 12:38:59.426000 audit[5558]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=3 a0=5 a1=ffffce523048 a2=98 a3=ffffce523038 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.426000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.426000 audit: BPF prog-id=175 op=UNLOAD Jul 21 12:38:59.426000 audit[5558]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=3 a1=57156c a2=ffffce523018 a3=0 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.426000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.435000 audit: BPF prog-id=176 op=LOAD Jul 21 12:38:59.435000 audit[5558]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=4 a0=5 a1=ffffce522d08 a2=94 a3=95 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.435000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.435000 audit: BPF prog-id=176 op=UNLOAD Jul 21 12:38:59.435000 audit[5558]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=4 a1=57156c a2=94 a3=95 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.435000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.436000 audit: BPF prog-id=177 op=LOAD Jul 21 12:38:59.436000 audit[5558]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=4 a0=5 a1=ffffce522d68 a2=94 a3=2 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.436000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.436000 audit: BPF prog-id=177 op=UNLOAD Jul 21 12:38:59.436000 audit[5558]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=4 a1=57156c a2=70 a3=2 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.436000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.469253 containerd[2389]: time="2026-07-21T12:38:59.467189025Z" level=info msg="CreateContainer within sandbox \"13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c\" for name:\"whisker\" returns container id \"d8868853eb3e70b2acd4ecd1ffee6f490c051f16962a36b79fed0f5a1e78bddd\"" Jul 21 12:38:59.479682 containerd[2389]: time="2026-07-21T12:38:59.478794861Z" level=info msg="StartContainer for \"d8868853eb3e70b2acd4ecd1ffee6f490c051f16962a36b79fed0f5a1e78bddd\"" Jul 21 12:38:59.488937 containerd[2389]: time="2026-07-21T12:38:59.488876049Z" level=info msg="connecting to shim d8868853eb3e70b2acd4ecd1ffee6f490c051f16962a36b79fed0f5a1e78bddd" address="unix:///run/containerd/s/18e4bbb4d5c16b8d7d8aa3f28f79ddcf72483723f6f9aa9b97d6c7555ce78e47" protocol=ttrpc version=3 Jul 21 12:38:59.543849 systemd[1]: Started cri-containerd-d8868853eb3e70b2acd4ecd1ffee6f490c051f16962a36b79fed0f5a1e78bddd.scope - libcontainer container d8868853eb3e70b2acd4ecd1ffee6f490c051f16962a36b79fed0f5a1e78bddd. Jul 21 12:38:59.595000 audit: BPF prog-id=178 op=LOAD Jul 21 12:38:59.596000 audit: BPF prog-id=179 op=LOAD Jul 21 12:38:59.596000 audit[5561]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=1c3f3b031f90 a2=98 a3=0 items=0 ppid=5391 pid=5561 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.596000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6438383638383533656233653730623261636434656364316666656536 Jul 21 12:38:59.597000 audit: BPF prog-id=179 op=UNLOAD Jul 21 12:38:59.597000 audit[5561]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=5391 pid=5561 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.597000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6438383638383533656233653730623261636434656364316666656536 Jul 21 12:38:59.597000 audit: BPF prog-id=180 op=LOAD Jul 21 12:38:59.597000 audit[5561]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=1c3f3b032268 a2=98 a3=0 items=0 ppid=5391 pid=5561 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.597000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6438383638383533656233653730623261636434656364316666656536 Jul 21 12:38:59.597000 audit: BPF prog-id=181 op=LOAD Jul 21 12:38:59.597000 audit[5561]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=1c3f3b031fa8 a2=98 a3=0 items=0 ppid=5391 pid=5561 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.597000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6438383638383533656233653730623261636434656364316666656536 Jul 21 12:38:59.597000 audit: BPF prog-id=181 op=UNLOAD Jul 21 12:38:59.597000 audit[5561]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=5391 pid=5561 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.597000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6438383638383533656233653730623261636434656364316666656536 Jul 21 12:38:59.597000 audit: BPF prog-id=180 op=UNLOAD Jul 21 12:38:59.597000 audit[5561]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=5391 pid=5561 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.597000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6438383638383533656233653730623261636434656364316666656536 Jul 21 12:38:59.598000 audit: BPF prog-id=182 op=LOAD Jul 21 12:38:59.598000 audit[5561]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=1c3f3b0324b8 a2=98 a3=0 items=0 ppid=5391 pid=5561 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.598000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6438383638383533656233653730623261636434656364316666656536 Jul 21 12:38:59.752005 sshd[5556]: Connection closed by authenticating user root 144.225.8.54 port 58418 [preauth] Jul 21 12:38:59.752000 audit[5556]: AUDIT1109 pid=5556 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:38:59.758892 containerd[2389]: time="2026-07-21T12:38:59.757637398Z" level=info msg="StartContainer for \"d8868853eb3e70b2acd4ecd1ffee6f490c051f16962a36b79fed0f5a1e78bddd\" returns successfully" Jul 21 12:38:59.758341 systemd[1]: sshd@48-17-172.31.16.165:22-144.225.8.54:58418.service: Deactivated successfully. Jul 21 12:38:59.759000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@48-17-172.31.16.165:22-144.225.8.54:58418 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:59.766768 containerd[2389]: time="2026-07-21T12:38:59.765527206Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/whisker-backend:v3.32.1\"" Jul 21 12:38:59.831739 systemd[1]: Started sshd@49-18-172.31.16.165:22-144.225.8.54:58434.service - OpenSSH per-connection server daemon (144.225.8.54:58434). Jul 21 12:38:59.830000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@49-18-172.31.16.165:22-144.225.8.54:58434 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:38:59.904000 audit: BPF prog-id=183 op=LOAD Jul 21 12:38:59.904000 audit[5558]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=4 a0=5 a1=ffffce522d28 a2=94 a3=ffffce522d58 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.904000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.904000 audit: BPF prog-id=183 op=UNLOAD Jul 21 12:38:59.904000 audit[5558]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=4 a1=57156c a2=94 a3=ffffce522d58 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.904000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.925000 audit: BPF prog-id=184 op=LOAD Jul 21 12:38:59.925000 audit[5558]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=5 a0=5 a1=ffffce522d38 a2=94 a3=4 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.925000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.925000 audit: BPF prog-id=184 op=UNLOAD Jul 21 12:38:59.925000 audit[5558]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=5 a1=57156c a2=70 a3=4 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.925000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.926000 audit: BPF prog-id=185 op=LOAD Jul 21 12:38:59.926000 audit[5558]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=6 a0=5 a1=ffffce522b78 a2=94 a3=5 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.926000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.926000 audit: BPF prog-id=185 op=UNLOAD Jul 21 12:38:59.926000 audit[5558]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=6 a1=57156c a2=70 a3=5 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.926000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.927000 audit: BPF prog-id=186 op=LOAD Jul 21 12:38:59.927000 audit[5558]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=5 a0=5 a1=ffffce522da8 a2=94 a3=6 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.927000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.928000 audit: BPF prog-id=186 op=UNLOAD Jul 21 12:38:59.928000 audit[5558]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=5 a1=57156c a2=70 a3=6 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.928000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.928000 audit: BPF prog-id=187 op=LOAD Jul 21 12:38:59.928000 audit[5558]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=5 a0=5 a1=ffffce522578 a2=94 a3=88 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.928000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.930000 audit: BPF prog-id=188 op=LOAD Jul 21 12:38:59.930000 audit[5558]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=7 a0=5 a1=ffffce522338 a2=94 a3=2 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.930000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.930000 audit: BPF prog-id=188 op=UNLOAD Jul 21 12:38:59.930000 audit[5558]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=7 a1=57156c a2=c a3=0 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.930000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.931000 audit: BPF prog-id=187 op=UNLOAD Jul 21 12:38:59.931000 audit[5558]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=5 a1=57156c a2=caaa190 a3=ca9cb00 items=0 ppid=5430 pid=5558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.931000 audit: PROCTITLE proctitle=627066746F6F6C006D6170006C697374002D2D6A736F6E Jul 21 12:38:59.963000 audit: BPF prog-id=189 op=LOAD Jul 21 12:38:59.963000 audit[5604]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=3 a0=5 a1=ffffef18e4b8 a2=98 a3=ffffef18e4a8 items=0 ppid=5430 pid=5604 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.963000 audit: PROCTITLE proctitle=627066746F6F6C006D617000637265617465002F7379732F66732F6270662F63616C69636F2F63616C69636F5F6661696C736166655F706F7274735F763100747970650068617368006B657900340076616C7565003100656E7472696573003635353335006E616D650063616C69636F5F6661696C736166655F706F7274735F Jul 21 12:38:59.963000 audit: BPF prog-id=189 op=UNLOAD Jul 21 12:38:59.963000 audit[5604]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=3 a1=57156c a2=ffffef18e488 a3=0 items=0 ppid=5430 pid=5604 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.963000 audit: PROCTITLE proctitle=627066746F6F6C006D617000637265617465002F7379732F66732F6270662F63616C69636F2F63616C69636F5F6661696C736166655F706F7274735F763100747970650068617368006B657900340076616C7565003100656E7472696573003635353335006E616D650063616C69636F5F6661696C736166655F706F7274735F Jul 21 12:38:59.963000 audit: BPF prog-id=190 op=LOAD Jul 21 12:38:59.963000 audit[5604]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=3 a0=5 a1=ffffef18e368 a2=94 a3=95 items=0 ppid=5430 pid=5604 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.963000 audit: PROCTITLE proctitle=627066746F6F6C006D617000637265617465002F7379732F66732F6270662F63616C69636F2F63616C69636F5F6661696C736166655F706F7274735F763100747970650068617368006B657900340076616C7565003100656E7472696573003635353335006E616D650063616C69636F5F6661696C736166655F706F7274735F Jul 21 12:38:59.963000 audit: BPF prog-id=190 op=UNLOAD Jul 21 12:38:59.963000 audit[5604]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=3 a1=57156c a2=94 a3=95 items=0 ppid=5430 pid=5604 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.963000 audit: PROCTITLE proctitle=627066746F6F6C006D617000637265617465002F7379732F66732F6270662F63616C69636F2F63616C69636F5F6661696C736166655F706F7274735F763100747970650068617368006B657900340076616C7565003100656E7472696573003635353335006E616D650063616C69636F5F6661696C736166655F706F7274735F Jul 21 12:38:59.963000 audit: BPF prog-id=191 op=LOAD Jul 21 12:38:59.963000 audit[5604]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=3 a0=5 a1=ffffef18e398 a2=94 a3=ffffef18e3c8 items=0 ppid=5430 pid=5604 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.963000 audit: PROCTITLE proctitle=627066746F6F6C006D617000637265617465002F7379732F66732F6270662F63616C69636F2F63616C69636F5F6661696C736166655F706F7274735F763100747970650068617368006B657900340076616C7565003100656E7472696573003635353335006E616D650063616C69636F5F6661696C736166655F706F7274735F Jul 21 12:38:59.963000 audit: BPF prog-id=191 op=UNLOAD Jul 21 12:38:59.963000 audit[5604]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=3 a1=57156c a2=94 a3=ffffef18e3c8 items=0 ppid=5430 pid=5604 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:38:59.963000 audit: PROCTITLE proctitle=627066746F6F6C006D617000637265617465002F7379732F66732F6270662F63616C69636F2F63616C69636F5F6661696C736166655F706F7274735F763100747970650068617368006B657900340076616C7565003100656E7472696573003635353335006E616D650063616C69636F5F6661696C736166655F706F7274735F Jul 21 12:39:00.154636 sshd[5591]: Connection closed by authenticating user root 144.225.8.54 port 58434 [preauth] Jul 21 12:39:00.156000 audit[5591]: AUDIT1109 pid=5591 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:00.158160 (udev-worker)[5372]: Network interface NamePolicy= disabled on kernel command line. Jul 21 12:39:00.164000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@49-18-172.31.16.165:22-144.225.8.54:58434 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:00.162566 systemd-networkd[2075]: vxlan.calico: Link UP Jul 21 12:39:00.162583 systemd-networkd[2075]: vxlan.calico: Gained carrier Jul 21 12:39:00.163511 systemd[1]: sshd@49-18-172.31.16.165:22-144.225.8.54:58434.service: Deactivated successfully. Jul 21 12:39:00.206000 audit: BPF prog-id=192 op=LOAD Jul 21 12:39:00.206000 audit[5630]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=3 a0=5 a1=ffffd62a33e8 a2=98 a3=ffffd62a33d8 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.206000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.206000 audit: BPF prog-id=192 op=UNLOAD Jul 21 12:39:00.206000 audit[5630]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=3 a1=57156c a2=ffffd62a33b8 a3=0 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.206000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.207000 audit: BPF prog-id=193 op=LOAD Jul 21 12:39:00.207000 audit[5630]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=3 a0=5 a1=ffffd62a30c8 a2=94 a3=95 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.207000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.207000 audit: BPF prog-id=193 op=UNLOAD Jul 21 12:39:00.207000 audit[5630]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=3 a1=57156c a2=94 a3=95 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.207000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.207000 audit: BPF prog-id=194 op=LOAD Jul 21 12:39:00.207000 audit[5630]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=3 a0=5 a1=ffffd62a3128 a2=94 a3=2 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.207000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.207000 audit: BPF prog-id=194 op=UNLOAD Jul 21 12:39:00.207000 audit[5630]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=3 a1=57156c a2=70 a3=2 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.207000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.207000 audit: BPF prog-id=195 op=LOAD Jul 21 12:39:00.207000 audit[5630]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=6 a0=5 a1=ffffd62a2fa8 a2=94 a3=ffffd62a2fd8 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.207000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.207000 audit: BPF prog-id=195 op=UNLOAD Jul 21 12:39:00.207000 audit[5630]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=6 a1=57156c a2=94 a3=ffffd62a2fd8 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.207000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.207000 audit: BPF prog-id=196 op=LOAD Jul 21 12:39:00.207000 audit[5630]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=6 a0=5 a1=ffffd62a30f8 a2=94 a3=b7 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.207000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.208000 audit: BPF prog-id=196 op=UNLOAD Jul 21 12:39:00.208000 audit[5630]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=6 a1=57156c a2=70 a3=b7 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.208000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.209000 audit: BPF prog-id=197 op=LOAD Jul 21 12:39:00.209000 audit[5630]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=6 a0=5 a1=ffffd62a27a8 a2=94 a3=2 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.209000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.209000 audit: BPF prog-id=197 op=UNLOAD Jul 21 12:39:00.209000 audit[5630]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=6 a1=57156c a2=70 a3=2 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.209000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.209000 audit: BPF prog-id=198 op=LOAD Jul 21 12:39:00.209000 audit[5630]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=6 a0=5 a1=ffffd62a2938 a2=94 a3=30 items=0 ppid=5430 pid=5630 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.209000 audit: PROCTITLE proctitle=627066746F6F6C0070726F67006C6F6164002F7573722F6C69622F63616C69636F2F6270662F66696C7465722E6F002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41007479706500786470 Jul 21 12:39:00.219000 audit: BPF prog-id=199 op=LOAD Jul 21 12:39:00.219000 audit[5634]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=3 a0=5 a1=fffff3f49ae8 a2=98 a3=fffff3f49ad8 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.219000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.219000 audit: BPF prog-id=199 op=UNLOAD Jul 21 12:39:00.219000 audit[5634]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=3 a1=57156c a2=fffff3f49ab8 a3=0 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.219000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.219000 audit: BPF prog-id=200 op=LOAD Jul 21 12:39:00.219000 audit[5634]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=4 a0=5 a1=fffff3f497a8 a2=94 a3=95 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.219000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.219000 audit: BPF prog-id=200 op=UNLOAD Jul 21 12:39:00.219000 audit[5634]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=4 a1=57156c a2=94 a3=95 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.219000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.219000 audit: BPF prog-id=201 op=LOAD Jul 21 12:39:00.219000 audit[5634]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=4 a0=5 a1=fffff3f49808 a2=94 a3=2 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.219000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.219000 audit: BPF prog-id=201 op=UNLOAD Jul 21 12:39:00.219000 audit[5634]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=4 a1=57156c a2=70 a3=2 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.219000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.237130 systemd[1]: Started sshd@50-19-172.31.16.165:22-144.225.8.54:58440.service - OpenSSH per-connection server daemon (144.225.8.54:58440). Jul 21 12:39:00.236000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@50-19-172.31.16.165:22-144.225.8.54:58440 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:00.470000 audit: BPF prog-id=202 op=LOAD Jul 21 12:39:00.470000 audit[5634]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=4 a0=5 a1=fffff3f497c8 a2=94 a3=fffff3f497f8 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.470000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.470000 audit: BPF prog-id=202 op=UNLOAD Jul 21 12:39:00.470000 audit[5634]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=4 a1=57156c a2=94 a3=fffff3f497f8 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.470000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.492000 audit: BPF prog-id=203 op=LOAD Jul 21 12:39:00.492000 audit[5634]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=5 a0=5 a1=fffff3f497d8 a2=94 a3=4 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.492000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.492000 audit: BPF prog-id=203 op=UNLOAD Jul 21 12:39:00.492000 audit[5634]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=5 a1=57156c a2=70 a3=4 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.492000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.492000 audit: BPF prog-id=204 op=LOAD Jul 21 12:39:00.492000 audit[5634]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=6 a0=5 a1=fffff3f49618 a2=94 a3=5 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.492000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.493000 audit: BPF prog-id=204 op=UNLOAD Jul 21 12:39:00.493000 audit[5634]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=6 a1=57156c a2=70 a3=5 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.493000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.493000 audit: BPF prog-id=205 op=LOAD Jul 21 12:39:00.493000 audit[5634]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=5 a0=5 a1=fffff3f49848 a2=94 a3=6 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.493000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.493000 audit: BPF prog-id=205 op=UNLOAD Jul 21 12:39:00.493000 audit[5634]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=5 a1=57156c a2=70 a3=6 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.493000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.493000 audit: BPF prog-id=206 op=LOAD Jul 21 12:39:00.493000 audit[5634]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=5 a0=5 a1=fffff3f49018 a2=94 a3=88 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.493000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.494000 audit: BPF prog-id=207 op=LOAD Jul 21 12:39:00.494000 audit[5634]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=7 a0=5 a1=fffff3f48dd8 a2=94 a3=2 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.494000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.494000 audit: BPF prog-id=207 op=UNLOAD Jul 21 12:39:00.494000 audit[5634]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=7 a1=57156c a2=c a3=0 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.494000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.495000 audit: BPF prog-id=206 op=UNLOAD Jul 21 12:39:00.495000 audit[5634]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=5 a1=57156c a2=3a0ea190 a3=3a0dcb00 items=0 ppid=5430 pid=5634 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="bpftool" exe="/usr/bin/bpftool" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.495000 audit: PROCTITLE proctitle=627066746F6F6C002D2D6A736F6E002D2D7072657474790070726F670073686F770070696E6E6564002F7379732F66732F6270662F63616C69636F2F7864702F70726566696C7465725F76315F63616C69636F5F746D705F41 Jul 21 12:39:00.504000 audit: BPF prog-id=198 op=UNLOAD Jul 21 12:39:00.504000 audit[5430]: SYSCALL arch=c00000b7 syscall=35 success=yes exit=0 a0=ffffffffffffff9c a1=4000963200 a2=0 a3=0 items=0 ppid=5423 pid=5430 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="calico-node" exe="/usr/bin/calico-node" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.504000 audit: PROCTITLE proctitle=63616C69636F2D6E6F6465002D66656C6978 Jul 21 12:39:00.567144 sshd[5636]: Connection closed by authenticating user root 144.225.8.54 port 58440 [preauth] Jul 21 12:39:00.566000 audit[5636]: AUDIT1109 pid=5636 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:00.571143 systemd[1]: sshd@50-19-172.31.16.165:22-144.225.8.54:58440.service: Deactivated successfully. Jul 21 12:39:00.571000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@50-19-172.31.16.165:22-144.225.8.54:58440 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:00.629000 audit[5673]: NETFILTER_CFG table=nat:108 family=2 entries=15 op=nft_register_chain pid=5673 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:00.629000 audit[5673]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=5084 a0=3 a1=ffffdeae8030 a2=0 a3=ffff8929d7e0 items=0 ppid=5430 pid=5673 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.629000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:00.639000 audit[5674]: NETFILTER_CFG table=calico-arp:109 family=3 entries=9 op=nft_register_chain pid=5674 subj=system_u:system_r:kernel_t:s0 comm="nft" Jul 21 12:39:00.639000 audit[5674]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=1536 a0=3 a1=ffffd6b68028 a2=0 a3=ffffa2785020 items=0 ppid=5430 pid=5674 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="nft" exe="/usr/sbin/nft" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.639000 audit: PROCTITLE proctitle=2F7573722F7362696E2F6E6674002D66002D Jul 21 12:39:00.645000 audit[5679]: NETFILTER_CFG table=mangle:110 family=2 entries=18 op=nft_register_chain pid=5679 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:00.645000 audit[5679]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=8040 a0=3 a1=ffffd8e1f730 a2=0 a3=ffff958fb7e0 items=0 ppid=5430 pid=5679 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.645000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:00.648926 systemd[1]: Started sshd@51-20-172.31.16.165:22-144.225.8.54:58454.service - OpenSSH per-connection server daemon (144.225.8.54:58454). Jul 21 12:39:00.647000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@51-20-172.31.16.165:22-144.225.8.54:58454 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:00.661000 audit[5670]: NETFILTER_CFG table=raw:111 family=2 entries=21 op=nft_register_chain pid=5670 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:00.661000 audit[5670]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=8540 a0=3 a1=fffff0e72830 a2=0 a3=ffffadd907e0 items=0 ppid=5430 pid=5670 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.661000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:00.663000 audit[5671]: NETFILTER_CFG table=filter:112 family=2 entries=73 op=nft_register_chain pid=5671 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:00.663000 audit[5671]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=38700 a0=3 a1=ffffc1339a20 a2=0 a3=ffff930e57e0 items=0 ppid=5430 pid=5671 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:00.663000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:00.970099 sshd[5682]: Connection closed by authenticating user root 144.225.8.54 port 58454 [preauth] Jul 21 12:39:00.969000 audit[5682]: AUDIT1109 pid=5682 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:00.974011 systemd[1]: sshd@51-20-172.31.16.165:22-144.225.8.54:58454.service: Deactivated successfully. Jul 21 12:39:00.973000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@51-20-172.31.16.165:22-144.225.8.54:58454 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:01.043000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@52-4129-172.31.16.165:22-144.225.8.54:58466 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:01.044305 systemd[1]: Started sshd@52-4129-172.31.16.165:22-144.225.8.54:58466.service - OpenSSH per-connection server daemon (144.225.8.54:58466). Jul 21 12:39:01.372177 sshd[5698]: Connection closed by authenticating user root 144.225.8.54 port 58466 [preauth] Jul 21 12:39:01.371000 audit[5698]: AUDIT1109 pid=5698 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:01.377922 systemd[1]: sshd@52-4129-172.31.16.165:22-144.225.8.54:58466.service: Deactivated successfully. Jul 21 12:39:01.378000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@52-4129-172.31.16.165:22-144.225.8.54:58466 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:01.447000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@53-4130-172.31.16.165:22-144.225.8.54:58478 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:01.448050 systemd[1]: Started sshd@53-4130-172.31.16.165:22-144.225.8.54:58478.service - OpenSSH per-connection server daemon (144.225.8.54:58478). Jul 21 12:39:01.818324 sshd[5708]: Connection closed by authenticating user root 144.225.8.54 port 58478 [preauth] Jul 21 12:39:01.821000 audit[5708]: AUDIT1109 pid=5708 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:01.835085 systemd[1]: sshd@53-4130-172.31.16.165:22-144.225.8.54:58478.service: Deactivated successfully. Jul 21 12:39:01.835000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@53-4130-172.31.16.165:22-144.225.8.54:58478 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:01.907159 systemd[1]: Started sshd@54-4131-172.31.16.165:22-144.225.8.54:58494.service - OpenSSH per-connection server daemon (144.225.8.54:58494). Jul 21 12:39:01.906000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@54-4131-172.31.16.165:22-144.225.8.54:58494 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:02.032395 systemd-networkd[2075]: vxlan.calico: Gained IPv6LL Jul 21 12:39:02.285032 sshd[5714]: Connection closed by authenticating user root 144.225.8.54 port 58494 [preauth] Jul 21 12:39:02.284000 audit[5714]: AUDIT1109 pid=5714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:02.291084 systemd[1]: sshd@54-4131-172.31.16.165:22-144.225.8.54:58494.service: Deactivated successfully. Jul 21 12:39:02.292000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@54-4131-172.31.16.165:22-144.225.8.54:58494 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:02.369315 systemd[1]: Started sshd@55-4132-172.31.16.165:22-144.225.8.54:58504.service - OpenSSH per-connection server daemon (144.225.8.54:58504). Jul 21 12:39:02.369000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@55-4132-172.31.16.165:22-144.225.8.54:58504 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:02.388482 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount3986435978.mount: Deactivated successfully. Jul 21 12:39:02.450817 containerd[2389]: time="2026-07-21T12:39:02.450420444Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/whisker-backend:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:02.455655 containerd[2389]: time="2026-07-21T12:39:02.455024064Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/whisker-backend:v3.32.1: active requests=1, bytes read=18874368" Jul 21 12:39:02.459884 containerd[2389]: time="2026-07-21T12:39:02.459719472Z" level=info msg="ImageCreate event name:\"sha256:4e99e0e0121e58d031b42a5801b38c599f370e7726b7701dafe44a0090e95cae\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:02.468231 containerd[2389]: time="2026-07-21T12:39:02.465703548Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/whisker-backend@sha256:7dbabe59bd70625fc067156098b17367d636939053328201d45ef8e1aa56439c\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:02.469237 containerd[2389]: time="2026-07-21T12:39:02.468520128Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/whisker-backend:v3.32.1\" with image id \"sha256:4e99e0e0121e58d031b42a5801b38c599f370e7726b7701dafe44a0090e95cae\", repo tag \"ghcr.io/flatcar/calico/whisker-backend:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/whisker-backend@sha256:7dbabe59bd70625fc067156098b17367d636939053328201d45ef8e1aa56439c\", size \"22955564\" in 2.70176087s" Jul 21 12:39:02.469476 containerd[2389]: time="2026-07-21T12:39:02.469433208Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/whisker-backend:v3.32.1\" returns image reference \"sha256:4e99e0e0121e58d031b42a5801b38c599f370e7726b7701dafe44a0090e95cae\"" Jul 21 12:39:02.482069 containerd[2389]: time="2026-07-21T12:39:02.482010444Z" level=info msg="CreateContainer within sandbox \"13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c\" for container name:\"whisker-backend\"" Jul 21 12:39:02.529323 containerd[2389]: time="2026-07-21T12:39:02.529270764Z" level=info msg="CreateContainer within sandbox \"13651f0bceac45d7de527e6c85cb2c27ae01b7e2562041ac4c354b1ab1c7ce5c\" for name:\"whisker-backend\" returns container id \"17cf9c7327ba8cddab2bc210d6f451ba4c9554dee393a6f83aaa1883112a59cf\"" Jul 21 12:39:02.532810 containerd[2389]: time="2026-07-21T12:39:02.532760184Z" level=info msg="StartContainer for \"17cf9c7327ba8cddab2bc210d6f451ba4c9554dee393a6f83aaa1883112a59cf\"" Jul 21 12:39:02.537834 containerd[2389]: time="2026-07-21T12:39:02.537643308Z" level=info msg="connecting to shim 17cf9c7327ba8cddab2bc210d6f451ba4c9554dee393a6f83aaa1883112a59cf" address="unix:///run/containerd/s/18e4bbb4d5c16b8d7d8aa3f28f79ddcf72483723f6f9aa9b97d6c7555ce78e47" protocol=ttrpc version=3 Jul 21 12:39:02.588624 systemd[1]: Started cri-containerd-17cf9c7327ba8cddab2bc210d6f451ba4c9554dee393a6f83aaa1883112a59cf.scope - libcontainer container 17cf9c7327ba8cddab2bc210d6f451ba4c9554dee393a6f83aaa1883112a59cf. Jul 21 12:39:02.635000 audit: BPF prog-id=208 op=LOAD Jul 21 12:39:02.637430 kernel: kauditd_printk_skb: 289 callbacks suppressed Jul 21 12:39:02.637495 kernel: audit: type=1334 audit(1784637542.635:767): prog-id=208 op=LOAD Jul 21 12:39:02.638000 audit: BPF prog-id=209 op=LOAD Jul 21 12:39:02.638000 audit[5732]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=7965e5433f90 a2=98 a3=0 items=0 ppid=5391 pid=5732 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.651231 kernel: audit: type=1334 audit(1784637542.638:768): prog-id=209 op=LOAD Jul 21 12:39:02.651374 kernel: audit: type=1300 audit(1784637542.638:768): arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=7965e5433f90 a2=98 a3=0 items=0 ppid=5391 pid=5732 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.638000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3137636639633733323762613863646461623262633231306436663435 Jul 21 12:39:02.659956 kernel: audit: type=1327 audit(1784637542.638:768): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3137636639633733323762613863646461623262633231306436663435 Jul 21 12:39:02.638000 audit: BPF prog-id=209 op=UNLOAD Jul 21 12:39:02.666729 kernel: audit: type=1334 audit(1784637542.638:769): prog-id=209 op=UNLOAD Jul 21 12:39:02.638000 audit[5732]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=5391 pid=5732 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.674049 kernel: audit: type=1300 audit(1784637542.638:769): arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=5391 pid=5732 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.638000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3137636639633733323762613863646461623262633231306436663435 Jul 21 12:39:02.683024 kernel: audit: type=1327 audit(1784637542.638:769): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3137636639633733323762613863646461623262633231306436663435 Jul 21 12:39:02.639000 audit: BPF prog-id=210 op=LOAD Jul 21 12:39:02.688114 kernel: audit: type=1334 audit(1784637542.639:770): prog-id=210 op=LOAD Jul 21 12:39:02.639000 audit[5732]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=7965e5434268 a2=98 a3=0 items=0 ppid=5391 pid=5732 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.696720 kernel: audit: type=1300 audit(1784637542.639:770): arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=7965e5434268 a2=98 a3=0 items=0 ppid=5391 pid=5732 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.639000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3137636639633733323762613863646461623262633231306436663435 Jul 21 12:39:02.702743 kernel: audit: type=1327 audit(1784637542.639:770): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3137636639633733323762613863646461623262633231306436663435 Jul 21 12:39:02.641000 audit: BPF prog-id=211 op=LOAD Jul 21 12:39:02.641000 audit[5732]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=7965e5433fa8 a2=98 a3=0 items=0 ppid=5391 pid=5732 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.641000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3137636639633733323762613863646461623262633231306436663435 Jul 21 12:39:02.651000 audit: BPF prog-id=211 op=UNLOAD Jul 21 12:39:02.651000 audit[5732]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=5391 pid=5732 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.651000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3137636639633733323762613863646461623262633231306436663435 Jul 21 12:39:02.651000 audit: BPF prog-id=210 op=UNLOAD Jul 21 12:39:02.651000 audit[5732]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=5391 pid=5732 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.651000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3137636639633733323762613863646461623262633231306436663435 Jul 21 12:39:02.651000 audit: BPF prog-id=212 op=LOAD Jul 21 12:39:02.651000 audit[5732]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=7965e54344b8 a2=98 a3=0 items=0 ppid=5391 pid=5732 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.651000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3137636639633733323762613863646461623262633231306436663435 Jul 21 12:39:02.712622 sshd[5725]: Connection closed by authenticating user root 144.225.8.54 port 58504 [preauth] Jul 21 12:39:02.712000 audit[5725]: AUDIT1109 pid=5725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:02.718747 systemd[1]: sshd@55-4132-172.31.16.165:22-144.225.8.54:58504.service: Deactivated successfully. Jul 21 12:39:02.718000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@55-4132-172.31.16.165:22-144.225.8.54:58504 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:02.790000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@56-4133-172.31.16.165:22-144.225.8.54:58514 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:02.791821 systemd[1]: Started sshd@56-4133-172.31.16.165:22-144.225.8.54:58514.service - OpenSSH per-connection server daemon (144.225.8.54:58514). Jul 21 12:39:02.805574 containerd[2389]: time="2026-07-21T12:39:02.805325749Z" level=info msg="StartContainer for \"17cf9c7327ba8cddab2bc210d6f451ba4c9554dee393a6f83aaa1883112a59cf\" returns successfully" Jul 21 12:39:02.979000 audit[5770]: NETFILTER_CFG table=filter:113 family=2 entries=19 op=nft_register_rule pid=5770 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:02.979000 audit[5770]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=6736 a0=3 a1=ffffe1931d10 a2=0 a3=1 items=0 ppid=4148 pid=5770 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.979000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:02.990000 audit[5770]: NETFILTER_CFG table=nat:114 family=2 entries=21 op=nft_register_chain pid=5770 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:02.990000 audit[5770]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=7044 a0=3 a1=ffffe1931d10 a2=0 a3=1 items=0 ppid=4148 pid=5770 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:02.990000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:03.135428 sshd[5761]: Connection closed by authenticating user root 144.225.8.54 port 58514 [preauth] Jul 21 12:39:03.135000 audit[5761]: AUDIT1109 pid=5761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:03.141771 systemd[1]: sshd@56-4133-172.31.16.165:22-144.225.8.54:58514.service: Deactivated successfully. Jul 21 12:39:03.142000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@56-4133-172.31.16.165:22-144.225.8.54:58514 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:03.207000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@57-21-172.31.16.165:22-144.225.8.54:58518 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:03.208860 systemd[1]: Started sshd@57-21-172.31.16.165:22-144.225.8.54:58518.service - OpenSSH per-connection server daemon (144.225.8.54:58518). Jul 21 12:39:03.528725 sshd[5774]: Connection closed by authenticating user root 144.225.8.54 port 58518 [preauth] Jul 21 12:39:03.528000 audit[5774]: AUDIT1109 pid=5774 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:03.534656 systemd[1]: sshd@57-21-172.31.16.165:22-144.225.8.54:58518.service: Deactivated successfully. Jul 21 12:39:03.535000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@57-21-172.31.16.165:22-144.225.8.54:58518 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:03.608337 systemd[1]: Started sshd@58-22-172.31.16.165:22-144.225.8.54:58526.service - OpenSSH per-connection server daemon (144.225.8.54:58526). Jul 21 12:39:03.607000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@58-22-172.31.16.165:22-144.225.8.54:58526 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:03.928103 sshd[5782]: Connection closed by authenticating user root 144.225.8.54 port 58526 [preauth] Jul 21 12:39:03.930000 audit[5782]: AUDIT1109 pid=5782 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:03.935175 systemd[1]: sshd@58-22-172.31.16.165:22-144.225.8.54:58526.service: Deactivated successfully. Jul 21 12:39:03.936000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@58-22-172.31.16.165:22-144.225.8.54:58526 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:04.011814 systemd[1]: Started sshd@59-4134-172.31.16.165:22-144.225.8.54:58530.service - OpenSSH per-connection server daemon (144.225.8.54:58530). Jul 21 12:39:04.010000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@59-4134-172.31.16.165:22-144.225.8.54:58530 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:04.367102 sshd[5788]: Connection closed by authenticating user root 144.225.8.54 port 58530 [preauth] Jul 21 12:39:04.367000 audit[5788]: AUDIT1109 pid=5788 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:04.373056 systemd[1]: sshd@59-4134-172.31.16.165:22-144.225.8.54:58530.service: Deactivated successfully. Jul 21 12:39:04.376000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@59-4134-172.31.16.165:22-144.225.8.54:58530 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:04.447000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@60-4135-172.31.16.165:22-144.225.8.54:58542 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:04.448284 systemd[1]: Started sshd@60-4135-172.31.16.165:22-144.225.8.54:58542.service - OpenSSH per-connection server daemon (144.225.8.54:58542). Jul 21 12:39:04.495076 ntpd[2333]: Listen normally on 6 vxlan.calico 192.168.27.128:123 Jul 21 12:39:04.498125 ntpd[2333]: 21 Jul 12:39:04 ntpd[2333]: Listen normally on 6 vxlan.calico 192.168.27.128:123 Jul 21 12:39:04.498125 ntpd[2333]: 21 Jul 12:39:04 ntpd[2333]: Listen normally on 7 califfe15e350b2 [fe80::ecee:eeff:feee:eeee%4]:123 Jul 21 12:39:04.498125 ntpd[2333]: 21 Jul 12:39:04 ntpd[2333]: Listen normally on 8 vxlan.calico [fe80::64e1:81ff:fe82:7844%5]:123 Jul 21 12:39:04.497965 ntpd[2333]: Listen normally on 7 califfe15e350b2 [fe80::ecee:eeff:feee:eeee%4]:123 Jul 21 12:39:04.498028 ntpd[2333]: Listen normally on 8 vxlan.calico [fe80::64e1:81ff:fe82:7844%5]:123 Jul 21 12:39:04.768792 sshd[5794]: Connection closed by authenticating user root 144.225.8.54 port 58542 [preauth] Jul 21 12:39:04.768000 audit[5794]: AUDIT1109 pid=5794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:04.771876 systemd[1]: sshd@60-4135-172.31.16.165:22-144.225.8.54:58542.service: Deactivated successfully. Jul 21 12:39:04.771000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@60-4135-172.31.16.165:22-144.225.8.54:58542 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:04.845031 systemd[1]: Started sshd@61-4136-172.31.16.165:22-144.225.8.54:58544.service - OpenSSH per-connection server daemon (144.225.8.54:58544). Jul 21 12:39:04.844000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@61-4136-172.31.16.165:22-144.225.8.54:58544 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:05.147825 sshd[5800]: Connection closed by authenticating user root 144.225.8.54 port 58544 [preauth] Jul 21 12:39:05.147000 audit[5800]: AUDIT1109 pid=5800 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:05.151390 systemd[1]: sshd@61-4136-172.31.16.165:22-144.225.8.54:58544.service: Deactivated successfully. Jul 21 12:39:05.150000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@61-4136-172.31.16.165:22-144.225.8.54:58544 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:05.221000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@62-4137-172.31.16.165:22-144.225.8.54:58554 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:05.222692 systemd[1]: Started sshd@62-4137-172.31.16.165:22-144.225.8.54:58554.service - OpenSSH per-connection server daemon (144.225.8.54:58554). Jul 21 12:39:05.364635 containerd[2389]: time="2026-07-21T12:39:05.364567982Z" level=info msg="RunPodSandbox for name:\"calico-apiserver-6b46596bdc-qpmql\" uid:\"0b7ec60e-2413-45ca-95d4-82567a28dfd4\" namespace:\"calico-system\"" Jul 21 12:39:05.532248 sshd[5806]: Connection closed by authenticating user root 144.225.8.54 port 58554 [preauth] Jul 21 12:39:05.532000 audit[5806]: AUDIT1109 pid=5806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:05.538634 systemd[1]: sshd@62-4137-172.31.16.165:22-144.225.8.54:58554.service: Deactivated successfully. Jul 21 12:39:05.539000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@62-4137-172.31.16.165:22-144.225.8.54:58554 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:05.611000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@63-4138-172.31.16.165:22-144.225.8.54:58570 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:05.612801 systemd[1]: Started sshd@63-4138-172.31.16.165:22-144.225.8.54:58570.service - OpenSSH per-connection server daemon (144.225.8.54:58570). Jul 21 12:39:05.921744 systemd-networkd[2075]: calid1c2c3ae5c8: Link UP Jul 21 12:39:05.927745 systemd-networkd[2075]: calid1c2c3ae5c8: Gained carrier Jul 21 12:39:05.950928 (udev-worker)[5847]: Network interface NamePolicy= disabled on kernel command line. Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.563 [INFO][5809] cni-plugin/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.595 [INFO][5809] cni-plugin/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.595 [INFO][5809] cni-plugin/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.652 [INFO][5809] cni-plugin/plugin.go 343: Calico CNI found existing endpoint: &{{WorkloadEndpoint projectcalico.org/v3} {ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0 calico-apiserver-6b46596bdc- calico-system 0b7ec60e-2413-45ca-95d4-82567a28dfd4 896 0 2026-07-21 12:38:26 +0000 UTC map[apiserver:true app.kubernetes.io/component:APIServer.operator.tigera.io app.kubernetes.io/instance:default app.kubernetes.io/managed-by:tigera-operator app.kubernetes.io/name:calico-apiserver app.kubernetes.io/part-of:Calico k8s-app:calico-apiserver pod-template-hash:6b46596bdc projectcalico.org/namespace:calico-system projectcalico.org/orchestrator:k8s projectcalico.org/serviceaccount:calico-apiserver] map[] [] [] []} {k8s ip-172-31-16-165 calico-apiserver-6b46596bdc-qpmql eth0 calico-apiserver [] [] [kns.calico-system ksa.calico-system.calico-apiserver] calid1c2c3ae5c8 [] [] }} ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-qpmql" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.654 [INFO][5809] cni-plugin/k8s.go 76: Extracted identifiers for CmdAddK8s ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-qpmql" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.790 [INFO][5826] ipam/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.833 [INFO][5826] ipam/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.833 [INFO][5826] ipam/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.835 [INFO][5826] ipam/ipam_plugin.go 307: Calico CNI IPAM request count IPv4=1 IPv6=0 ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" HandleID="k8s-pod-network.24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Workload="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.840 [INFO][5826] ipam/ipam_plugin.go 379: Auto assigning IP ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" HandleID="k8s-pod-network.24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Workload="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" assignArgs=ipam.AutoAssignArgs{Num4:1, Num6:0, HandleID:(*string)(0x40006bfaa0), Attrs:map[string]string{"namespace":"calico-system", "node":"ip-172-31-16-165", "pod":"calico-apiserver-6b46596bdc-qpmql", "timestamp":"2026-07-21 12:39:05.835468793 +0000 UTC"}, Hostname:"ip-172-31-16-165", IPv4Pools:[]net.IPNet{}, IPv6Pools:[]net.IPNet{}, MaxBlocksPerHost:0, HostReservedAttrIPv4s:(*ipam.HostReservedAttr)(nil), HostReservedAttrIPv6s:(*ipam.HostReservedAttr)(nil), IntendedUse:"Workload", MaxAllocToHandlePerIPVersion:0, Namespace:(*v1.Namespace)(0x400037f340)} Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.840 [INFO][5826] ipam/ipam_plugin.go 526: About to acquire host-wide IPAM lock. Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.841 [INFO][5826] ipam/ipam_plugin.go 541: Acquired host-wide IPAM lock. Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.841 [INFO][5826] ipam/ipam.go 118: Auto-assign 1 ipv4, 0 ipv6 addrs for host 'ip-172-31-16-165' Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.845 [INFO][5826] ipam/ipam.go 723: Looking up existing affinities for host handle="k8s-pod-network.24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" host="ip-172-31-16-165" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.855 [INFO][5826] ipam/ipam.go 415: Looking up existing affinities for host host="ip-172-31-16-165" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.868 [INFO][5826] ipam/ipam.go 531: Trying affinity for 192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.871 [INFO][5826] ipam/ipam.go 166: Attempting to load block cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.878 [INFO][5826] ipam/ipam.go 243: Affinity is confirmed and block has been loaded cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.878 [INFO][5826] ipam/ipam.go 1392: Attempting to assign 1 addresses from block block=192.168.27.128/26 handle="k8s-pod-network.24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" host="ip-172-31-16-165" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.881 [INFO][5826] ipam/ipam.go 1974: Creating new handle: k8s-pod-network.24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.890 [INFO][5826] ipam/ipam.go 1422: Writing block in order to claim IPs block=192.168.27.128/26 handle="k8s-pod-network.24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" host="ip-172-31-16-165" Jul 21 12:39:05.979241 containerd[2389]: 2026-07-21 12:39:05.903 [INFO][5826] ipam/ipam.go 1438: Successfully claimed IPs: [192.168.27.130/26] block=192.168.27.128/26 handle="k8s-pod-network.24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" host="ip-172-31-16-165" Jul 21 12:39:05.985334 containerd[2389]: 2026-07-21 12:39:05.904 [INFO][5826] ipam/ipam.go 947: Auto-assigned 1 out of 1 IPv4s: [192.168.27.130/26] handle="k8s-pod-network.24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" host="ip-172-31-16-165" Jul 21 12:39:05.985334 containerd[2389]: 2026-07-21 12:39:05.904 [INFO][5826] ipam/ipam_plugin.go 547: Released host-wide IPAM lock. Jul 21 12:39:05.985334 containerd[2389]: 2026-07-21 12:39:05.904 [INFO][5826] ipam/ipam_plugin.go 403: Calico CNI IPAM assigned addresses IPv4=[192.168.27.130/26] IPv6=[] ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" HandleID="k8s-pod-network.24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Workload="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" Jul 21 12:39:05.985334 containerd[2389]: 2026-07-21 12:39:05.909 [INFO][5809] cni-plugin/k8s.go 422: Populated endpoint ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-qpmql" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0", GenerateName:"calico-apiserver-6b46596bdc-", Namespace:"calico-system", SelfLink:"", UID:"0b7ec60e-2413-45ca-95d4-82567a28dfd4", ResourceVersion:"896", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 26, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"apiserver":"true", "app.kubernetes.io/component":"APIServer.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"calico-apiserver", "app.kubernetes.io/part-of":"Calico", "k8s-app":"calico-apiserver", "pod-template-hash":"6b46596bdc", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"calico-apiserver"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"", Pod:"calico-apiserver-6b46596bdc-qpmql", Endpoint:"eth0", ServiceAccountName:"calico-apiserver", IPNetworks:[]string{"192.168.27.130/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.calico-apiserver"}, InterfaceName:"calid1c2c3ae5c8", MAC:"", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:05.985334 containerd[2389]: 2026-07-21 12:39:05.909 [INFO][5809] cni-plugin/k8s.go 423: Calico CNI using IPs: [192.168.27.130/32] ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-qpmql" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" Jul 21 12:39:05.985334 containerd[2389]: 2026-07-21 12:39:05.909 [INFO][5809] cni-plugin/dataplane_linux.go 77: Setting the host side veth name to calid1c2c3ae5c8 ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-qpmql" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" Jul 21 12:39:05.985334 containerd[2389]: 2026-07-21 12:39:05.919 [INFO][5809] cni-plugin/dataplane_linux.go 179: Read back correct host-side MAC. ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-qpmql" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" Jul 21 12:39:05.985334 containerd[2389]: 2026-07-21 12:39:05.928 [INFO][5809] cni-plugin/dataplane_linux.go 292: Adding IPv4 route (inside container) ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-qpmql" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" route=0.0.0.0/0 Jul 21 12:39:05.985334 containerd[2389]: 2026-07-21 12:39:05.932 [INFO][5809] cni-plugin/dataplane_linux.go 570: Disabling IPv4 forwarding ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-qpmql" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" Jul 21 12:39:05.986086 kubelet[4002]: I0721 12:39:05.984066 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="calico-system/whisker-6555bfc866-rglrt" podStartSLOduration=6.112606617 podStartE2EDuration="10.984041273s" podCreationTimestamp="2026-07-21 12:38:55 +0000 UTC" firstStartedPulling="2026-07-21 12:38:57.6008948 +0000 UTC m=+54.553912136" lastFinishedPulling="2026-07-21 12:39:02.472329372 +0000 UTC m=+59.425346792" observedRunningTime="2026-07-21 12:39:02.933548174 +0000 UTC m=+59.886565534" watchObservedRunningTime="2026-07-21 12:39:05.984041273 +0000 UTC m=+62.937058621" Jul 21 12:39:05.987157 containerd[2389]: 2026-07-21 12:39:05.933 [INFO][5809] cni-plugin/k8s.go 458: Added Mac, interface name, and active container ID to endpoint ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-qpmql" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0", GenerateName:"calico-apiserver-6b46596bdc-", Namespace:"calico-system", SelfLink:"", UID:"0b7ec60e-2413-45ca-95d4-82567a28dfd4", ResourceVersion:"896", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 26, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"apiserver":"true", "app.kubernetes.io/component":"APIServer.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"calico-apiserver", "app.kubernetes.io/part-of":"Calico", "k8s-app":"calico-apiserver", "pod-template-hash":"6b46596bdc", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"calico-apiserver"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f", Pod:"calico-apiserver-6b46596bdc-qpmql", Endpoint:"eth0", ServiceAccountName:"calico-apiserver", IPNetworks:[]string{"192.168.27.130/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.calico-apiserver"}, InterfaceName:"calid1c2c3ae5c8", MAC:"0e:38:64:23:6f:fa", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:05.987157 containerd[2389]: 2026-07-21 12:39:05.958 [INFO][5809] cni-plugin/k8s.go 544: Wrote updated endpoint to datastore ContainerID="24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-qpmql" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--qpmql-eth0" Jul 21 12:39:05.990351 sshd[5823]: Connection closed by authenticating user root 144.225.8.54 port 58570 [preauth] Jul 21 12:39:05.991000 audit[5823]: AUDIT1109 pid=5823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:05.995420 systemd[1]: sshd@63-4138-172.31.16.165:22-144.225.8.54:58570.service: Deactivated successfully. Jul 21 12:39:05.994000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@63-4138-172.31.16.165:22-144.225.8.54:58570 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:06.074000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@64-23-172.31.16.165:22-144.225.8.54:58580 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:06.075922 systemd[1]: Started sshd@64-23-172.31.16.165:22-144.225.8.54:58580.service - OpenSSH per-connection server daemon (144.225.8.54:58580). Jul 21 12:39:06.086251 containerd[2389]: time="2026-07-21T12:39:06.084998162Z" level=info msg="connecting to shim 24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f" address="unix:///run/containerd/s/4572f319c7ca3d0f9ea7e460faf448c396a3952c788884210644276a513d1f00" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:39:06.152000 audit[5876]: NETFILTER_CFG table=filter:115 family=2 entries=36 op=nft_register_chain pid=5876 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:06.152000 audit[5876]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=19608 a0=3 a1=ffffcdb43da0 a2=0 a3=ffffb520c7e0 items=0 ppid=5430 pid=5876 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:06.152000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:06.207000 audit[5897]: NETFILTER_CFG table=calico-arp:116 family=3 entries=3 op=nft_register_chain pid=5897 subj=system_u:system_r:kernel_t:s0 comm="nft" Jul 21 12:39:06.207000 audit[5897]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=732 a0=3 a1=fffff3812368 a2=0 a3=ffffbeb24020 items=0 ppid=5430 pid=5897 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="nft" exe="/usr/sbin/nft" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:06.207000 audit: PROCTITLE proctitle=2F7573722F7362696E2F6E6674002D66002D Jul 21 12:39:06.241668 systemd[1]: Started cri-containerd-24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f.scope - libcontainer container 24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f. Jul 21 12:39:06.322000 audit: BPF prog-id=213 op=LOAD Jul 21 12:39:06.326000 audit: BPF prog-id=214 op=LOAD Jul 21 12:39:06.326000 audit[5886]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1e9e18731f90 a2=98 a3=0 items=0 ppid=5868 pid=5886 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:06.326000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3234373239633831643832646431643131386439653236636636386532 Jul 21 12:39:06.328000 audit: BPF prog-id=214 op=UNLOAD Jul 21 12:39:06.328000 audit[5886]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=5868 pid=5886 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:06.328000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3234373239633831643832646431643131386439653236636636386532 Jul 21 12:39:06.328000 audit: BPF prog-id=215 op=LOAD Jul 21 12:39:06.328000 audit[5886]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1e9e18732268 a2=98 a3=0 items=0 ppid=5868 pid=5886 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:06.328000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3234373239633831643832646431643131386439653236636636386532 Jul 21 12:39:06.328000 audit: BPF prog-id=216 op=LOAD Jul 21 12:39:06.328000 audit[5886]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=1e9e18731fa8 a2=98 a3=0 items=0 ppid=5868 pid=5886 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:06.328000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3234373239633831643832646431643131386439653236636636386532 Jul 21 12:39:06.328000 audit: BPF prog-id=216 op=UNLOAD Jul 21 12:39:06.328000 audit[5886]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=5868 pid=5886 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:06.328000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3234373239633831643832646431643131386439653236636636386532 Jul 21 12:39:06.328000 audit: BPF prog-id=215 op=UNLOAD Jul 21 12:39:06.328000 audit[5886]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=5868 pid=5886 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:06.328000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3234373239633831643832646431643131386439653236636636386532 Jul 21 12:39:06.329000 audit: BPF prog-id=217 op=LOAD Jul 21 12:39:06.329000 audit[5886]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=1e9e187324b8 a2=98 a3=0 items=0 ppid=5868 pid=5886 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:06.329000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3234373239633831643832646431643131386439653236636636386532 Jul 21 12:39:06.418561 containerd[2389]: time="2026-07-21T12:39:06.418506867Z" level=info msg="RunPodSandbox for name:\"calico-apiserver-6b46596bdc-qpmql\" uid:\"0b7ec60e-2413-45ca-95d4-82567a28dfd4\" namespace:\"calico-system\" returns sandbox id \"24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f\"" Jul 21 12:39:06.422254 containerd[2389]: time="2026-07-21T12:39:06.421908039Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/apiserver:v3.32.1\"" Jul 21 12:39:06.458795 sshd[5871]: Connection closed by authenticating user root 144.225.8.54 port 58580 [preauth] Jul 21 12:39:06.457000 audit[5871]: AUDIT1109 pid=5871 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:06.461766 systemd[1]: sshd@64-23-172.31.16.165:22-144.225.8.54:58580.service: Deactivated successfully. Jul 21 12:39:06.463000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@64-23-172.31.16.165:22-144.225.8.54:58580 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:06.535288 systemd[1]: Started sshd@65-4139-172.31.16.165:22-144.225.8.54:58590.service - OpenSSH per-connection server daemon (144.225.8.54:58590). Jul 21 12:39:06.534000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@65-4139-172.31.16.165:22-144.225.8.54:58590 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:06.845099 sshd[5928]: Connection closed by authenticating user root 144.225.8.54 port 58590 [preauth] Jul 21 12:39:06.845000 audit[5928]: AUDIT1109 pid=5928 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:06.850757 systemd[1]: sshd@65-4139-172.31.16.165:22-144.225.8.54:58590.service: Deactivated successfully. Jul 21 12:39:06.850000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@65-4139-172.31.16.165:22-144.225.8.54:58590 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:06.919424 systemd[1]: Started sshd@66-24-172.31.16.165:22-144.225.8.54:58606.service - OpenSSH per-connection server daemon (144.225.8.54:58606). Jul 21 12:39:06.918000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@66-24-172.31.16.165:22-144.225.8.54:58606 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:07.214543 systemd-networkd[2075]: calid1c2c3ae5c8: Gained IPv6LL Jul 21 12:39:07.255950 sshd[5934]: Connection closed by authenticating user root 144.225.8.54 port 58606 [preauth] Jul 21 12:39:07.254000 audit[5934]: AUDIT1109 pid=5934 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:07.260132 systemd[1]: sshd@66-24-172.31.16.165:22-144.225.8.54:58606.service: Deactivated successfully. Jul 21 12:39:07.261000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@66-24-172.31.16.165:22-144.225.8.54:58606 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:07.333834 systemd[1]: Started sshd@67-4140-172.31.16.165:22-144.225.8.54:58616.service - OpenSSH per-connection server daemon (144.225.8.54:58616). Jul 21 12:39:07.332000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@67-4140-172.31.16.165:22-144.225.8.54:58616 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:07.358531 containerd[2389]: time="2026-07-21T12:39:07.356832208Z" level=info msg="RunPodSandbox for name:\"goldmane-6ccc4cdfd5-djlw8\" uid:\"8b660833-58e5-4f31-ba07-2a53a00be574\" namespace:\"calico-system\"" Jul 21 12:39:07.363801 containerd[2389]: time="2026-07-21T12:39:07.363606976Z" level=info msg="RunPodSandbox for name:\"csi-node-driver-4np6n\" uid:\"e8df5361-881a-429a-bf39-9bdb2f450187\" namespace:\"calico-system\"" Jul 21 12:39:07.369227 containerd[2389]: time="2026-07-21T12:39:07.368401516Z" level=info msg="RunPodSandbox for name:\"calico-apiserver-6b46596bdc-djqpg\" uid:\"9ad91eae-2d77-41fd-a210-1ddd3bf4e62a\" namespace:\"calico-system\"" Jul 21 12:39:07.716404 sshd[5945]: Connection closed by authenticating user root 144.225.8.54 port 58616 [preauth] Jul 21 12:39:07.719000 audit[5945]: AUDIT1109 pid=5945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:07.724176 kernel: kauditd_printk_skb: 82 callbacks suppressed Jul 21 12:39:07.724318 kernel: audit: type=1109 audit(1784637547.719:823): pid=5945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:07.731919 systemd[1]: sshd@67-4140-172.31.16.165:22-144.225.8.54:58616.service: Deactivated successfully. Jul 21 12:39:07.731000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@67-4140-172.31.16.165:22-144.225.8.54:58616 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:07.742243 kernel: audit: type=1131 audit(1784637547.731:824): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@67-4140-172.31.16.165:22-144.225.8.54:58616 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:07.796319 systemd[1]: Started sshd@68-4141-172.31.16.165:22-144.225.8.54:48486.service - OpenSSH per-connection server daemon (144.225.8.54:48486). Jul 21 12:39:07.795000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@68-4141-172.31.16.165:22-144.225.8.54:48486 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:07.811352 kernel: audit: type=1130 audit(1784637547.795:825): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@68-4141-172.31.16.165:22-144.225.8.54:48486 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:08.152567 sshd[5995]: Connection closed by authenticating user root 144.225.8.54 port 48486 [preauth] Jul 21 12:39:08.153000 audit[5995]: AUDIT1109 pid=5995 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:08.163501 kernel: audit: type=1109 audit(1784637548.153:826): pid=5995 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:08.163906 systemd-networkd[2075]: cali5f4e890389a: Link UP Jul 21 12:39:08.164459 systemd-networkd[2075]: cali5f4e890389a: Gained carrier Jul 21 12:39:08.173885 systemd[1]: sshd@68-4141-172.31.16.165:22-144.225.8.54:48486.service: Deactivated successfully. Jul 21 12:39:08.173000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@68-4141-172.31.16.165:22-144.225.8.54:48486 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:08.189443 kernel: audit: type=1131 audit(1784637548.173:827): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@68-4141-172.31.16.165:22-144.225.8.54:48486 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:08.256671 systemd[1]: Started sshd@69-25-172.31.16.165:22-144.225.8.54:48490.service - OpenSSH per-connection server daemon (144.225.8.54:48490). Jul 21 12:39:08.256000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@69-25-172.31.16.165:22-144.225.8.54:48490 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:07.596 [INFO][5948] cni-plugin/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:07.644 [INFO][5948] cni-plugin/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:07.645 [INFO][5948] cni-plugin/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:07.669 [INFO][5948] cni-plugin/plugin.go 343: Calico CNI found existing endpoint: &{{WorkloadEndpoint projectcalico.org/v3} {ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0 csi-node-driver- calico-system e8df5361-881a-429a-bf39-9bdb2f450187 750 0 2026-07-21 12:38:30 +0000 UTC map[app.kubernetes.io/component:Installation.operator.tigera.io app.kubernetes.io/instance:default app.kubernetes.io/managed-by:tigera-operator app.kubernetes.io/name:csi-node-driver app.kubernetes.io/part-of:Calico controller-revision-hash:7bc4f5785d k8s-app:csi-node-driver name:csi-node-driver pod-template-generation:1 projectcalico.org/namespace:calico-system projectcalico.org/orchestrator:k8s projectcalico.org/serviceaccount:csi-node-driver] map[] [] [] []} {k8s ip-172-31-16-165 csi-node-driver-4np6n eth0 csi-node-driver [] [] [kns.calico-system ksa.calico-system.csi-node-driver] cali5f4e890389a [] [] }} ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Namespace="calico-system" Pod="csi-node-driver-4np6n" WorkloadEndpoint="ip--172--31--16--165-k8s-csi--node--driver--4np6n-" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:07.670 [INFO][5948] cni-plugin/k8s.go 76: Extracted identifiers for CmdAddK8s ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Namespace="calico-system" Pod="csi-node-driver-4np6n" WorkloadEndpoint="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:07.925 [INFO][5982] ipam/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:07.998 [INFO][5982] ipam/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:07.998 [INFO][5982] ipam/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.005 [INFO][5982] ipam/ipam_plugin.go 307: Calico CNI IPAM request count IPv4=1 IPv6=0 ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" HandleID="k8s-pod-network.336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Workload="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.009 [INFO][5982] ipam/ipam_plugin.go 379: Auto assigning IP ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" HandleID="k8s-pod-network.336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Workload="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" assignArgs=ipam.AutoAssignArgs{Num4:1, Num6:0, HandleID:(*string)(0x4000492030), Attrs:map[string]string{"namespace":"calico-system", "node":"ip-172-31-16-165", "pod":"csi-node-driver-4np6n", "timestamp":"2026-07-21 12:39:08.005478843 +0000 UTC"}, Hostname:"ip-172-31-16-165", IPv4Pools:[]net.IPNet{}, IPv6Pools:[]net.IPNet{}, MaxBlocksPerHost:0, HostReservedAttrIPv4s:(*ipam.HostReservedAttr)(nil), HostReservedAttrIPv6s:(*ipam.HostReservedAttr)(nil), IntendedUse:"Workload", MaxAllocToHandlePerIPVersion:0, Namespace:(*v1.Namespace)(0x400073a9a0)} Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.009 [INFO][5982] ipam/ipam_plugin.go 526: About to acquire host-wide IPAM lock. Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.009 [INFO][5982] ipam/ipam_plugin.go 541: Acquired host-wide IPAM lock. Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.009 [INFO][5982] ipam/ipam.go 118: Auto-assign 1 ipv4, 0 ipv6 addrs for host 'ip-172-31-16-165' Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.014 [INFO][5982] ipam/ipam.go 723: Looking up existing affinities for host handle="k8s-pod-network.336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" host="ip-172-31-16-165" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.036 [INFO][5982] ipam/ipam.go 415: Looking up existing affinities for host host="ip-172-31-16-165" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.057 [INFO][5982] ipam/ipam.go 531: Trying affinity for 192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.065 [INFO][5982] ipam/ipam.go 166: Attempting to load block cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.073 [INFO][5982] ipam/ipam.go 243: Affinity is confirmed and block has been loaded cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.075 [INFO][5982] ipam/ipam.go 1392: Attempting to assign 1 addresses from block block=192.168.27.128/26 handle="k8s-pod-network.336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" host="ip-172-31-16-165" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.079 [INFO][5982] ipam/ipam.go 1974: Creating new handle: k8s-pod-network.336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.107 [INFO][5982] ipam/ipam.go 1422: Writing block in order to claim IPs block=192.168.27.128/26 handle="k8s-pod-network.336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" host="ip-172-31-16-165" Jul 21 12:39:08.263948 containerd[2389]: 2026-07-21 12:39:08.124 [INFO][5982] ipam/ipam.go 1438: Successfully claimed IPs: [192.168.27.131/26] block=192.168.27.128/26 handle="k8s-pod-network.336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" host="ip-172-31-16-165" Jul 21 12:39:08.272401 containerd[2389]: 2026-07-21 12:39:08.125 [INFO][5982] ipam/ipam.go 947: Auto-assigned 1 out of 1 IPv4s: [192.168.27.131/26] handle="k8s-pod-network.336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" host="ip-172-31-16-165" Jul 21 12:39:08.272401 containerd[2389]: 2026-07-21 12:39:08.125 [INFO][5982] ipam/ipam_plugin.go 547: Released host-wide IPAM lock. Jul 21 12:39:08.272401 containerd[2389]: 2026-07-21 12:39:08.126 [INFO][5982] ipam/ipam_plugin.go 403: Calico CNI IPAM assigned addresses IPv4=[192.168.27.131/26] IPv6=[] ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" HandleID="k8s-pod-network.336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Workload="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" Jul 21 12:39:08.272401 containerd[2389]: 2026-07-21 12:39:08.137 [INFO][5948] cni-plugin/k8s.go 422: Populated endpoint ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Namespace="calico-system" Pod="csi-node-driver-4np6n" WorkloadEndpoint="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0", GenerateName:"csi-node-driver-", Namespace:"calico-system", SelfLink:"", UID:"e8df5361-881a-429a-bf39-9bdb2f450187", ResourceVersion:"750", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 30, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"app.kubernetes.io/component":"Installation.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"csi-node-driver", "app.kubernetes.io/part-of":"Calico", "controller-revision-hash":"7bc4f5785d", "k8s-app":"csi-node-driver", "name":"csi-node-driver", "pod-template-generation":"1", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"csi-node-driver"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"", Pod:"csi-node-driver-4np6n", Endpoint:"eth0", ServiceAccountName:"csi-node-driver", IPNetworks:[]string{"192.168.27.131/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.csi-node-driver"}, InterfaceName:"cali5f4e890389a", MAC:"", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:08.272401 containerd[2389]: 2026-07-21 12:39:08.137 [INFO][5948] cni-plugin/k8s.go 423: Calico CNI using IPs: [192.168.27.131/32] ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Namespace="calico-system" Pod="csi-node-driver-4np6n" WorkloadEndpoint="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" Jul 21 12:39:08.272401 containerd[2389]: 2026-07-21 12:39:08.138 [INFO][5948] cni-plugin/dataplane_linux.go 77: Setting the host side veth name to cali5f4e890389a ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Namespace="calico-system" Pod="csi-node-driver-4np6n" WorkloadEndpoint="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" Jul 21 12:39:08.272401 containerd[2389]: 2026-07-21 12:39:08.158 [INFO][5948] cni-plugin/dataplane_linux.go 179: Read back correct host-side MAC. ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Namespace="calico-system" Pod="csi-node-driver-4np6n" WorkloadEndpoint="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" Jul 21 12:39:08.272401 containerd[2389]: 2026-07-21 12:39:08.160 [INFO][5948] cni-plugin/dataplane_linux.go 292: Adding IPv4 route (inside container) ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Namespace="calico-system" Pod="csi-node-driver-4np6n" WorkloadEndpoint="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" route=0.0.0.0/0 Jul 21 12:39:08.272401 containerd[2389]: 2026-07-21 12:39:08.160 [INFO][5948] cni-plugin/dataplane_linux.go 570: Disabling IPv4 forwarding ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Namespace="calico-system" Pod="csi-node-driver-4np6n" WorkloadEndpoint="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" Jul 21 12:39:08.275325 kernel: audit: type=1130 audit(1784637548.256:828): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@69-25-172.31.16.165:22-144.225.8.54:48490 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:08.275404 containerd[2389]: 2026-07-21 12:39:08.204 [INFO][5948] cni-plugin/k8s.go 458: Added Mac, interface name, and active container ID to endpoint ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Namespace="calico-system" Pod="csi-node-driver-4np6n" WorkloadEndpoint="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0", GenerateName:"csi-node-driver-", Namespace:"calico-system", SelfLink:"", UID:"e8df5361-881a-429a-bf39-9bdb2f450187", ResourceVersion:"750", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 30, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"app.kubernetes.io/component":"Installation.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"csi-node-driver", "app.kubernetes.io/part-of":"Calico", "controller-revision-hash":"7bc4f5785d", "k8s-app":"csi-node-driver", "name":"csi-node-driver", "pod-template-generation":"1", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"csi-node-driver"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e", Pod:"csi-node-driver-4np6n", Endpoint:"eth0", ServiceAccountName:"csi-node-driver", IPNetworks:[]string{"192.168.27.131/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.csi-node-driver"}, InterfaceName:"cali5f4e890389a", MAC:"f6:01:67:d9:a8:88", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:08.275404 containerd[2389]: 2026-07-21 12:39:08.242 [INFO][5948] cni-plugin/k8s.go 544: Wrote updated endpoint to datastore ContainerID="336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" Namespace="calico-system" Pod="csi-node-driver-4np6n" WorkloadEndpoint="ip--172--31--16--165-k8s-csi--node--driver--4np6n-eth0" Jul 21 12:39:08.331656 systemd-networkd[2075]: cali9a39a32a0ed: Link UP Jul 21 12:39:08.334691 systemd-networkd[2075]: cali9a39a32a0ed: Gained carrier Jul 21 12:39:08.439326 containerd[2389]: time="2026-07-21T12:39:08.438788333Z" level=info msg="connecting to shim 336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e" address="unix:///run/containerd/s/4b17f696d5f099a854edff7db3a04f9a670cb9817840980ffedb2fe99f11e712" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:07.615 [INFO][5946] cni-plugin/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:07.687 [INFO][5946] cni-plugin/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:07.688 [INFO][5946] cni-plugin/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:07.727 [INFO][5946] cni-plugin/plugin.go 343: Calico CNI found existing endpoint: &{{WorkloadEndpoint projectcalico.org/v3} {ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0 goldmane-6ccc4cdfd5- calico-system 8b660833-58e5-4f31-ba07-2a53a00be574 897 0 2026-07-21 12:38:26 +0000 UTC map[app.kubernetes.io/component:Goldmane.operator.tigera.io app.kubernetes.io/instance:default app.kubernetes.io/managed-by:tigera-operator app.kubernetes.io/name:goldmane app.kubernetes.io/part-of:Calico k8s-app:goldmane pod-template-hash:6ccc4cdfd5 projectcalico.org/namespace:calico-system projectcalico.org/orchestrator:k8s projectcalico.org/serviceaccount:goldmane] map[] [] [] []} {k8s ip-172-31-16-165 goldmane-6ccc4cdfd5-djlw8 eth0 goldmane [] [] [kns.calico-system ksa.calico-system.goldmane] cali9a39a32a0ed [] [] }} ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Namespace="calico-system" Pod="goldmane-6ccc4cdfd5-djlw8" WorkloadEndpoint="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:07.728 [INFO][5946] cni-plugin/k8s.go 76: Extracted identifiers for CmdAddK8s ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Namespace="calico-system" Pod="goldmane-6ccc4cdfd5-djlw8" WorkloadEndpoint="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:07.998 [INFO][5990] ipam/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.055 [INFO][5990] ipam/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.056 [INFO][5990] ipam/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.060 [INFO][5990] ipam/ipam_plugin.go 307: Calico CNI IPAM request count IPv4=1 IPv6=0 ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" HandleID="k8s-pod-network.8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Workload="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.074 [INFO][5990] ipam/ipam_plugin.go 379: Auto assigning IP ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" HandleID="k8s-pod-network.8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Workload="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" assignArgs=ipam.AutoAssignArgs{Num4:1, Num6:0, HandleID:(*string)(0x4000768df0), Attrs:map[string]string{"namespace":"calico-system", "node":"ip-172-31-16-165", "pod":"goldmane-6ccc4cdfd5-djlw8", "timestamp":"2026-07-21 12:39:08.060678004 +0000 UTC"}, Hostname:"ip-172-31-16-165", IPv4Pools:[]net.IPNet{}, IPv6Pools:[]net.IPNet{}, MaxBlocksPerHost:0, HostReservedAttrIPv4s:(*ipam.HostReservedAttr)(nil), HostReservedAttrIPv6s:(*ipam.HostReservedAttr)(nil), IntendedUse:"Workload", MaxAllocToHandlePerIPVersion:0, Namespace:(*v1.Namespace)(0x4000267600)} Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.074 [INFO][5990] ipam/ipam_plugin.go 526: About to acquire host-wide IPAM lock. Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.125 [INFO][5990] ipam/ipam_plugin.go 541: Acquired host-wide IPAM lock. Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.126 [INFO][5990] ipam/ipam.go 118: Auto-assign 1 ipv4, 0 ipv6 addrs for host 'ip-172-31-16-165' Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.137 [INFO][5990] ipam/ipam.go 723: Looking up existing affinities for host handle="k8s-pod-network.8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" host="ip-172-31-16-165" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.155 [INFO][5990] ipam/ipam.go 415: Looking up existing affinities for host host="ip-172-31-16-165" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.172 [INFO][5990] ipam/ipam.go 531: Trying affinity for 192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.184 [INFO][5990] ipam/ipam.go 166: Attempting to load block cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.198 [INFO][5990] ipam/ipam.go 243: Affinity is confirmed and block has been loaded cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.198 [INFO][5990] ipam/ipam.go 1392: Attempting to assign 1 addresses from block block=192.168.27.128/26 handle="k8s-pod-network.8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" host="ip-172-31-16-165" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.203 [INFO][5990] ipam/ipam.go 1974: Creating new handle: k8s-pod-network.8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043 Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.213 [INFO][5990] ipam/ipam.go 1422: Writing block in order to claim IPs block=192.168.27.128/26 handle="k8s-pod-network.8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" host="ip-172-31-16-165" Jul 21 12:39:08.446325 containerd[2389]: 2026-07-21 12:39:08.253 [INFO][5990] ipam/ipam.go 1438: Successfully claimed IPs: [192.168.27.132/26] block=192.168.27.128/26 handle="k8s-pod-network.8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" host="ip-172-31-16-165" Jul 21 12:39:08.448468 containerd[2389]: 2026-07-21 12:39:08.257 [INFO][5990] ipam/ipam.go 947: Auto-assigned 1 out of 1 IPv4s: [192.168.27.132/26] handle="k8s-pod-network.8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" host="ip-172-31-16-165" Jul 21 12:39:08.448468 containerd[2389]: 2026-07-21 12:39:08.258 [INFO][5990] ipam/ipam_plugin.go 547: Released host-wide IPAM lock. Jul 21 12:39:08.448468 containerd[2389]: 2026-07-21 12:39:08.258 [INFO][5990] ipam/ipam_plugin.go 403: Calico CNI IPAM assigned addresses IPv4=[192.168.27.132/26] IPv6=[] ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" HandleID="k8s-pod-network.8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Workload="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" Jul 21 12:39:08.448468 containerd[2389]: 2026-07-21 12:39:08.290 [INFO][5946] cni-plugin/k8s.go 422: Populated endpoint ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Namespace="calico-system" Pod="goldmane-6ccc4cdfd5-djlw8" WorkloadEndpoint="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0", GenerateName:"goldmane-6ccc4cdfd5-", Namespace:"calico-system", SelfLink:"", UID:"8b660833-58e5-4f31-ba07-2a53a00be574", ResourceVersion:"897", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 26, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"app.kubernetes.io/component":"Goldmane.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"goldmane", "app.kubernetes.io/part-of":"Calico", "k8s-app":"goldmane", "pod-template-hash":"6ccc4cdfd5", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"goldmane"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"", Pod:"goldmane-6ccc4cdfd5-djlw8", Endpoint:"eth0", ServiceAccountName:"goldmane", IPNetworks:[]string{"192.168.27.132/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.goldmane"}, InterfaceName:"cali9a39a32a0ed", MAC:"", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:08.448468 containerd[2389]: 2026-07-21 12:39:08.297 [INFO][5946] cni-plugin/k8s.go 423: Calico CNI using IPs: [192.168.27.132/32] ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Namespace="calico-system" Pod="goldmane-6ccc4cdfd5-djlw8" WorkloadEndpoint="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" Jul 21 12:39:08.448468 containerd[2389]: 2026-07-21 12:39:08.298 [INFO][5946] cni-plugin/dataplane_linux.go 77: Setting the host side veth name to cali9a39a32a0ed ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Namespace="calico-system" Pod="goldmane-6ccc4cdfd5-djlw8" WorkloadEndpoint="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" Jul 21 12:39:08.448468 containerd[2389]: 2026-07-21 12:39:08.323 [INFO][5946] cni-plugin/dataplane_linux.go 179: Read back correct host-side MAC. ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Namespace="calico-system" Pod="goldmane-6ccc4cdfd5-djlw8" WorkloadEndpoint="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" Jul 21 12:39:08.448468 containerd[2389]: 2026-07-21 12:39:08.371 [INFO][5946] cni-plugin/dataplane_linux.go 292: Adding IPv4 route (inside container) ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Namespace="calico-system" Pod="goldmane-6ccc4cdfd5-djlw8" WorkloadEndpoint="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" route=0.0.0.0/0 Jul 21 12:39:08.448468 containerd[2389]: 2026-07-21 12:39:08.374 [INFO][5946] cni-plugin/dataplane_linux.go 570: Disabling IPv4 forwarding ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Namespace="calico-system" Pod="goldmane-6ccc4cdfd5-djlw8" WorkloadEndpoint="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" Jul 21 12:39:08.449986 containerd[2389]: 2026-07-21 12:39:08.375 [INFO][5946] cni-plugin/k8s.go 458: Added Mac, interface name, and active container ID to endpoint ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Namespace="calico-system" Pod="goldmane-6ccc4cdfd5-djlw8" WorkloadEndpoint="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0", GenerateName:"goldmane-6ccc4cdfd5-", Namespace:"calico-system", SelfLink:"", UID:"8b660833-58e5-4f31-ba07-2a53a00be574", ResourceVersion:"897", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 26, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"app.kubernetes.io/component":"Goldmane.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"goldmane", "app.kubernetes.io/part-of":"Calico", "k8s-app":"goldmane", "pod-template-hash":"6ccc4cdfd5", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"goldmane"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043", Pod:"goldmane-6ccc4cdfd5-djlw8", Endpoint:"eth0", ServiceAccountName:"goldmane", IPNetworks:[]string{"192.168.27.132/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.goldmane"}, InterfaceName:"cali9a39a32a0ed", MAC:"66:0e:8d:ba:37:71", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:08.449986 containerd[2389]: 2026-07-21 12:39:08.424 [INFO][5946] cni-plugin/k8s.go 544: Wrote updated endpoint to datastore ContainerID="8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" Namespace="calico-system" Pod="goldmane-6ccc4cdfd5-djlw8" WorkloadEndpoint="ip--172--31--16--165-k8s-goldmane--6ccc4cdfd5--djlw8-eth0" Jul 21 12:39:08.496666 systemd-networkd[2075]: cali1ab6e5f751a: Link UP Jul 21 12:39:08.506584 systemd-networkd[2075]: cali1ab6e5f751a: Gained carrier Jul 21 12:39:08.590929 systemd[1]: Started cri-containerd-336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e.scope - libcontainer container 336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e. Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:07.563 [INFO][5961] cni-plugin/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:07.640 [INFO][5961] cni-plugin/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:07.641 [INFO][5961] cni-plugin/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:07.809 [INFO][5961] cni-plugin/plugin.go 343: Calico CNI found existing endpoint: &{{WorkloadEndpoint projectcalico.org/v3} {ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0 calico-apiserver-6b46596bdc- calico-system 9ad91eae-2d77-41fd-a210-1ddd3bf4e62a 895 0 2026-07-21 12:38:26 +0000 UTC map[apiserver:true app.kubernetes.io/component:APIServer.operator.tigera.io app.kubernetes.io/instance:default app.kubernetes.io/managed-by:tigera-operator app.kubernetes.io/name:calico-apiserver app.kubernetes.io/part-of:Calico k8s-app:calico-apiserver pod-template-hash:6b46596bdc projectcalico.org/namespace:calico-system projectcalico.org/orchestrator:k8s projectcalico.org/serviceaccount:calico-apiserver] map[] [] [] []} {k8s ip-172-31-16-165 calico-apiserver-6b46596bdc-djqpg eth0 calico-apiserver [] [] [kns.calico-system ksa.calico-system.calico-apiserver] cali1ab6e5f751a [] [] }} ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-djqpg" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:07.809 [INFO][5961] cni-plugin/k8s.go 76: Extracted identifiers for CmdAddK8s ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-djqpg" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.083 [INFO][5997] ipam/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.147 [INFO][5997] ipam/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.148 [INFO][5997] ipam/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.154 [INFO][5997] ipam/ipam_plugin.go 307: Calico CNI IPAM request count IPv4=1 IPv6=0 ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" HandleID="k8s-pod-network.fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Workload="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.206 [INFO][5997] ipam/ipam_plugin.go 379: Auto assigning IP ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" HandleID="k8s-pod-network.fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Workload="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" assignArgs=ipam.AutoAssignArgs{Num4:1, Num6:0, HandleID:(*string)(0x40003da200), Attrs:map[string]string{"namespace":"calico-system", "node":"ip-172-31-16-165", "pod":"calico-apiserver-6b46596bdc-djqpg", "timestamp":"2026-07-21 12:39:08.15455416 +0000 UTC"}, Hostname:"ip-172-31-16-165", IPv4Pools:[]net.IPNet{}, IPv6Pools:[]net.IPNet{}, MaxBlocksPerHost:0, HostReservedAttrIPv4s:(*ipam.HostReservedAttr)(nil), HostReservedAttrIPv6s:(*ipam.HostReservedAttr)(nil), IntendedUse:"Workload", MaxAllocToHandlePerIPVersion:0, Namespace:(*v1.Namespace)(0x400034a9a0)} Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.206 [INFO][5997] ipam/ipam_plugin.go 526: About to acquire host-wide IPAM lock. Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.258 [INFO][5997] ipam/ipam_plugin.go 541: Acquired host-wide IPAM lock. Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.258 [INFO][5997] ipam/ipam.go 118: Auto-assign 1 ipv4, 0 ipv6 addrs for host 'ip-172-31-16-165' Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.279 [INFO][5997] ipam/ipam.go 723: Looking up existing affinities for host handle="k8s-pod-network.fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" host="ip-172-31-16-165" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.309 [INFO][5997] ipam/ipam.go 415: Looking up existing affinities for host host="ip-172-31-16-165" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.363 [INFO][5997] ipam/ipam.go 531: Trying affinity for 192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.371 [INFO][5997] ipam/ipam.go 166: Attempting to load block cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.385 [INFO][5997] ipam/ipam.go 243: Affinity is confirmed and block has been loaded cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.385 [INFO][5997] ipam/ipam.go 1392: Attempting to assign 1 addresses from block block=192.168.27.128/26 handle="k8s-pod-network.fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" host="ip-172-31-16-165" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.394 [INFO][5997] ipam/ipam.go 1974: Creating new handle: k8s-pod-network.fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.415 [INFO][5997] ipam/ipam.go 1422: Writing block in order to claim IPs block=192.168.27.128/26 handle="k8s-pod-network.fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" host="ip-172-31-16-165" Jul 21 12:39:08.598183 containerd[2389]: 2026-07-21 12:39:08.442 [INFO][5997] ipam/ipam.go 1438: Successfully claimed IPs: [192.168.27.133/26] block=192.168.27.128/26 handle="k8s-pod-network.fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" host="ip-172-31-16-165" Jul 21 12:39:08.599412 containerd[2389]: 2026-07-21 12:39:08.443 [INFO][5997] ipam/ipam.go 947: Auto-assigned 1 out of 1 IPv4s: [192.168.27.133/26] handle="k8s-pod-network.fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" host="ip-172-31-16-165" Jul 21 12:39:08.599412 containerd[2389]: 2026-07-21 12:39:08.443 [INFO][5997] ipam/ipam_plugin.go 547: Released host-wide IPAM lock. Jul 21 12:39:08.599412 containerd[2389]: 2026-07-21 12:39:08.444 [INFO][5997] ipam/ipam_plugin.go 403: Calico CNI IPAM assigned addresses IPv4=[192.168.27.133/26] IPv6=[] ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" HandleID="k8s-pod-network.fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Workload="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" Jul 21 12:39:08.599412 containerd[2389]: 2026-07-21 12:39:08.469 [INFO][5961] cni-plugin/k8s.go 422: Populated endpoint ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-djqpg" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0", GenerateName:"calico-apiserver-6b46596bdc-", Namespace:"calico-system", SelfLink:"", UID:"9ad91eae-2d77-41fd-a210-1ddd3bf4e62a", ResourceVersion:"895", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 26, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"apiserver":"true", "app.kubernetes.io/component":"APIServer.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"calico-apiserver", "app.kubernetes.io/part-of":"Calico", "k8s-app":"calico-apiserver", "pod-template-hash":"6b46596bdc", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"calico-apiserver"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"", Pod:"calico-apiserver-6b46596bdc-djqpg", Endpoint:"eth0", ServiceAccountName:"calico-apiserver", IPNetworks:[]string{"192.168.27.133/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.calico-apiserver"}, InterfaceName:"cali1ab6e5f751a", MAC:"", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:08.599412 containerd[2389]: 2026-07-21 12:39:08.470 [INFO][5961] cni-plugin/k8s.go 423: Calico CNI using IPs: [192.168.27.133/32] ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-djqpg" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" Jul 21 12:39:08.599412 containerd[2389]: 2026-07-21 12:39:08.470 [INFO][5961] cni-plugin/dataplane_linux.go 77: Setting the host side veth name to cali1ab6e5f751a ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-djqpg" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" Jul 21 12:39:08.599412 containerd[2389]: 2026-07-21 12:39:08.492 [INFO][5961] cni-plugin/dataplane_linux.go 179: Read back correct host-side MAC. ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-djqpg" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" Jul 21 12:39:08.599412 containerd[2389]: 2026-07-21 12:39:08.510 [INFO][5961] cni-plugin/dataplane_linux.go 292: Adding IPv4 route (inside container) ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-djqpg" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" route=0.0.0.0/0 Jul 21 12:39:08.599412 containerd[2389]: 2026-07-21 12:39:08.510 [INFO][5961] cni-plugin/dataplane_linux.go 570: Disabling IPv4 forwarding ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-djqpg" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" Jul 21 12:39:08.601545 containerd[2389]: 2026-07-21 12:39:08.511 [INFO][5961] cni-plugin/k8s.go 458: Added Mac, interface name, and active container ID to endpoint ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-djqpg" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0", GenerateName:"calico-apiserver-6b46596bdc-", Namespace:"calico-system", SelfLink:"", UID:"9ad91eae-2d77-41fd-a210-1ddd3bf4e62a", ResourceVersion:"895", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 26, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"apiserver":"true", "app.kubernetes.io/component":"APIServer.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"calico-apiserver", "app.kubernetes.io/part-of":"Calico", "k8s-app":"calico-apiserver", "pod-template-hash":"6b46596bdc", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"calico-apiserver"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d", Pod:"calico-apiserver-6b46596bdc-djqpg", Endpoint:"eth0", ServiceAccountName:"calico-apiserver", IPNetworks:[]string{"192.168.27.133/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.calico-apiserver"}, InterfaceName:"cali1ab6e5f751a", MAC:"e6:81:27:6a:e4:0a", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:08.601545 containerd[2389]: 2026-07-21 12:39:08.559 [INFO][5961] cni-plugin/k8s.go 544: Wrote updated endpoint to datastore ContainerID="fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" Namespace="calico-system" Pod="calico-apiserver-6b46596bdc-djqpg" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--apiserver--6b46596bdc--djqpg-eth0" Jul 21 12:39:08.627444 containerd[2389]: time="2026-07-21T12:39:08.627387510Z" level=info msg="connecting to shim 8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043" address="unix:///run/containerd/s/7aa86f7ececf34cd74682f0598f58ef38f741902e4406124b68c4b87b97bf516" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:39:08.677000 audit: BPF prog-id=218 op=LOAD Jul 21 12:39:08.684242 kernel: audit: type=1334 audit(1784637548.677:829): prog-id=218 op=LOAD Jul 21 12:39:08.684000 audit: BPF prog-id=219 op=LOAD Jul 21 12:39:08.684000 audit[6057]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=7951a9135f90 a2=98 a3=0 items=0 ppid=6041 pid=6057 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.693764 kernel: audit: type=1334 audit(1784637548.684:830): prog-id=219 op=LOAD Jul 21 12:39:08.693828 kernel: audit: type=1300 audit(1784637548.684:830): arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=7951a9135f90 a2=98 a3=0 items=0 ppid=6041 pid=6057 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.684000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3333366362666333376162643766363338396565633032343732653132 Jul 21 12:39:08.710422 kernel: audit: type=1327 audit(1784637548.684:830): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3333366362666333376162643766363338396565633032343732653132 Jul 21 12:39:08.710530 sshd[6014]: Connection closed by authenticating user root 144.225.8.54 port 48490 [preauth] Jul 21 12:39:08.684000 audit: BPF prog-id=219 op=UNLOAD Jul 21 12:39:08.684000 audit[6057]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6041 pid=6057 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.684000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3333366362666333376162643766363338396565633032343732653132 Jul 21 12:39:08.684000 audit: BPF prog-id=220 op=LOAD Jul 21 12:39:08.684000 audit[6057]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=7951a9136268 a2=98 a3=0 items=0 ppid=6041 pid=6057 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.684000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3333366362666333376162643766363338396565633032343732653132 Jul 21 12:39:08.686000 audit: BPF prog-id=221 op=LOAD Jul 21 12:39:08.686000 audit[6057]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=7951a9135fa8 a2=98 a3=0 items=0 ppid=6041 pid=6057 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.686000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3333366362666333376162643766363338396565633032343732653132 Jul 21 12:39:08.709000 audit: BPF prog-id=221 op=UNLOAD Jul 21 12:39:08.709000 audit[6057]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=6041 pid=6057 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.709000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3333366362666333376162643766363338396565633032343732653132 Jul 21 12:39:08.709000 audit[6014]: AUDIT1109 pid=6014 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:08.711000 audit: BPF prog-id=220 op=UNLOAD Jul 21 12:39:08.711000 audit[6057]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6041 pid=6057 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.711000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3333366362666333376162643766363338396565633032343732653132 Jul 21 12:39:08.727114 systemd[1]: sshd@69-25-172.31.16.165:22-144.225.8.54:48490.service: Deactivated successfully. Jul 21 12:39:08.727000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@69-25-172.31.16.165:22-144.225.8.54:48490 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:08.735000 audit: BPF prog-id=222 op=LOAD Jul 21 12:39:08.735000 audit[6057]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=7951a91364b8 a2=98 a3=0 items=0 ppid=6041 pid=6057 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.735000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3333366362666333376162643766363338396565633032343732653132 Jul 21 12:39:08.790752 containerd[2389]: time="2026-07-21T12:39:08.790699855Z" level=info msg="connecting to shim fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d" address="unix:///run/containerd/s/8945df67554362404de5b5b1b5e00929c059c5df475077268516219eddafc2d9" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:39:08.804764 systemd[1]: Started cri-containerd-8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043.scope - libcontainer container 8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043. Jul 21 12:39:08.810529 systemd[1]: Started sshd@70-26-172.31.16.165:22-144.225.8.54:48500.service - OpenSSH per-connection server daemon (144.225.8.54:48500). Jul 21 12:39:08.810000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@70-26-172.31.16.165:22-144.225.8.54:48500 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:08.871000 audit[6168]: NETFILTER_CFG table=filter:117 family=2 entries=92 op=nft_register_chain pid=6168 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:08.871000 audit[6168]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=52604 a0=3 a1=ffffecb8c9e0 a2=0 a3=ffff96e017e0 items=0 ppid=5430 pid=6168 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.871000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:08.879000 audit: BPF prog-id=223 op=LOAD Jul 21 12:39:08.880000 audit: BPF prog-id=224 op=LOAD Jul 21 12:39:08.880000 audit[6116]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=41569ea4bf90 a2=98 a3=0 items=0 ppid=6101 pid=6116 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.880000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3838373363333239346639396534363736643962643936613139343464 Jul 21 12:39:08.881000 audit: BPF prog-id=224 op=UNLOAD Jul 21 12:39:08.881000 audit[6116]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6101 pid=6116 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.881000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3838373363333239346639396534363736643962643936613139343464 Jul 21 12:39:08.886000 audit: BPF prog-id=225 op=LOAD Jul 21 12:39:08.886000 audit[6116]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=41569ea4c268 a2=98 a3=0 items=0 ppid=6101 pid=6116 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.886000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3838373363333239346639396534363736643962643936613139343464 Jul 21 12:39:08.888000 audit: BPF prog-id=226 op=LOAD Jul 21 12:39:08.888000 audit[6116]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=41569ea4bfa8 a2=98 a3=0 items=0 ppid=6101 pid=6116 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.888000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3838373363333239346639396534363736643962643936613139343464 Jul 21 12:39:08.894000 audit: BPF prog-id=226 op=UNLOAD Jul 21 12:39:08.894000 audit[6116]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=6101 pid=6116 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.894000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3838373363333239346639396534363736643962643936613139343464 Jul 21 12:39:08.897000 audit: BPF prog-id=225 op=UNLOAD Jul 21 12:39:08.897000 audit[6116]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6101 pid=6116 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.897000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3838373363333239346639396534363736643962643936613139343464 Jul 21 12:39:08.896000 audit[6170]: NETFILTER_CFG table=calico-arp:118 family=3 entries=9 op=nft_register_chain pid=6170 subj=system_u:system_r:kernel_t:s0 comm="nft" Jul 21 12:39:08.896000 audit[6170]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=2116 a0=3 a1=ffffd6c7a2e8 a2=0 a3=ffffb7dc7020 items=0 ppid=5430 pid=6170 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="nft" exe="/usr/sbin/nft" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.896000 audit: PROCTITLE proctitle=2F7573722F7362696E2F6E6674002D66002D Jul 21 12:39:08.897000 audit: BPF prog-id=227 op=LOAD Jul 21 12:39:08.897000 audit[6116]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=41569ea4c4b8 a2=98 a3=0 items=0 ppid=6101 pid=6116 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:08.897000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3838373363333239346639396534363736643962643936613139343464 Jul 21 12:39:08.972314 containerd[2389]: time="2026-07-21T12:39:08.972154160Z" level=info msg="RunPodSandbox for name:\"csi-node-driver-4np6n\" uid:\"e8df5361-881a-429a-bf39-9bdb2f450187\" namespace:\"calico-system\" returns sandbox id \"336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e\"" Jul 21 12:39:09.014741 systemd[1]: Started cri-containerd-fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d.scope - libcontainer container fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d. Jul 21 12:39:09.063223 containerd[2389]: time="2026-07-21T12:39:09.063134801Z" level=info msg="RunPodSandbox for name:\"goldmane-6ccc4cdfd5-djlw8\" uid:\"8b660833-58e5-4f31-ba07-2a53a00be574\" namespace:\"calico-system\" returns sandbox id \"8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043\"" Jul 21 12:39:09.116000 audit: BPF prog-id=228 op=LOAD Jul 21 12:39:09.117000 audit: BPF prog-id=229 op=LOAD Jul 21 12:39:09.117000 audit[6181]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=3229a4a9f90 a2=98 a3=0 items=0 ppid=6144 pid=6181 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:09.117000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6661343232616532386131623762663463646433306138626162386262 Jul 21 12:39:09.117000 audit: BPF prog-id=229 op=UNLOAD Jul 21 12:39:09.117000 audit[6181]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6144 pid=6181 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:09.117000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6661343232616532386131623762663463646433306138626162386262 Jul 21 12:39:09.117000 audit: BPF prog-id=230 op=LOAD Jul 21 12:39:09.117000 audit[6181]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=3229a4aa268 a2=98 a3=0 items=0 ppid=6144 pid=6181 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:09.117000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6661343232616532386131623762663463646433306138626162386262 Jul 21 12:39:09.118000 audit: BPF prog-id=231 op=LOAD Jul 21 12:39:09.118000 audit[6181]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=3229a4a9fa8 a2=98 a3=0 items=0 ppid=6144 pid=6181 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:09.118000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6661343232616532386131623762663463646433306138626162386262 Jul 21 12:39:09.118000 audit: BPF prog-id=231 op=UNLOAD Jul 21 12:39:09.118000 audit[6181]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=6144 pid=6181 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:09.118000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6661343232616532386131623762663463646433306138626162386262 Jul 21 12:39:09.118000 audit: BPF prog-id=230 op=UNLOAD Jul 21 12:39:09.118000 audit[6181]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6144 pid=6181 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:09.118000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6661343232616532386131623762663463646433306138626162386262 Jul 21 12:39:09.118000 audit: BPF prog-id=232 op=LOAD Jul 21 12:39:09.118000 audit[6181]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=3229a4aa4b8 a2=98 a3=0 items=0 ppid=6144 pid=6181 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:09.118000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6661343232616532386131623762663463646433306138626162386262 Jul 21 12:39:09.201514 containerd[2389]: time="2026-07-21T12:39:09.201429605Z" level=info msg="RunPodSandbox for name:\"calico-apiserver-6b46596bdc-djqpg\" uid:\"9ad91eae-2d77-41fd-a210-1ddd3bf4e62a\" namespace:\"calico-system\" returns sandbox id \"fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d\"" Jul 21 12:39:09.227975 sshd[6147]: Connection closed by authenticating user root 144.225.8.54 port 48500 [preauth] Jul 21 12:39:09.228000 audit[6147]: AUDIT1109 pid=6147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:09.232541 systemd[1]: sshd@70-26-172.31.16.165:22-144.225.8.54:48500.service: Deactivated successfully. Jul 21 12:39:09.232000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@70-26-172.31.16.165:22-144.225.8.54:48500 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:09.303110 systemd[1]: Started sshd@71-27-172.31.16.165:22-144.225.8.54:48504.service - OpenSSH per-connection server daemon (144.225.8.54:48504). Jul 21 12:39:09.302000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@71-27-172.31.16.165:22-144.225.8.54:48504 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:09.355763 containerd[2389]: time="2026-07-21T12:39:09.355577850Z" level=info msg="RunPodSandbox for name:\"coredns-66bc5c9577-hjfjb\" uid:\"325210e6-833a-406c-b0cc-a5a598a42634\" namespace:\"kube-system\"" Jul 21 12:39:09.359937 containerd[2389]: time="2026-07-21T12:39:09.359850138Z" level=info msg="RunPodSandbox for name:\"coredns-66bc5c9577-6bgj5\" uid:\"115029ad-1967-4a5d-8486-f0f9b1d4dbb5\" namespace:\"kube-system\"" Jul 21 12:39:09.626533 sshd[6218]: Connection closed by authenticating user root 144.225.8.54 port 48504 [preauth] Jul 21 12:39:09.626000 audit[6218]: AUDIT1109 pid=6218 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:09.633118 systemd[1]: sshd@71-27-172.31.16.165:22-144.225.8.54:48504.service: Deactivated successfully. Jul 21 12:39:09.634000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@71-27-172.31.16.165:22-144.225.8.54:48504 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:09.645526 systemd-networkd[2075]: cali5f4e890389a: Gained IPv6LL Jul 21 12:39:09.709546 systemd-networkd[2075]: cali1ab6e5f751a: Gained IPv6LL Jul 21 12:39:09.711000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@72-4142-172.31.16.165:22-144.225.8.54:48510 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:09.712864 systemd[1]: Started sshd@72-4142-172.31.16.165:22-144.225.8.54:48510.service - OpenSSH per-connection server daemon (144.225.8.54:48510). Jul 21 12:39:09.860810 systemd-networkd[2075]: califee178f2956: Link UP Jul 21 12:39:09.873653 systemd-networkd[2075]: califee178f2956: Gained carrier Jul 21 12:39:09.966112 systemd-networkd[2075]: cali9a39a32a0ed: Gained IPv6LL Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.455 [INFO][6221] cni-plugin/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.498 [INFO][6221] cni-plugin/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.499 [INFO][6221] cni-plugin/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.513 [INFO][6221] cni-plugin/plugin.go 343: Calico CNI found existing endpoint: &{{WorkloadEndpoint projectcalico.org/v3} {ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0 coredns-66bc5c9577- kube-system 325210e6-833a-406c-b0cc-a5a598a42634 890 0 2026-07-21 12:38:07 +0000 UTC map[k8s-app:kube-dns pod-template-hash:66bc5c9577 projectcalico.org/namespace:kube-system projectcalico.org/orchestrator:k8s projectcalico.org/serviceaccount:coredns] map[] [] [] []} {k8s ip-172-31-16-165 coredns-66bc5c9577-hjfjb eth0 coredns [] [] [kns.kube-system ksa.kube-system.coredns] califee178f2956 [{dns UDP 53 0 } {dns-tcp TCP 53 0 } {metrics TCP 9153 0 } {liveness-probe TCP 8080 0 } {readiness-probe TCP 8181 0 }] [] }} ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Namespace="kube-system" Pod="coredns-66bc5c9577-hjfjb" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.513 [INFO][6221] cni-plugin/k8s.go 76: Extracted identifiers for CmdAddK8s ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Namespace="kube-system" Pod="coredns-66bc5c9577-hjfjb" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.590 [INFO][6244] ipam/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.658 [INFO][6244] ipam/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.658 [INFO][6244] ipam/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.661 [INFO][6244] ipam/ipam_plugin.go 307: Calico CNI IPAM request count IPv4=1 IPv6=0 ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" HandleID="k8s-pod-network.f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Workload="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.669 [INFO][6244] ipam/ipam_plugin.go 379: Auto assigning IP ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" HandleID="k8s-pod-network.f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Workload="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" assignArgs=ipam.AutoAssignArgs{Num4:1, Num6:0, HandleID:(*string)(0x4000720750), Attrs:map[string]string{"namespace":"kube-system", "node":"ip-172-31-16-165", "pod":"coredns-66bc5c9577-hjfjb", "timestamp":"2026-07-21 12:39:09.66136856 +0000 UTC"}, Hostname:"ip-172-31-16-165", IPv4Pools:[]net.IPNet{}, IPv6Pools:[]net.IPNet{}, MaxBlocksPerHost:0, HostReservedAttrIPv4s:(*ipam.HostReservedAttr)(nil), HostReservedAttrIPv6s:(*ipam.HostReservedAttr)(nil), IntendedUse:"Workload", MaxAllocToHandlePerIPVersion:0, Namespace:(*v1.Namespace)(0x4000702b00)} Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.669 [INFO][6244] ipam/ipam_plugin.go 526: About to acquire host-wide IPAM lock. Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.669 [INFO][6244] ipam/ipam_plugin.go 541: Acquired host-wide IPAM lock. Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.669 [INFO][6244] ipam/ipam.go 118: Auto-assign 1 ipv4, 0 ipv6 addrs for host 'ip-172-31-16-165' Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.678 [INFO][6244] ipam/ipam.go 723: Looking up existing affinities for host handle="k8s-pod-network.f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" host="ip-172-31-16-165" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.724 [INFO][6244] ipam/ipam.go 415: Looking up existing affinities for host host="ip-172-31-16-165" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.745 [INFO][6244] ipam/ipam.go 531: Trying affinity for 192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.755 [INFO][6244] ipam/ipam.go 166: Attempting to load block cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.766 [INFO][6244] ipam/ipam.go 243: Affinity is confirmed and block has been loaded cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.767 [INFO][6244] ipam/ipam.go 1392: Attempting to assign 1 addresses from block block=192.168.27.128/26 handle="k8s-pod-network.f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" host="ip-172-31-16-165" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.779 [INFO][6244] ipam/ipam.go 1974: Creating new handle: k8s-pod-network.f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5 Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.797 [INFO][6244] ipam/ipam.go 1422: Writing block in order to claim IPs block=192.168.27.128/26 handle="k8s-pod-network.f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" host="ip-172-31-16-165" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.828 [INFO][6244] ipam/ipam.go 1438: Successfully claimed IPs: [192.168.27.134/26] block=192.168.27.128/26 handle="k8s-pod-network.f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" host="ip-172-31-16-165" Jul 21 12:39:09.990544 containerd[2389]: 2026-07-21 12:39:09.830 [INFO][6244] ipam/ipam.go 947: Auto-assigned 1 out of 1 IPv4s: [192.168.27.134/26] handle="k8s-pod-network.f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" host="ip-172-31-16-165" Jul 21 12:39:09.996700 containerd[2389]: 2026-07-21 12:39:09.832 [INFO][6244] ipam/ipam_plugin.go 547: Released host-wide IPAM lock. Jul 21 12:39:09.996700 containerd[2389]: 2026-07-21 12:39:09.834 [INFO][6244] ipam/ipam_plugin.go 403: Calico CNI IPAM assigned addresses IPv4=[192.168.27.134/26] IPv6=[] ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" HandleID="k8s-pod-network.f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Workload="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" Jul 21 12:39:09.996700 containerd[2389]: 2026-07-21 12:39:09.849 [INFO][6221] cni-plugin/k8s.go 422: Populated endpoint ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Namespace="kube-system" Pod="coredns-66bc5c9577-hjfjb" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0", GenerateName:"coredns-66bc5c9577-", Namespace:"kube-system", SelfLink:"", UID:"325210e6-833a-406c-b0cc-a5a598a42634", ResourceVersion:"890", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 7, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"k8s-app":"kube-dns", "pod-template-hash":"66bc5c9577", "projectcalico.org/namespace":"kube-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"coredns"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"", Pod:"coredns-66bc5c9577-hjfjb", Endpoint:"eth0", ServiceAccountName:"coredns", IPNetworks:[]string{"192.168.27.134/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.kube-system", "ksa.kube-system.coredns"}, InterfaceName:"califee178f2956", MAC:"", Ports:[]internalapi.WorkloadEndpointPort{internalapi.WorkloadEndpointPort{Name:"dns", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"UDP"}, Port:0x35, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"dns-tcp", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x35, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"metrics", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x23c1, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"liveness-probe", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x1f90, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"readiness-probe", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x1ff5, HostPort:0x0, HostIP:""}}, AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:09.996700 containerd[2389]: 2026-07-21 12:39:09.850 [INFO][6221] cni-plugin/k8s.go 423: Calico CNI using IPs: [192.168.27.134/32] ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Namespace="kube-system" Pod="coredns-66bc5c9577-hjfjb" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" Jul 21 12:39:09.996700 containerd[2389]: 2026-07-21 12:39:09.850 [INFO][6221] cni-plugin/dataplane_linux.go 77: Setting the host side veth name to califee178f2956 ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Namespace="kube-system" Pod="coredns-66bc5c9577-hjfjb" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" Jul 21 12:39:09.996700 containerd[2389]: 2026-07-21 12:39:09.857 [INFO][6221] cni-plugin/dataplane_linux.go 179: Read back correct host-side MAC. ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Namespace="kube-system" Pod="coredns-66bc5c9577-hjfjb" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" Jul 21 12:39:09.996700 containerd[2389]: 2026-07-21 12:39:09.873 [INFO][6221] cni-plugin/dataplane_linux.go 292: Adding IPv4 route (inside container) ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Namespace="kube-system" Pod="coredns-66bc5c9577-hjfjb" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" route=0.0.0.0/0 Jul 21 12:39:09.996700 containerd[2389]: 2026-07-21 12:39:09.875 [INFO][6221] cni-plugin/dataplane_linux.go 570: Disabling IPv4 forwarding ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Namespace="kube-system" Pod="coredns-66bc5c9577-hjfjb" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" Jul 21 12:39:09.998724 containerd[2389]: 2026-07-21 12:39:09.881 [INFO][6221] cni-plugin/k8s.go 458: Added Mac, interface name, and active container ID to endpoint ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Namespace="kube-system" Pod="coredns-66bc5c9577-hjfjb" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0", GenerateName:"coredns-66bc5c9577-", Namespace:"kube-system", SelfLink:"", UID:"325210e6-833a-406c-b0cc-a5a598a42634", ResourceVersion:"890", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 7, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"k8s-app":"kube-dns", "pod-template-hash":"66bc5c9577", "projectcalico.org/namespace":"kube-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"coredns"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5", Pod:"coredns-66bc5c9577-hjfjb", Endpoint:"eth0", ServiceAccountName:"coredns", IPNetworks:[]string{"192.168.27.134/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.kube-system", "ksa.kube-system.coredns"}, InterfaceName:"califee178f2956", MAC:"56:79:3b:7f:2f:22", Ports:[]internalapi.WorkloadEndpointPort{internalapi.WorkloadEndpointPort{Name:"dns", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"UDP"}, Port:0x35, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"dns-tcp", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x35, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"metrics", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x23c1, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"liveness-probe", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x1f90, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"readiness-probe", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x1ff5, HostPort:0x0, HostIP:""}}, AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:09.998724 containerd[2389]: 2026-07-21 12:39:09.964 [INFO][6221] cni-plugin/k8s.go 544: Wrote updated endpoint to datastore ContainerID="f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" Namespace="kube-system" Pod="coredns-66bc5c9577-hjfjb" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--hjfjb-eth0" Jul 21 12:39:10.131058 sshd[6262]: Connection closed by authenticating user root 144.225.8.54 port 48510 [preauth] Jul 21 12:39:10.134000 audit[6262]: AUDIT1109 pid=6262 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:10.142729 systemd[1]: sshd@72-4142-172.31.16.165:22-144.225.8.54:48510.service: Deactivated successfully. Jul 21 12:39:10.143000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@72-4142-172.31.16.165:22-144.225.8.54:48510 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:10.160237 containerd[2389]: time="2026-07-21T12:39:10.158608350Z" level=info msg="connecting to shim f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5" address="unix:///run/containerd/s/5eadd8f071e0a6fc7e4f86676fb7f4a9de76b66984224595143a0cd06b024728" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:39:10.227736 systemd-networkd[2075]: calib7ce1f5fb11: Link UP Jul 21 12:39:10.230999 systemd[1]: Started sshd@73-4143-172.31.16.165:22-144.225.8.54:48520.service - OpenSSH per-connection server daemon (144.225.8.54:48520). Jul 21 12:39:10.230000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@73-4143-172.31.16.165:22-144.225.8.54:48520 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:10.238658 systemd-networkd[2075]: calib7ce1f5fb11: Gained carrier Jul 21 12:39:10.247000 audit[6319]: NETFILTER_CFG table=filter:119 family=2 entries=64 op=nft_register_chain pid=6319 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:10.247000 audit[6319]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=30188 a0=3 a1=ffffef93ad30 a2=0 a3=ffffb15777e0 items=0 ppid=5430 pid=6319 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.247000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:10.279000 audit[6325]: NETFILTER_CFG table=calico-arp:120 family=3 entries=3 op=nft_register_chain pid=6325 subj=system_u:system_r:kernel_t:s0 comm="nft" Jul 21 12:39:10.279000 audit[6325]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=732 a0=3 a1=ffffe4ceefa8 a2=0 a3=ffff81d19020 items=0 ppid=5430 pid=6325 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="nft" exe="/usr/sbin/nft" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.279000 audit: PROCTITLE proctitle=2F7573722F7362696E2F6E6674002D66002D Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:09.520 [INFO][6222] cni-plugin/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:09.551 [INFO][6222] cni-plugin/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:09.551 [INFO][6222] cni-plugin/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:09.593 [INFO][6222] cni-plugin/plugin.go 343: Calico CNI found existing endpoint: &{{WorkloadEndpoint projectcalico.org/v3} {ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0 coredns-66bc5c9577- kube-system 115029ad-1967-4a5d-8486-f0f9b1d4dbb5 893 0 2026-07-21 12:38:07 +0000 UTC map[k8s-app:kube-dns pod-template-hash:66bc5c9577 projectcalico.org/namespace:kube-system projectcalico.org/orchestrator:k8s projectcalico.org/serviceaccount:coredns] map[] [] [] []} {k8s ip-172-31-16-165 coredns-66bc5c9577-6bgj5 eth0 coredns [] [] [kns.kube-system ksa.kube-system.coredns] calib7ce1f5fb11 [{dns UDP 53 0 } {dns-tcp TCP 53 0 } {metrics TCP 9153 0 } {liveness-probe TCP 8080 0 } {readiness-probe TCP 8181 0 }] [] }} ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Namespace="kube-system" Pod="coredns-66bc5c9577-6bgj5" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:09.593 [INFO][6222] cni-plugin/k8s.go 76: Extracted identifiers for CmdAddK8s ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Namespace="kube-system" Pod="coredns-66bc5c9577-6bgj5" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:09.866 [INFO][6251] ipam/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:09.991 [INFO][6251] ipam/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:09.992 [INFO][6251] ipam/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.012 [INFO][6251] ipam/ipam_plugin.go 307: Calico CNI IPAM request count IPv4=1 IPv6=0 ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" HandleID="k8s-pod-network.dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Workload="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.022 [INFO][6251] ipam/ipam_plugin.go 379: Auto assigning IP ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" HandleID="k8s-pod-network.dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Workload="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" assignArgs=ipam.AutoAssignArgs{Num4:1, Num6:0, HandleID:(*string)(0x400043afb0), Attrs:map[string]string{"namespace":"kube-system", "node":"ip-172-31-16-165", "pod":"coredns-66bc5c9577-6bgj5", "timestamp":"2026-07-21 12:39:10.012120053 +0000 UTC"}, Hostname:"ip-172-31-16-165", IPv4Pools:[]net.IPNet{}, IPv6Pools:[]net.IPNet{}, MaxBlocksPerHost:0, HostReservedAttrIPv4s:(*ipam.HostReservedAttr)(nil), HostReservedAttrIPv6s:(*ipam.HostReservedAttr)(nil), IntendedUse:"Workload", MaxAllocToHandlePerIPVersion:0, Namespace:(*v1.Namespace)(0x4000194b00)} Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.022 [INFO][6251] ipam/ipam_plugin.go 526: About to acquire host-wide IPAM lock. Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.023 [INFO][6251] ipam/ipam_plugin.go 541: Acquired host-wide IPAM lock. Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.024 [INFO][6251] ipam/ipam.go 118: Auto-assign 1 ipv4, 0 ipv6 addrs for host 'ip-172-31-16-165' Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.029 [INFO][6251] ipam/ipam.go 723: Looking up existing affinities for host handle="k8s-pod-network.dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" host="ip-172-31-16-165" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.046 [INFO][6251] ipam/ipam.go 415: Looking up existing affinities for host host="ip-172-31-16-165" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.072 [INFO][6251] ipam/ipam.go 531: Trying affinity for 192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.098 [INFO][6251] ipam/ipam.go 166: Attempting to load block cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.125 [INFO][6251] ipam/ipam.go 243: Affinity is confirmed and block has been loaded cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.125 [INFO][6251] ipam/ipam.go 1392: Attempting to assign 1 addresses from block block=192.168.27.128/26 handle="k8s-pod-network.dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" host="ip-172-31-16-165" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.134 [INFO][6251] ipam/ipam.go 1974: Creating new handle: k8s-pod-network.dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531 Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.154 [INFO][6251] ipam/ipam.go 1422: Writing block in order to claim IPs block=192.168.27.128/26 handle="k8s-pod-network.dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" host="ip-172-31-16-165" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.178 [INFO][6251] ipam/ipam.go 1438: Successfully claimed IPs: [192.168.27.135/26] block=192.168.27.128/26 handle="k8s-pod-network.dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" host="ip-172-31-16-165" Jul 21 12:39:10.329580 containerd[2389]: 2026-07-21 12:39:10.179 [INFO][6251] ipam/ipam.go 947: Auto-assigned 1 out of 1 IPv4s: [192.168.27.135/26] handle="k8s-pod-network.dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" host="ip-172-31-16-165" Jul 21 12:39:10.332135 containerd[2389]: 2026-07-21 12:39:10.179 [INFO][6251] ipam/ipam_plugin.go 547: Released host-wide IPAM lock. Jul 21 12:39:10.332135 containerd[2389]: 2026-07-21 12:39:10.179 [INFO][6251] ipam/ipam_plugin.go 403: Calico CNI IPAM assigned addresses IPv4=[192.168.27.135/26] IPv6=[] ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" HandleID="k8s-pod-network.dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Workload="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" Jul 21 12:39:10.332135 containerd[2389]: 2026-07-21 12:39:10.188 [INFO][6222] cni-plugin/k8s.go 422: Populated endpoint ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Namespace="kube-system" Pod="coredns-66bc5c9577-6bgj5" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0", GenerateName:"coredns-66bc5c9577-", Namespace:"kube-system", SelfLink:"", UID:"115029ad-1967-4a5d-8486-f0f9b1d4dbb5", ResourceVersion:"893", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 7, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"k8s-app":"kube-dns", "pod-template-hash":"66bc5c9577", "projectcalico.org/namespace":"kube-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"coredns"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"", Pod:"coredns-66bc5c9577-6bgj5", Endpoint:"eth0", ServiceAccountName:"coredns", IPNetworks:[]string{"192.168.27.135/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.kube-system", "ksa.kube-system.coredns"}, InterfaceName:"calib7ce1f5fb11", MAC:"", Ports:[]internalapi.WorkloadEndpointPort{internalapi.WorkloadEndpointPort{Name:"dns", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"UDP"}, Port:0x35, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"dns-tcp", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x35, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"metrics", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x23c1, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"liveness-probe", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x1f90, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"readiness-probe", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x1ff5, HostPort:0x0, HostIP:""}}, AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:10.332135 containerd[2389]: 2026-07-21 12:39:10.195 [INFO][6222] cni-plugin/k8s.go 423: Calico CNI using IPs: [192.168.27.135/32] ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Namespace="kube-system" Pod="coredns-66bc5c9577-6bgj5" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" Jul 21 12:39:10.332135 containerd[2389]: 2026-07-21 12:39:10.195 [INFO][6222] cni-plugin/dataplane_linux.go 77: Setting the host side veth name to calib7ce1f5fb11 ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Namespace="kube-system" Pod="coredns-66bc5c9577-6bgj5" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" Jul 21 12:39:10.332135 containerd[2389]: 2026-07-21 12:39:10.221 [INFO][6222] cni-plugin/dataplane_linux.go 179: Read back correct host-side MAC. ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Namespace="kube-system" Pod="coredns-66bc5c9577-6bgj5" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" Jul 21 12:39:10.332135 containerd[2389]: 2026-07-21 12:39:10.240 [INFO][6222] cni-plugin/dataplane_linux.go 292: Adding IPv4 route (inside container) ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Namespace="kube-system" Pod="coredns-66bc5c9577-6bgj5" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" route=0.0.0.0/0 Jul 21 12:39:10.332135 containerd[2389]: 2026-07-21 12:39:10.254 [INFO][6222] cni-plugin/dataplane_linux.go 570: Disabling IPv4 forwarding ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Namespace="kube-system" Pod="coredns-66bc5c9577-6bgj5" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" Jul 21 12:39:10.334810 containerd[2389]: 2026-07-21 12:39:10.256 [INFO][6222] cni-plugin/k8s.go 458: Added Mac, interface name, and active container ID to endpoint ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Namespace="kube-system" Pod="coredns-66bc5c9577-6bgj5" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0", GenerateName:"coredns-66bc5c9577-", Namespace:"kube-system", SelfLink:"", UID:"115029ad-1967-4a5d-8486-f0f9b1d4dbb5", ResourceVersion:"893", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 7, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"k8s-app":"kube-dns", "pod-template-hash":"66bc5c9577", "projectcalico.org/namespace":"kube-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"coredns"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531", Pod:"coredns-66bc5c9577-6bgj5", Endpoint:"eth0", ServiceAccountName:"coredns", IPNetworks:[]string{"192.168.27.135/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.kube-system", "ksa.kube-system.coredns"}, InterfaceName:"calib7ce1f5fb11", MAC:"6a:35:0d:a4:83:56", Ports:[]internalapi.WorkloadEndpointPort{internalapi.WorkloadEndpointPort{Name:"dns", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"UDP"}, Port:0x35, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"dns-tcp", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x35, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"metrics", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x23c1, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"liveness-probe", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x1f90, HostPort:0x0, HostIP:""}, internalapi.WorkloadEndpointPort{Name:"readiness-probe", Protocol:numorstring.Protocol{Type:1, NumVal:0x0, StrVal:"TCP"}, Port:0x1ff5, HostPort:0x0, HostIP:""}}, AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:10.334810 containerd[2389]: 2026-07-21 12:39:10.306 [INFO][6222] cni-plugin/k8s.go 544: Wrote updated endpoint to datastore ContainerID="dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" Namespace="kube-system" Pod="coredns-66bc5c9577-6bgj5" WorkloadEndpoint="ip--172--31--16--165-k8s-coredns--66bc5c9577--6bgj5-eth0" Jul 21 12:39:10.361085 containerd[2389]: time="2026-07-21T12:39:10.360566515Z" level=info msg="RunPodSandbox for name:\"calico-kube-controllers-cbf695f-b4zcr\" uid:\"0f387b73-51f8-48e1-9153-5bdf9a5d18b4\" namespace:\"calico-system\"" Jul 21 12:39:10.429601 systemd[1]: Started cri-containerd-f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5.scope - libcontainer container f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5. Jul 21 12:39:10.458000 audit[6354]: NETFILTER_CFG table=filter:121 family=2 entries=48 op=nft_register_chain pid=6354 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:10.458000 audit[6354]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=22736 a0=3 a1=fffff77fb020 a2=0 a3=ffff9d0157e0 items=0 ppid=5430 pid=6354 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.458000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:10.505000 audit: BPF prog-id=233 op=LOAD Jul 21 12:39:10.506000 audit[6376]: NETFILTER_CFG table=calico-arp:122 family=3 entries=3 op=nft_register_chain pid=6376 subj=system_u:system_r:kernel_t:s0 comm="nft" Jul 21 12:39:10.506000 audit[6376]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=732 a0=3 a1=ffffe7a48c18 a2=0 a3=ffffa03b3020 items=0 ppid=5430 pid=6376 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="nft" exe="/usr/sbin/nft" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.506000 audit: PROCTITLE proctitle=2F7573722F7362696E2F6E6674002D66002D Jul 21 12:39:10.511000 audit: BPF prog-id=234 op=LOAD Jul 21 12:39:10.511000 audit[6320]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=39b6c82b1f90 a2=98 a3=0 items=0 ppid=6304 pid=6320 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.511000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6637306166363031373936326336643664396263333230383461643662 Jul 21 12:39:10.512000 audit: BPF prog-id=234 op=UNLOAD Jul 21 12:39:10.512000 audit[6320]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6304 pid=6320 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.512000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6637306166363031373936326336643664396263333230383461643662 Jul 21 12:39:10.512000 audit: BPF prog-id=235 op=LOAD Jul 21 12:39:10.512000 audit[6320]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=39b6c82b2268 a2=98 a3=0 items=0 ppid=6304 pid=6320 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.512000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6637306166363031373936326336643664396263333230383461643662 Jul 21 12:39:10.512000 audit: BPF prog-id=236 op=LOAD Jul 21 12:39:10.512000 audit[6320]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=39b6c82b1fa8 a2=98 a3=0 items=0 ppid=6304 pid=6320 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.512000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6637306166363031373936326336643664396263333230383461643662 Jul 21 12:39:10.514000 audit: BPF prog-id=236 op=UNLOAD Jul 21 12:39:10.514000 audit[6320]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=6304 pid=6320 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.514000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6637306166363031373936326336643664396263333230383461643662 Jul 21 12:39:10.514000 audit: BPF prog-id=235 op=UNLOAD Jul 21 12:39:10.514000 audit[6320]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6304 pid=6320 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.514000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6637306166363031373936326336643664396263333230383461643662 Jul 21 12:39:10.517180 containerd[2389]: time="2026-07-21T12:39:10.517129064Z" level=info msg="connecting to shim dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531" address="unix:///run/containerd/s/d0af374a8db74913f86effa4930c58949916db079708ea989a561fc3ed472467" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:39:10.514000 audit: BPF prog-id=237 op=LOAD Jul 21 12:39:10.514000 audit[6320]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=39b6c82b24b8 a2=98 a3=0 items=0 ppid=6304 pid=6320 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.514000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6637306166363031373936326336643664396263333230383461643662 Jul 21 12:39:10.614630 sshd[6322]: Connection closed by authenticating user root 144.225.8.54 port 48520 [preauth] Jul 21 12:39:10.614000 audit[6322]: AUDIT1109 pid=6322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:10.621066 systemd[1]: sshd@73-4143-172.31.16.165:22-144.225.8.54:48520.service: Deactivated successfully. Jul 21 12:39:10.624000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@73-4143-172.31.16.165:22-144.225.8.54:48520 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:10.698000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@74-4144-172.31.16.165:22-144.225.8.54:48536 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:10.699440 systemd[1]: Started sshd@74-4144-172.31.16.165:22-144.225.8.54:48536.service - OpenSSH per-connection server daemon (144.225.8.54:48536). Jul 21 12:39:10.743355 containerd[2389]: time="2026-07-21T12:39:10.743252553Z" level=info msg="RunPodSandbox for name:\"coredns-66bc5c9577-hjfjb\" uid:\"325210e6-833a-406c-b0cc-a5a598a42634\" namespace:\"kube-system\" returns sandbox id \"f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5\"" Jul 21 12:39:10.759614 systemd[1]: Started cri-containerd-dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531.scope - libcontainer container dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531. Jul 21 12:39:10.772428 containerd[2389]: time="2026-07-21T12:39:10.771251949Z" level=info msg="CreateContainer within sandbox \"f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5\" for container name:\"coredns\"" Jul 21 12:39:10.834821 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount3306949700.mount: Deactivated successfully. Jul 21 12:39:10.846930 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount2812368816.mount: Deactivated successfully. Jul 21 12:39:10.879000 audit: BPF prog-id=238 op=LOAD Jul 21 12:39:10.882000 audit: BPF prog-id=239 op=LOAD Jul 21 12:39:10.882000 audit[6396]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=160c02515f90 a2=98 a3=0 items=0 ppid=6378 pid=6396 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.882000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6466653263303137663731646564663032656366666133326366643630 Jul 21 12:39:10.882000 audit: BPF prog-id=239 op=UNLOAD Jul 21 12:39:10.882000 audit[6396]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6378 pid=6396 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.882000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6466653263303137663731646564663032656366666133326366643630 Jul 21 12:39:10.884000 audit: BPF prog-id=240 op=LOAD Jul 21 12:39:10.884000 audit[6396]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=160c02516268 a2=98 a3=0 items=0 ppid=6378 pid=6396 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.884000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6466653263303137663731646564663032656366666133326366643630 Jul 21 12:39:10.888000 audit: BPF prog-id=241 op=LOAD Jul 21 12:39:10.888000 audit[6396]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=23 a0=5 a1=160c02515fa8 a2=98 a3=0 items=0 ppid=6378 pid=6396 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.888000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6466653263303137663731646564663032656366666133326366643630 Jul 21 12:39:10.891000 audit: BPF prog-id=241 op=UNLOAD Jul 21 12:39:10.891000 audit[6396]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=6378 pid=6396 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.891000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6466653263303137663731646564663032656366666133326366643630 Jul 21 12:39:10.892000 audit: BPF prog-id=240 op=UNLOAD Jul 21 12:39:10.892000 audit[6396]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6378 pid=6396 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.892000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6466653263303137663731646564663032656366666133326366643630 Jul 21 12:39:10.892000 audit: BPF prog-id=242 op=LOAD Jul 21 12:39:10.892000 audit[6396]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=160c025164b8 a2=98 a3=0 items=0 ppid=6378 pid=6396 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:10.892000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6466653263303137663731646564663032656366666133326366643630 Jul 21 12:39:10.924229 containerd[2389]: time="2026-07-21T12:39:10.921972382Z" level=info msg="CreateContainer within sandbox \"f70af6017962c6d6d9bc32084ad6b2630e90842d055baee320e5daf0a28998f5\" for name:\"coredns\" returns container id \"6b3ff45b07bcce706ac4cd01f0c5fe7d51e0b400c687c6efd487b4f146286ffc\"" Jul 21 12:39:10.942451 containerd[2389]: time="2026-07-21T12:39:10.942174622Z" level=info msg="StartContainer for \"6b3ff45b07bcce706ac4cd01f0c5fe7d51e0b400c687c6efd487b4f146286ffc\"" Jul 21 12:39:10.950795 containerd[2389]: time="2026-07-21T12:39:10.950725978Z" level=info msg="connecting to shim 6b3ff45b07bcce706ac4cd01f0c5fe7d51e0b400c687c6efd487b4f146286ffc" address="unix:///run/containerd/s/5eadd8f071e0a6fc7e4f86676fb7f4a9de76b66984224595143a0cd06b024728" protocol=ttrpc version=3 Jul 21 12:39:11.070885 containerd[2389]: time="2026-07-21T12:39:11.070702027Z" level=info msg="RunPodSandbox for name:\"coredns-66bc5c9577-6bgj5\" uid:\"115029ad-1967-4a5d-8486-f0f9b1d4dbb5\" namespace:\"kube-system\" returns sandbox id \"dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531\"" Jul 21 12:39:11.078244 systemd[1]: Started cri-containerd-6b3ff45b07bcce706ac4cd01f0c5fe7d51e0b400c687c6efd487b4f146286ffc.scope - libcontainer container 6b3ff45b07bcce706ac4cd01f0c5fe7d51e0b400c687c6efd487b4f146286ffc. Jul 21 12:39:11.115669 containerd[2389]: time="2026-07-21T12:39:11.115520755Z" level=info msg="CreateContainer within sandbox \"dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531\" for container name:\"coredns\"" Jul 21 12:39:11.122381 sshd[6416]: Connection closed by authenticating user root 144.225.8.54 port 48536 [preauth] Jul 21 12:39:11.124000 audit[6416]: AUDIT1109 pid=6416 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:11.131444 systemd[1]: sshd@74-4144-172.31.16.165:22-144.225.8.54:48536.service: Deactivated successfully. Jul 21 12:39:11.131000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@74-4144-172.31.16.165:22-144.225.8.54:48536 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:11.181580 systemd-networkd[2075]: califee178f2956: Gained IPv6LL Jul 21 12:39:11.189000 audit: BPF prog-id=243 op=LOAD Jul 21 12:39:11.193000 audit: BPF prog-id=244 op=LOAD Jul 21 12:39:11.196324 containerd[2389]: time="2026-07-21T12:39:11.195380803Z" level=info msg="CreateContainer within sandbox \"dfe2c017f71dedf02ecffa32cfd60264a1d6a314ac402b6459978685dbdbe531\" for name:\"coredns\" returns container id \"3ea98d872f14b7cb355a4a10c62232ff47b233ca96b697248e12754c4dd52d6e\"" Jul 21 12:39:11.193000 audit[6448]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=26cdef631f90 a2=98 a3=0 items=0 ppid=6304 pid=6448 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.193000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3662336666343562303762636365373036616334636430316630633566 Jul 21 12:39:11.198000 audit: BPF prog-id=244 op=UNLOAD Jul 21 12:39:11.203828 containerd[2389]: time="2026-07-21T12:39:11.201563743Z" level=info msg="StartContainer for \"3ea98d872f14b7cb355a4a10c62232ff47b233ca96b697248e12754c4dd52d6e\"" Jul 21 12:39:11.198000 audit[6448]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6304 pid=6448 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.198000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3662336666343562303762636365373036616334636430316630633566 Jul 21 12:39:11.204000 audit: BPF prog-id=245 op=LOAD Jul 21 12:39:11.204000 audit[6448]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=26cdef632268 a2=98 a3=0 items=0 ppid=6304 pid=6448 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.204000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3662336666343562303762636365373036616334636430316630633566 Jul 21 12:39:11.210976 containerd[2389]: time="2026-07-21T12:39:11.210761251Z" level=info msg="connecting to shim 3ea98d872f14b7cb355a4a10c62232ff47b233ca96b697248e12754c4dd52d6e" address="unix:///run/containerd/s/d0af374a8db74913f86effa4930c58949916db079708ea989a561fc3ed472467" protocol=ttrpc version=3 Jul 21 12:39:11.209000 audit: BPF prog-id=246 op=LOAD Jul 21 12:39:11.209000 audit[6448]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=26cdef631fa8 a2=98 a3=0 items=0 ppid=6304 pid=6448 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.216000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@75-28-172.31.16.165:22-144.225.8.54:48542 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:11.209000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3662336666343562303762636365373036616334636430316630633566 Jul 21 12:39:11.217143 systemd[1]: Started sshd@75-28-172.31.16.165:22-144.225.8.54:48542.service - OpenSSH per-connection server daemon (144.225.8.54:48542). Jul 21 12:39:11.219000 audit: BPF prog-id=246 op=UNLOAD Jul 21 12:39:11.219000 audit[6448]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=6304 pid=6448 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.219000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3662336666343562303762636365373036616334636430316630633566 Jul 21 12:39:11.220000 audit: BPF prog-id=245 op=UNLOAD Jul 21 12:39:11.220000 audit[6448]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6304 pid=6448 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.220000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3662336666343562303762636365373036616334636430316630633566 Jul 21 12:39:11.222000 audit: BPF prog-id=247 op=LOAD Jul 21 12:39:11.222000 audit[6448]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=26cdef6324b8 a2=98 a3=0 items=0 ppid=6304 pid=6448 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.222000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3662336666343562303762636365373036616334636430316630633566 Jul 21 12:39:11.364623 systemd[1]: Started cri-containerd-3ea98d872f14b7cb355a4a10c62232ff47b233ca96b697248e12754c4dd52d6e.scope - libcontainer container 3ea98d872f14b7cb355a4a10c62232ff47b233ca96b697248e12754c4dd52d6e. Jul 21 12:39:11.444605 systemd-networkd[2075]: calicf35013cec5: Link UP Jul 21 12:39:11.452756 systemd-networkd[2075]: calicf35013cec5: Gained carrier Jul 21 12:39:11.462868 containerd[2389]: time="2026-07-21T12:39:11.462365324Z" level=info msg="StartContainer for \"6b3ff45b07bcce706ac4cd01f0c5fe7d51e0b400c687c6efd487b4f146286ffc\" returns successfully" Jul 21 12:39:11.463000 audit: BPF prog-id=248 op=LOAD Jul 21 12:39:11.471000 audit: BPF prog-id=249 op=LOAD Jul 21 12:39:11.471000 audit[6486]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=346c93f31f90 a2=98 a3=0 items=0 ppid=6378 pid=6486 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.471000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3365613938643837326631346237636233353561346131306336323233 Jul 21 12:39:11.471000 audit: BPF prog-id=249 op=UNLOAD Jul 21 12:39:11.471000 audit[6486]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6378 pid=6486 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.471000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3365613938643837326631346237636233353561346131306336323233 Jul 21 12:39:11.474000 audit: BPF prog-id=250 op=LOAD Jul 21 12:39:11.474000 audit[6486]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=346c93f32268 a2=98 a3=0 items=0 ppid=6378 pid=6486 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.474000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3365613938643837326631346237636233353561346131306336323233 Jul 21 12:39:11.475000 audit: BPF prog-id=251 op=LOAD Jul 21 12:39:11.475000 audit[6486]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=346c93f31fa8 a2=98 a3=0 items=0 ppid=6378 pid=6486 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.475000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3365613938643837326631346237636233353561346131306336323233 Jul 21 12:39:11.476000 audit: BPF prog-id=251 op=UNLOAD Jul 21 12:39:11.476000 audit[6486]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=6378 pid=6486 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.476000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3365613938643837326631346237636233353561346131306336323233 Jul 21 12:39:11.477000 audit: BPF prog-id=250 op=UNLOAD Jul 21 12:39:11.477000 audit[6486]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6378 pid=6486 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.477000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3365613938643837326631346237636233353561346131306336323233 Jul 21 12:39:11.477000 audit: BPF prog-id=252 op=LOAD Jul 21 12:39:11.477000 audit[6486]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=346c93f324b8 a2=98 a3=0 items=0 ppid=6378 pid=6486 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:11.477000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3365613938643837326631346237636233353561346131306336323233 Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:10.631 [INFO][6347] cni-plugin/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:10.774 [INFO][6347] cni-plugin/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:10.774 [INFO][6347] cni-plugin/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:10.814 [INFO][6347] cni-plugin/plugin.go 343: Calico CNI found existing endpoint: &{{WorkloadEndpoint projectcalico.org/v3} {ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0 calico-kube-controllers-cbf695f- calico-system 0f387b73-51f8-48e1-9153-5bdf9a5d18b4 886 0 2026-07-21 12:38:30 +0000 UTC map[app.kubernetes.io/component:Installation.operator.tigera.io app.kubernetes.io/instance:default app.kubernetes.io/managed-by:tigera-operator app.kubernetes.io/name:calico-kube-controllers app.kubernetes.io/part-of:Calico k8s-app:calico-kube-controllers pod-template-hash:cbf695f projectcalico.org/namespace:calico-system projectcalico.org/orchestrator:k8s projectcalico.org/serviceaccount:calico-kube-controllers] map[] [] [] []} {k8s ip-172-31-16-165 calico-kube-controllers-cbf695f-b4zcr eth0 calico-kube-controllers [] [] [kns.calico-system ksa.calico-system.calico-kube-controllers] calicf35013cec5 [] [] }} ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Namespace="calico-system" Pod="calico-kube-controllers-cbf695f-b4zcr" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:10.814 [INFO][6347] cni-plugin/k8s.go 76: Extracted identifiers for CmdAddK8s ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Namespace="calico-system" Pod="calico-kube-controllers-cbf695f-b4zcr" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.127 [INFO][6438] ipam/discovery.go 46: No explicit Calico API group configured, attempting to auto-discover Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.179 [INFO][6438] ipam/discovery.go 74: Auto-discovered Calico API groups v1present=true v3present=true Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.179 [INFO][6438] ipam/client.go 85: Using API group for CRD backend apiGroup="crd.projectcalico.org/v1" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.187 [INFO][6438] ipam/ipam_plugin.go 307: Calico CNI IPAM request count IPv4=1 IPv6=0 ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" HandleID="k8s-pod-network.e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Workload="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.196 [INFO][6438] ipam/ipam_plugin.go 379: Auto assigning IP ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" HandleID="k8s-pod-network.e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Workload="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" assignArgs=ipam.AutoAssignArgs{Num4:1, Num6:0, HandleID:(*string)(0x40002e7680), Attrs:map[string]string{"namespace":"calico-system", "node":"ip-172-31-16-165", "pod":"calico-kube-controllers-cbf695f-b4zcr", "timestamp":"2026-07-21 12:39:11.187822339 +0000 UTC"}, Hostname:"ip-172-31-16-165", IPv4Pools:[]net.IPNet{}, IPv6Pools:[]net.IPNet{}, MaxBlocksPerHost:0, HostReservedAttrIPv4s:(*ipam.HostReservedAttr)(nil), HostReservedAttrIPv6s:(*ipam.HostReservedAttr)(nil), IntendedUse:"Workload", MaxAllocToHandlePerIPVersion:0, Namespace:(*v1.Namespace)(0x400059f080)} Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.196 [INFO][6438] ipam/ipam_plugin.go 526: About to acquire host-wide IPAM lock. Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.197 [INFO][6438] ipam/ipam_plugin.go 541: Acquired host-wide IPAM lock. Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.209 [INFO][6438] ipam/ipam.go 118: Auto-assign 1 ipv4, 0 ipv6 addrs for host 'ip-172-31-16-165' Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.227 [INFO][6438] ipam/ipam.go 723: Looking up existing affinities for host handle="k8s-pod-network.e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" host="ip-172-31-16-165" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.259 [INFO][6438] ipam/ipam.go 415: Looking up existing affinities for host host="ip-172-31-16-165" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.312 [INFO][6438] ipam/ipam.go 531: Trying affinity for 192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.321 [INFO][6438] ipam/ipam.go 166: Attempting to load block cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.332 [INFO][6438] ipam/ipam.go 243: Affinity is confirmed and block has been loaded cidr=192.168.27.128/26 host="ip-172-31-16-165" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.333 [INFO][6438] ipam/ipam.go 1392: Attempting to assign 1 addresses from block block=192.168.27.128/26 handle="k8s-pod-network.e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" host="ip-172-31-16-165" Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.342 [INFO][6438] ipam/ipam.go 1974: Creating new handle: k8s-pod-network.e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4 Jul 21 12:39:11.551718 containerd[2389]: 2026-07-21 12:39:11.362 [INFO][6438] ipam/ipam.go 1422: Writing block in order to claim IPs block=192.168.27.128/26 handle="k8s-pod-network.e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" host="ip-172-31-16-165" Jul 21 12:39:11.555779 containerd[2389]: 2026-07-21 12:39:11.401 [INFO][6438] ipam/ipam.go 1438: Successfully claimed IPs: [192.168.27.136/26] block=192.168.27.128/26 handle="k8s-pod-network.e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" host="ip-172-31-16-165" Jul 21 12:39:11.555779 containerd[2389]: 2026-07-21 12:39:11.402 [INFO][6438] ipam/ipam.go 947: Auto-assigned 1 out of 1 IPv4s: [192.168.27.136/26] handle="k8s-pod-network.e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" host="ip-172-31-16-165" Jul 21 12:39:11.555779 containerd[2389]: 2026-07-21 12:39:11.403 [INFO][6438] ipam/ipam_plugin.go 547: Released host-wide IPAM lock. Jul 21 12:39:11.555779 containerd[2389]: 2026-07-21 12:39:11.403 [INFO][6438] ipam/ipam_plugin.go 403: Calico CNI IPAM assigned addresses IPv4=[192.168.27.136/26] IPv6=[] ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" HandleID="k8s-pod-network.e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Workload="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" Jul 21 12:39:11.555779 containerd[2389]: 2026-07-21 12:39:11.427 [INFO][6347] cni-plugin/k8s.go 422: Populated endpoint ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Namespace="calico-system" Pod="calico-kube-controllers-cbf695f-b4zcr" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0", GenerateName:"calico-kube-controllers-cbf695f-", Namespace:"calico-system", SelfLink:"", UID:"0f387b73-51f8-48e1-9153-5bdf9a5d18b4", ResourceVersion:"886", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 30, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"app.kubernetes.io/component":"Installation.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"calico-kube-controllers", "app.kubernetes.io/part-of":"Calico", "k8s-app":"calico-kube-controllers", "pod-template-hash":"cbf695f", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"calico-kube-controllers"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"", Pod:"calico-kube-controllers-cbf695f-b4zcr", Endpoint:"eth0", ServiceAccountName:"calico-kube-controllers", IPNetworks:[]string{"192.168.27.136/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.calico-kube-controllers"}, InterfaceName:"calicf35013cec5", MAC:"", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:11.555779 containerd[2389]: 2026-07-21 12:39:11.427 [INFO][6347] cni-plugin/k8s.go 423: Calico CNI using IPs: [192.168.27.136/32] ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Namespace="calico-system" Pod="calico-kube-controllers-cbf695f-b4zcr" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" Jul 21 12:39:11.555779 containerd[2389]: 2026-07-21 12:39:11.427 [INFO][6347] cni-plugin/dataplane_linux.go 77: Setting the host side veth name to calicf35013cec5 ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Namespace="calico-system" Pod="calico-kube-controllers-cbf695f-b4zcr" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" Jul 21 12:39:11.555779 containerd[2389]: 2026-07-21 12:39:11.436 [INFO][6347] cni-plugin/dataplane_linux.go 179: Read back correct host-side MAC. ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Namespace="calico-system" Pod="calico-kube-controllers-cbf695f-b4zcr" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" Jul 21 12:39:11.555779 containerd[2389]: 2026-07-21 12:39:11.457 [INFO][6347] cni-plugin/dataplane_linux.go 292: Adding IPv4 route (inside container) ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Namespace="calico-system" Pod="calico-kube-controllers-cbf695f-b4zcr" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" route=0.0.0.0/0 Jul 21 12:39:11.555779 containerd[2389]: 2026-07-21 12:39:11.470 [INFO][6347] cni-plugin/dataplane_linux.go 570: Disabling IPv4 forwarding ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Namespace="calico-system" Pod="calico-kube-controllers-cbf695f-b4zcr" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" Jul 21 12:39:11.556561 containerd[2389]: 2026-07-21 12:39:11.484 [INFO][6347] cni-plugin/k8s.go 458: Added Mac, interface name, and active container ID to endpoint ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Namespace="calico-system" Pod="calico-kube-controllers-cbf695f-b4zcr" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" endpoint=&internalapi.WorkloadEndpoint{TypeMeta:v1.TypeMeta{Kind:"WorkloadEndpoint", APIVersion:"projectcalico.org/v3"}, ObjectMeta:v1.ObjectMeta{Name:"ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0", GenerateName:"calico-kube-controllers-cbf695f-", Namespace:"calico-system", SelfLink:"", UID:"0f387b73-51f8-48e1-9153-5bdf9a5d18b4", ResourceVersion:"886", Generation:0, CreationTimestamp:time.Date(2026, time.July, 21, 12, 38, 30, 0, time.Local), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"app.kubernetes.io/component":"Installation.operator.tigera.io", "app.kubernetes.io/instance":"default", "app.kubernetes.io/managed-by":"tigera-operator", "app.kubernetes.io/name":"calico-kube-controllers", "app.kubernetes.io/part-of":"Calico", "k8s-app":"calico-kube-controllers", "pod-template-hash":"cbf695f", "projectcalico.org/namespace":"calico-system", "projectcalico.org/orchestrator":"k8s", "projectcalico.org/serviceaccount":"calico-kube-controllers"}, Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:internalapi.WorkloadEndpointSpec{Orchestrator:"k8s", Workload:"", Node:"ip-172-31-16-165", ContainerID:"e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4", Pod:"calico-kube-controllers-cbf695f-b4zcr", Endpoint:"eth0", ServiceAccountName:"calico-kube-controllers", IPNetworks:[]string{"192.168.27.136/32"}, IPNATs:[]internalapi.IPNAT(nil), IPv4Gateway:"", IPv6Gateway:"", Profiles:[]string{"kns.calico-system", "ksa.calico-system.calico-kube-controllers"}, InterfaceName:"calicf35013cec5", MAC:"92:3f:6d:cf:9e:ae", Ports:[]internalapi.WorkloadEndpointPort(nil), AllowSpoofedSourcePrefixes:[]string(nil), QoSControls:(*internalapi.QoSControls)(nil)}} Jul 21 12:39:11.556561 containerd[2389]: 2026-07-21 12:39:11.530 [INFO][6347] cni-plugin/k8s.go 544: Wrote updated endpoint to datastore ContainerID="e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" Namespace="calico-system" Pod="calico-kube-controllers-cbf695f-b4zcr" WorkloadEndpoint="ip--172--31--16--165-k8s-calico--kube--controllers--cbf695f--b4zcr-eth0" Jul 21 12:39:11.618390 sshd[6484]: Connection closed by authenticating user root 144.225.8.54 port 48542 [preauth] Jul 21 12:39:11.619000 audit[6484]: AUDIT1109 pid=6484 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:11.627274 systemd[1]: sshd@75-28-172.31.16.165:22-144.225.8.54:48542.service: Deactivated successfully. Jul 21 12:39:11.627000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@75-28-172.31.16.165:22-144.225.8.54:48542 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:11.631732 containerd[2389]: time="2026-07-21T12:39:11.627750993Z" level=info msg="StartContainer for \"3ea98d872f14b7cb355a4a10c62232ff47b233ca96b697248e12754c4dd52d6e\" returns successfully" Jul 21 12:39:11.719367 systemd[1]: Started sshd@76-4145-172.31.16.165:22-144.225.8.54:48548.service - OpenSSH per-connection server daemon (144.225.8.54:48548). Jul 21 12:39:11.720000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@76-4145-172.31.16.165:22-144.225.8.54:48548 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:11.727560 containerd[2389]: time="2026-07-21T12:39:11.725112058Z" level=info msg="connecting to shim e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4" address="unix:///run/containerd/s/444b2f397d740223926cc462f0d80167124910910d96f175b87325709dea04f5" namespace=k8s.io protocol=ttrpc version=3 Jul 21 12:39:11.935879 systemd[1]: Started cri-containerd-e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4.scope - libcontainer container e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4. Jul 21 12:39:12.062903 kubelet[4002]: I0721 12:39:12.062732 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="kube-system/coredns-66bc5c9577-hjfjb" podStartSLOduration=65.062541283 podStartE2EDuration="1m5.062541283s" podCreationTimestamp="2026-07-21 12:38:07 +0000 UTC" firstStartedPulling="0001-01-01 00:00:00 +0000 UTC" lastFinishedPulling="0001-01-01 00:00:00 +0000 UTC" observedRunningTime="2026-07-21 12:39:12.058928407 +0000 UTC m=+69.011945779" watchObservedRunningTime="2026-07-21 12:39:12.062541283 +0000 UTC m=+69.015558631" Jul 21 12:39:12.077630 systemd-networkd[2075]: calib7ce1f5fb11: Gained IPv6LL Jul 21 12:39:12.160551 sshd[6552]: Connection closed by authenticating user root 144.225.8.54 port 48548 [preauth] Jul 21 12:39:12.162000 audit[6552]: AUDIT1109 pid=6552 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:12.171456 systemd[1]: sshd@76-4145-172.31.16.165:22-144.225.8.54:48548.service: Deactivated successfully. Jul 21 12:39:12.172000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@76-4145-172.31.16.165:22-144.225.8.54:48548 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:12.242000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@77-4146-172.31.16.165:22-144.225.8.54:48554 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:12.243765 systemd[1]: Started sshd@77-4146-172.31.16.165:22-144.225.8.54:48554.service - OpenSSH per-connection server daemon (144.225.8.54:48554). Jul 21 12:39:12.302000 audit[6602]: NETFILTER_CFG table=filter:123 family=2 entries=56 op=nft_register_chain pid=6602 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:12.302000 audit[6602]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=25532 a0=3 a1=fffff83ad810 a2=0 a3=ffff97cb77e0 items=0 ppid=5430 pid=6602 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.302000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:12.384000 audit: BPF prog-id=253 op=LOAD Jul 21 12:39:12.388000 audit[6609]: NETFILTER_CFG table=calico-arp:124 family=3 entries=3 op=nft_register_chain pid=6609 subj=system_u:system_r:kernel_t:s0 comm="nft" Jul 21 12:39:12.388000 audit[6609]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=732 a0=3 a1=fffffa69d6b8 a2=0 a3=ffff8863a020 items=0 ppid=5430 pid=6609 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="nft" exe="/usr/sbin/nft" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.388000 audit: PROCTITLE proctitle=2F7573722F7362696E2F6E6674002D66002D Jul 21 12:39:12.390000 audit: BPF prog-id=254 op=LOAD Jul 21 12:39:12.390000 audit[6567]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=5d1471431f90 a2=98 a3=0 items=0 ppid=6549 pid=6567 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.390000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6539663731616236393563313662326230343063316161616234363330 Jul 21 12:39:12.396000 audit: BPF prog-id=254 op=UNLOAD Jul 21 12:39:12.396000 audit[6567]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6549 pid=6567 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.396000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6539663731616236393563313662326230343063316161616234363330 Jul 21 12:39:12.396000 audit: BPF prog-id=255 op=LOAD Jul 21 12:39:12.396000 audit[6567]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=5d1471432268 a2=98 a3=0 items=0 ppid=6549 pid=6567 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.396000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6539663731616236393563313662326230343063316161616234363330 Jul 21 12:39:12.396000 audit: BPF prog-id=256 op=LOAD Jul 21 12:39:12.396000 audit[6567]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=5d1471431fa8 a2=98 a3=0 items=0 ppid=6549 pid=6567 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.396000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6539663731616236393563313662326230343063316161616234363330 Jul 21 12:39:12.396000 audit: BPF prog-id=256 op=UNLOAD Jul 21 12:39:12.396000 audit[6567]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=6549 pid=6567 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.396000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6539663731616236393563313662326230343063316161616234363330 Jul 21 12:39:12.396000 audit: BPF prog-id=255 op=UNLOAD Jul 21 12:39:12.396000 audit[6567]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6549 pid=6567 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.396000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6539663731616236393563313662326230343063316161616234363330 Jul 21 12:39:12.395000 audit[6608]: NETFILTER_CFG table=filter:125 family=2 entries=18 op=nft_register_rule pid=6608 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:12.395000 audit[6608]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=6736 a0=3 a1=fffff9952a60 a2=0 a3=1 items=0 ppid=4148 pid=6608 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.395000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:12.396000 audit: BPF prog-id=257 op=LOAD Jul 21 12:39:12.396000 audit[6567]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=5d14714324b8 a2=98 a3=0 items=0 ppid=6549 pid=6567 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.396000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6539663731616236393563313662326230343063316161616234363330 Jul 21 12:39:12.407000 audit[6608]: NETFILTER_CFG table=nat:126 family=2 entries=16 op=nft_register_rule pid=6608 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:12.407000 audit[6608]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=4236 a0=3 a1=fffff9952a60 a2=0 a3=1 items=0 ppid=4148 pid=6608 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:12.407000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:12.547508 containerd[2389]: time="2026-07-21T12:39:12.547349806Z" level=info msg="RunPodSandbox for name:\"calico-kube-controllers-cbf695f-b4zcr\" uid:\"0f387b73-51f8-48e1-9153-5bdf9a5d18b4\" namespace:\"calico-system\" returns sandbox id \"e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4\"" Jul 21 12:39:12.661698 sshd[6605]: Connection closed by authenticating user root 144.225.8.54 port 48554 [preauth] Jul 21 12:39:12.661000 audit[6605]: AUDIT1109 pid=6605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:12.668375 systemd[1]: sshd@77-4146-172.31.16.165:22-144.225.8.54:48554.service: Deactivated successfully. Jul 21 12:39:12.668000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@77-4146-172.31.16.165:22-144.225.8.54:48554 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:12.750007 systemd[1]: Started sshd@78-29-172.31.16.165:22-144.225.8.54:48562.service - OpenSSH per-connection server daemon (144.225.8.54:48562). Jul 21 12:39:12.749000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@78-29-172.31.16.165:22-144.225.8.54:48562 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:12.752288 kernel: kauditd_printk_skb: 228 callbacks suppressed Jul 21 12:39:12.752386 kernel: audit: type=1130 audit(1784637552.749:929): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@78-29-172.31.16.165:22-144.225.8.54:48562 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:13.078524 sshd[6623]: Connection closed by authenticating user root 144.225.8.54 port 48562 [preauth] Jul 21 12:39:13.078000 audit[6623]: AUDIT1109 pid=6623 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:13.090350 kernel: audit: type=1109 audit(1784637553.078:930): pid=6623 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:13.092514 systemd[1]: sshd@78-29-172.31.16.165:22-144.225.8.54:48562.service: Deactivated successfully. Jul 21 12:39:13.094000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@78-29-172.31.16.165:22-144.225.8.54:48562 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:13.103231 kernel: audit: type=1131 audit(1784637553.094:931): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@78-29-172.31.16.165:22-144.225.8.54:48562 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:13.155350 systemd[1]: Started sshd@79-30-172.31.16.165:22-144.225.8.54:48578.service - OpenSSH per-connection server daemon (144.225.8.54:48578). Jul 21 12:39:13.154000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@79-30-172.31.16.165:22-144.225.8.54:48578 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:13.164264 kernel: audit: type=1130 audit(1784637553.154:932): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@79-30-172.31.16.165:22-144.225.8.54:48578 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:13.421535 systemd-networkd[2075]: calicf35013cec5: Gained IPv6LL Jul 21 12:39:13.447741 containerd[2389]: time="2026-07-21T12:39:13.447288490Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/apiserver:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:13.450803 containerd[2389]: time="2026-07-21T12:39:13.450685030Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/apiserver:v3.32.1: active requests=1, bytes read=43036672" Jul 21 12:39:13.453138 containerd[2389]: time="2026-07-21T12:39:13.452869006Z" level=info msg="ImageCreate event name:\"sha256:7927104786f4d9c3e94554376a5bd883ff48769e526cebab512a744e42536f4b\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:13.461319 containerd[2389]: time="2026-07-21T12:39:13.461160502Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/apiserver@sha256:6c8b0e82ab9fc24e3d6734f470ff09ff034fda95e632da592891ea79f40e2c05\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:13.463894 containerd[2389]: time="2026-07-21T12:39:13.462838234Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/apiserver:v3.32.1\" with image id \"sha256:7927104786f4d9c3e94554376a5bd883ff48769e526cebab512a744e42536f4b\", repo tag \"ghcr.io/flatcar/calico/apiserver:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/apiserver@sha256:6c8b0e82ab9fc24e3d6734f470ff09ff034fda95e632da592891ea79f40e2c05\", size \"46859304\" in 7.040874767s" Jul 21 12:39:13.463894 containerd[2389]: time="2026-07-21T12:39:13.462897598Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/apiserver:v3.32.1\" returns image reference \"sha256:7927104786f4d9c3e94554376a5bd883ff48769e526cebab512a744e42536f4b\"" Jul 21 12:39:13.467378 containerd[2389]: time="2026-07-21T12:39:13.467088154Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/csi:v3.32.1\"" Jul 21 12:39:13.473845 containerd[2389]: time="2026-07-21T12:39:13.473769958Z" level=info msg="CreateContainer within sandbox \"24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f\" for container name:\"calico-apiserver\"" Jul 21 12:39:13.476000 audit[6643]: NETFILTER_CFG table=filter:127 family=2 entries=15 op=nft_register_rule pid=6643 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:13.476000 audit[6643]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=4504 a0=3 a1=ffffe2f17360 a2=0 a3=1 items=0 ppid=4148 pid=6643 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.487449 kernel: audit: type=1325 audit(1784637553.476:933): table=filter:127 family=2 entries=15 op=nft_register_rule pid=6643 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:13.487667 kernel: audit: type=1300 audit(1784637553.476:933): arch=c00000b7 syscall=211 success=yes exit=4504 a0=3 a1=ffffe2f17360 a2=0 a3=1 items=0 ppid=4148 pid=6643 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.476000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:13.490526 kernel: audit: type=1327 audit(1784637553.476:933): proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:13.493529 sshd[6630]: Connection closed by authenticating user root 144.225.8.54 port 48578 [preauth] Jul 21 12:39:13.493000 audit[6630]: AUDIT1109 pid=6630 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:13.505239 kernel: audit: type=1109 audit(1784637553.493:934): pid=6630 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:13.507000 audit[6643]: NETFILTER_CFG table=nat:128 family=2 entries=49 op=nft_register_chain pid=6643 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:13.507000 audit[6643]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=20628 a0=3 a1=ffffe2f17360 a2=0 a3=1 items=0 ppid=4148 pid=6643 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.524912 kernel: audit: type=1325 audit(1784637553.507:935): table=nat:128 family=2 entries=49 op=nft_register_chain pid=6643 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:13.518491 systemd[1]: sshd@79-30-172.31.16.165:22-144.225.8.54:48578.service: Deactivated successfully. Jul 21 12:39:13.525115 kernel: audit: type=1300 audit(1784637553.507:935): arch=c00000b7 syscall=211 success=yes exit=20628 a0=3 a1=ffffe2f17360 a2=0 a3=1 items=0 ppid=4148 pid=6643 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.507000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:13.517000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@79-30-172.31.16.165:22-144.225.8.54:48578 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:13.573000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@80-31-172.31.16.165:22-144.225.8.54:48582 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:13.574004 systemd[1]: Started sshd@80-31-172.31.16.165:22-144.225.8.54:48582.service - OpenSSH per-connection server daemon (144.225.8.54:48582). Jul 21 12:39:13.576472 containerd[2389]: time="2026-07-21T12:39:13.576378479Z" level=info msg="CreateContainer within sandbox \"24729c81d82dd1d118d9e26cf68e2e74587a00a288cf0eff13e771b00f96331f\" for name:\"calico-apiserver\" returns container id \"0baca55707b957b00fc59fd4d14143daee65ba4f575cf015978223d393ec49ca\"" Jul 21 12:39:13.579268 containerd[2389]: time="2026-07-21T12:39:13.578830991Z" level=info msg="StartContainer for \"0baca55707b957b00fc59fd4d14143daee65ba4f575cf015978223d393ec49ca\"" Jul 21 12:39:13.586563 containerd[2389]: time="2026-07-21T12:39:13.586498355Z" level=info msg="connecting to shim 0baca55707b957b00fc59fd4d14143daee65ba4f575cf015978223d393ec49ca" address="unix:///run/containerd/s/4572f319c7ca3d0f9ea7e460faf448c396a3952c788884210644276a513d1f00" protocol=ttrpc version=3 Jul 21 12:39:13.672465 systemd[1]: Started cri-containerd-0baca55707b957b00fc59fd4d14143daee65ba4f575cf015978223d393ec49ca.scope - libcontainer container 0baca55707b957b00fc59fd4d14143daee65ba4f575cf015978223d393ec49ca. Jul 21 12:39:13.738000 audit: BPF prog-id=258 op=LOAD Jul 21 12:39:13.739000 audit: BPF prog-id=259 op=LOAD Jul 21 12:39:13.739000 audit[6649]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2d0976cf3f90 a2=98 a3=0 items=0 ppid=5868 pid=6649 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.739000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3062616361353537303762393537623030666335396664346431343134 Jul 21 12:39:13.739000 audit: BPF prog-id=259 op=UNLOAD Jul 21 12:39:13.739000 audit[6649]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=5868 pid=6649 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.739000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3062616361353537303762393537623030666335396664346431343134 Jul 21 12:39:13.740000 audit: BPF prog-id=260 op=LOAD Jul 21 12:39:13.740000 audit[6649]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2d0976cf4268 a2=98 a3=0 items=0 ppid=5868 pid=6649 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.740000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3062616361353537303762393537623030666335396664346431343134 Jul 21 12:39:13.740000 audit: BPF prog-id=261 op=LOAD Jul 21 12:39:13.740000 audit[6649]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=2d0976cf3fa8 a2=98 a3=0 items=0 ppid=5868 pid=6649 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.740000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3062616361353537303762393537623030666335396664346431343134 Jul 21 12:39:13.740000 audit: BPF prog-id=261 op=UNLOAD Jul 21 12:39:13.740000 audit[6649]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=5868 pid=6649 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.740000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3062616361353537303762393537623030666335396664346431343134 Jul 21 12:39:13.740000 audit: BPF prog-id=260 op=UNLOAD Jul 21 12:39:13.740000 audit[6649]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=5868 pid=6649 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.740000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3062616361353537303762393537623030666335396664346431343134 Jul 21 12:39:13.740000 audit: BPF prog-id=262 op=LOAD Jul 21 12:39:13.740000 audit[6649]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2d0976cf44b8 a2=98 a3=0 items=0 ppid=5868 pid=6649 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:13.740000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3062616361353537303762393537623030666335396664346431343134 Jul 21 12:39:13.816467 containerd[2389]: time="2026-07-21T12:39:13.816315612Z" level=info msg="StartContainer for \"0baca55707b957b00fc59fd4d14143daee65ba4f575cf015978223d393ec49ca\" returns successfully" Jul 21 12:39:13.939105 sshd[6648]: Connection closed by authenticating user root 144.225.8.54 port 48582 [preauth] Jul 21 12:39:13.938000 audit[6648]: AUDIT1109 pid=6648 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:13.941834 systemd[1]: sshd@80-31-172.31.16.165:22-144.225.8.54:48582.service: Deactivated successfully. Jul 21 12:39:13.941000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@80-31-172.31.16.165:22-144.225.8.54:48582 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:14.015824 systemd[1]: Started sshd@81-32-172.31.16.165:22-144.225.8.54:48598.service - OpenSSH per-connection server daemon (144.225.8.54:48598). Jul 21 12:39:14.014000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@81-32-172.31.16.165:22-144.225.8.54:48598 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:14.104240 kubelet[4002]: I0721 12:39:14.102826 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="calico-system/calico-apiserver-6b46596bdc-qpmql" podStartSLOduration=41.058888647 podStartE2EDuration="48.10280635s" podCreationTimestamp="2026-07-21 12:38:26 +0000 UTC" firstStartedPulling="2026-07-21 12:39:06.421407711 +0000 UTC m=+63.374425035" lastFinishedPulling="2026-07-21 12:39:13.465325318 +0000 UTC m=+70.418342738" observedRunningTime="2026-07-21 12:39:14.097529134 +0000 UTC m=+71.050546482" watchObservedRunningTime="2026-07-21 12:39:14.10280635 +0000 UTC m=+71.055823686" Jul 21 12:39:14.105868 kubelet[4002]: I0721 12:39:14.104863 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="kube-system/coredns-66bc5c9577-6bgj5" podStartSLOduration=67.10483939 podStartE2EDuration="1m7.10483939s" podCreationTimestamp="2026-07-21 12:38:07 +0000 UTC" firstStartedPulling="0001-01-01 00:00:00 +0000 UTC" lastFinishedPulling="0001-01-01 00:00:00 +0000 UTC" observedRunningTime="2026-07-21 12:39:12.22318052 +0000 UTC m=+69.176197952" watchObservedRunningTime="2026-07-21 12:39:14.10483939 +0000 UTC m=+71.057856750" Jul 21 12:39:14.372504 sshd[6688]: Connection closed by authenticating user root 144.225.8.54 port 48598 [preauth] Jul 21 12:39:14.371000 audit[6688]: AUDIT1109 pid=6688 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:14.375530 systemd[1]: sshd@81-32-172.31.16.165:22-144.225.8.54:48598.service: Deactivated successfully. Jul 21 12:39:14.376000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@81-32-172.31.16.165:22-144.225.8.54:48598 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:14.449000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@82-33-172.31.16.165:22-144.225.8.54:48600 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:14.450056 systemd[1]: Started sshd@82-33-172.31.16.165:22-144.225.8.54:48600.service - OpenSSH per-connection server daemon (144.225.8.54:48600). Jul 21 12:39:14.572000 audit[6698]: NETFILTER_CFG table=filter:129 family=2 entries=12 op=nft_register_rule pid=6698 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:14.572000 audit[6698]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=4504 a0=3 a1=ffffc46c9e00 a2=0 a3=1 items=0 ppid=4148 pid=6698 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:14.572000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:14.580000 audit[6698]: NETFILTER_CFG table=nat:130 family=2 entries=22 op=nft_register_rule pid=6698 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:14.580000 audit[6698]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=6540 a0=3 a1=ffffc46c9e00 a2=0 a3=1 items=0 ppid=4148 pid=6698 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:14.580000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:14.808369 sshd[6694]: Connection closed by authenticating user root 144.225.8.54 port 48600 [preauth] Jul 21 12:39:14.808000 audit[6694]: AUDIT1109 pid=6694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:14.812000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@82-33-172.31.16.165:22-144.225.8.54:48600 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:14.813680 systemd[1]: sshd@82-33-172.31.16.165:22-144.225.8.54:48600.service: Deactivated successfully. Jul 21 12:39:14.884000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@83-34-172.31.16.165:22-144.225.8.54:48616 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:14.884954 systemd[1]: Started sshd@83-34-172.31.16.165:22-144.225.8.54:48616.service - OpenSSH per-connection server daemon (144.225.8.54:48616). Jul 21 12:39:15.075085 kubelet[4002]: I0721 12:39:15.074928 4002 prober_manager.go:312] "Failed to trigger a manual run" probe="Readiness" Jul 21 12:39:15.165223 containerd[2389]: time="2026-07-21T12:39:15.165089867Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/csi:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:15.168259 containerd[2389]: time="2026-07-21T12:39:15.167224391Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/csi:v3.32.1: active requests=0, bytes read=0" Jul 21 12:39:15.170103 containerd[2389]: time="2026-07-21T12:39:15.170028707Z" level=info msg="ImageCreate event name:\"sha256:ceff9d9a64db7b3c5e71949b590abc7acee14128c585b22913e2ec9f3bac9717\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:15.176459 containerd[2389]: time="2026-07-21T12:39:15.176371691Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/csi@sha256:1742a6ff76b073a6976147713743bee0f72b29e8eb188d46b93dabfd3ac86cff\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:15.178978 containerd[2389]: time="2026-07-21T12:39:15.178801127Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/csi:v3.32.1\" with image id \"sha256:ceff9d9a64db7b3c5e71949b590abc7acee14128c585b22913e2ec9f3bac9717\", repo tag \"ghcr.io/flatcar/calico/csi:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/csi@sha256:1742a6ff76b073a6976147713743bee0f72b29e8eb188d46b93dabfd3ac86cff\", size \"10490681\" in 1.710938661s" Jul 21 12:39:15.178978 containerd[2389]: time="2026-07-21T12:39:15.178854011Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/csi:v3.32.1\" returns image reference \"sha256:ceff9d9a64db7b3c5e71949b590abc7acee14128c585b22913e2ec9f3bac9717\"" Jul 21 12:39:15.180880 containerd[2389]: time="2026-07-21T12:39:15.180602303Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/goldmane:v3.32.1\"" Jul 21 12:39:15.194887 containerd[2389]: time="2026-07-21T12:39:15.193745867Z" level=info msg="CreateContainer within sandbox \"336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e\" for container name:\"calico-csi\"" Jul 21 12:39:15.253260 sshd[6706]: Connection closed by authenticating user root 144.225.8.54 port 48616 [preauth] Jul 21 12:39:15.252000 audit[6706]: AUDIT1109 pid=6706 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:15.258447 containerd[2389]: time="2026-07-21T12:39:15.258352355Z" level=info msg="CreateContainer within sandbox \"336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e\" for name:\"calico-csi\" returns container id \"991e127e63cafcdedd02887ae57fab9ce4f8422195d48e8ce0229f7df124a552\"" Jul 21 12:39:15.259419 systemd[1]: sshd@83-34-172.31.16.165:22-144.225.8.54:48616.service: Deactivated successfully. Jul 21 12:39:15.259000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@83-34-172.31.16.165:22-144.225.8.54:48616 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:15.264938 containerd[2389]: time="2026-07-21T12:39:15.262082699Z" level=info msg="StartContainer for \"991e127e63cafcdedd02887ae57fab9ce4f8422195d48e8ce0229f7df124a552\"" Jul 21 12:39:15.271597 containerd[2389]: time="2026-07-21T12:39:15.271502879Z" level=info msg="connecting to shim 991e127e63cafcdedd02887ae57fab9ce4f8422195d48e8ce0229f7df124a552" address="unix:///run/containerd/s/4b17f696d5f099a854edff7db3a04f9a670cb9817840980ffedb2fe99f11e712" protocol=ttrpc version=3 Jul 21 12:39:15.329763 systemd[1]: Started sshd@84-35-172.31.16.165:22-144.225.8.54:48630.service - OpenSSH per-connection server daemon (144.225.8.54:48630). Jul 21 12:39:15.329000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@84-35-172.31.16.165:22-144.225.8.54:48630 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:15.351146 systemd[1]: Started cri-containerd-991e127e63cafcdedd02887ae57fab9ce4f8422195d48e8ce0229f7df124a552.scope - libcontainer container 991e127e63cafcdedd02887ae57fab9ce4f8422195d48e8ce0229f7df124a552. Jul 21 12:39:15.458000 audit: BPF prog-id=263 op=LOAD Jul 21 12:39:15.458000 audit[6711]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=4de6f156a268 a2=98 a3=0 items=0 ppid=6041 pid=6711 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:15.458000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3939316531323765363363616663646564643032383837616535376661 Jul 21 12:39:15.459000 audit: BPF prog-id=264 op=LOAD Jul 21 12:39:15.459000 audit[6711]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=4de6f1569fa8 a2=98 a3=0 items=0 ppid=6041 pid=6711 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:15.459000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3939316531323765363363616663646564643032383837616535376661 Jul 21 12:39:15.459000 audit: BPF prog-id=264 op=UNLOAD Jul 21 12:39:15.459000 audit[6711]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6041 pid=6711 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:15.459000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3939316531323765363363616663646564643032383837616535376661 Jul 21 12:39:15.459000 audit: BPF prog-id=263 op=UNLOAD Jul 21 12:39:15.459000 audit[6711]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=13 a1=0 a2=0 a3=0 items=0 ppid=6041 pid=6711 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:15.459000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3939316531323765363363616663646564643032383837616535376661 Jul 21 12:39:15.459000 audit: BPF prog-id=265 op=LOAD Jul 21 12:39:15.459000 audit[6711]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=4de6f156a4b8 a2=98 a3=0 items=0 ppid=6041 pid=6711 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:15.459000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3939316531323765363363616663646564643032383837616535376661 Jul 21 12:39:15.496393 ntpd[2333]: Listen normally on 9 calid1c2c3ae5c8 [fe80::ecee:eeff:feee:eeee%8]:123 Jul 21 12:39:15.497168 ntpd[2333]: 21 Jul 12:39:15 ntpd[2333]: Listen normally on 9 calid1c2c3ae5c8 [fe80::ecee:eeff:feee:eeee%8]:123 Jul 21 12:39:15.497168 ntpd[2333]: 21 Jul 12:39:15 ntpd[2333]: Listen normally on 10 cali5f4e890389a [fe80::ecee:eeff:feee:eeee%9]:123 Jul 21 12:39:15.497168 ntpd[2333]: 21 Jul 12:39:15 ntpd[2333]: Listen normally on 11 cali9a39a32a0ed [fe80::ecee:eeff:feee:eeee%10]:123 Jul 21 12:39:15.497168 ntpd[2333]: 21 Jul 12:39:15 ntpd[2333]: Listen normally on 12 cali1ab6e5f751a [fe80::ecee:eeff:feee:eeee%11]:123 Jul 21 12:39:15.497168 ntpd[2333]: 21 Jul 12:39:15 ntpd[2333]: Listen normally on 13 califee178f2956 [fe80::ecee:eeff:feee:eeee%12]:123 Jul 21 12:39:15.497168 ntpd[2333]: 21 Jul 12:39:15 ntpd[2333]: Listen normally on 14 calib7ce1f5fb11 [fe80::ecee:eeff:feee:eeee%13]:123 Jul 21 12:39:15.496504 ntpd[2333]: Listen normally on 10 cali5f4e890389a [fe80::ecee:eeff:feee:eeee%9]:123 Jul 21 12:39:15.496557 ntpd[2333]: Listen normally on 11 cali9a39a32a0ed [fe80::ecee:eeff:feee:eeee%10]:123 Jul 21 12:39:15.496603 ntpd[2333]: Listen normally on 12 cali1ab6e5f751a [fe80::ecee:eeff:feee:eeee%11]:123 Jul 21 12:39:15.496648 ntpd[2333]: Listen normally on 13 califee178f2956 [fe80::ecee:eeff:feee:eeee%12]:123 Jul 21 12:39:15.496705 ntpd[2333]: Listen normally on 14 calib7ce1f5fb11 [fe80::ecee:eeff:feee:eeee%13]:123 Jul 21 12:39:15.498304 ntpd[2333]: Listen normally on 15 calicf35013cec5 [fe80::ecee:eeff:feee:eeee%14]:123 Jul 21 12:39:15.498903 ntpd[2333]: 21 Jul 12:39:15 ntpd[2333]: Listen normally on 15 calicf35013cec5 [fe80::ecee:eeff:feee:eeee%14]:123 Jul 21 12:39:15.525676 containerd[2389]: time="2026-07-21T12:39:15.525602005Z" level=info msg="StartContainer for \"991e127e63cafcdedd02887ae57fab9ce4f8422195d48e8ce0229f7df124a552\" returns successfully" Jul 21 12:39:15.665666 sshd[6724]: Connection closed by authenticating user root 144.225.8.54 port 48630 [preauth] Jul 21 12:39:15.667000 audit[6724]: AUDIT1109 pid=6724 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:15.670000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@84-35-172.31.16.165:22-144.225.8.54:48630 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:15.671071 systemd[1]: sshd@84-35-172.31.16.165:22-144.225.8.54:48630.service: Deactivated successfully. Jul 21 12:39:15.743000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@85-36-172.31.16.165:22-144.225.8.54:48634 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:15.744756 systemd[1]: Started sshd@85-36-172.31.16.165:22-144.225.8.54:48634.service - OpenSSH per-connection server daemon (144.225.8.54:48634). Jul 21 12:39:16.063973 sshd[6746]: Connection closed by authenticating user root 144.225.8.54 port 48634 [preauth] Jul 21 12:39:16.065000 audit[6746]: AUDIT1109 pid=6746 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:16.075126 systemd[1]: sshd@85-36-172.31.16.165:22-144.225.8.54:48634.service: Deactivated successfully. Jul 21 12:39:16.075000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@85-36-172.31.16.165:22-144.225.8.54:48634 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:16.143761 systemd[1]: Started sshd@86-37-172.31.16.165:22-144.225.8.54:48638.service - OpenSSH per-connection server daemon (144.225.8.54:48638). Jul 21 12:39:16.142000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@86-37-172.31.16.165:22-144.225.8.54:48638 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:16.491099 sshd[6753]: Connection closed by authenticating user root 144.225.8.54 port 48638 [preauth] Jul 21 12:39:16.490000 audit[6753]: AUDIT1109 pid=6753 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:16.501110 systemd[1]: sshd@86-37-172.31.16.165:22-144.225.8.54:48638.service: Deactivated successfully. Jul 21 12:39:16.503000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@86-37-172.31.16.165:22-144.225.8.54:48638 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:16.572000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@87-4147-172.31.16.165:22-144.225.8.54:48650 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:16.571921 systemd[1]: Started sshd@87-4147-172.31.16.165:22-144.225.8.54:48650.service - OpenSSH per-connection server daemon (144.225.8.54:48650). Jul 21 12:39:16.918882 sshd[6759]: Connection closed by authenticating user root 144.225.8.54 port 48650 [preauth] Jul 21 12:39:16.919000 audit[6759]: AUDIT1109 pid=6759 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:16.924800 systemd[1]: sshd@87-4147-172.31.16.165:22-144.225.8.54:48650.service: Deactivated successfully. Jul 21 12:39:16.924000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@87-4147-172.31.16.165:22-144.225.8.54:48650 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:16.998000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@88-38-172.31.16.165:22-144.225.8.54:48652 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:16.999110 systemd[1]: Started sshd@88-38-172.31.16.165:22-144.225.8.54:48652.service - OpenSSH per-connection server daemon (144.225.8.54:48652). Jul 21 12:39:17.391777 sshd[6765]: Connection closed by authenticating user root 144.225.8.54 port 48652 [preauth] Jul 21 12:39:17.391000 audit[6765]: AUDIT1109 pid=6765 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:17.398435 systemd[1]: sshd@88-38-172.31.16.165:22-144.225.8.54:48652.service: Deactivated successfully. Jul 21 12:39:17.400000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@88-38-172.31.16.165:22-144.225.8.54:48652 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:17.488885 systemd[1]: Started sshd@89-39-172.31.16.165:22-144.225.8.54:48660.service - OpenSSH per-connection server daemon (144.225.8.54:48660). Jul 21 12:39:17.487000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@89-39-172.31.16.165:22-144.225.8.54:48660 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:17.801342 sshd[6778]: Connection closed by authenticating user root 144.225.8.54 port 48660 [preauth] Jul 21 12:39:17.800000 audit[6778]: AUDIT1109 pid=6778 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:17.804762 systemd[1]: sshd@89-39-172.31.16.165:22-144.225.8.54:48660.service: Deactivated successfully. Jul 21 12:39:17.808954 kernel: kauditd_printk_skb: 73 callbacks suppressed Jul 21 12:39:17.809091 kernel: audit: type=1109 audit(1784637557.800:980): pid=6778 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:17.804000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@89-39-172.31.16.165:22-144.225.8.54:48660 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:17.816856 kernel: audit: type=1131 audit(1784637557.804:981): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@89-39-172.31.16.165:22-144.225.8.54:48660 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:17.874465 systemd[1]: Started sshd@90-40-172.31.16.165:22-144.225.8.54:60342.service - OpenSSH per-connection server daemon (144.225.8.54:60342). Jul 21 12:39:17.873000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@90-40-172.31.16.165:22-144.225.8.54:60342 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:17.882280 kernel: audit: type=1130 audit(1784637557.873:982): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@90-40-172.31.16.165:22-144.225.8.54:60342 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:18.204717 sshd[6784]: Connection closed by authenticating user root 144.225.8.54 port 60342 [preauth] Jul 21 12:39:18.205000 audit[6784]: AUDIT1109 pid=6784 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:18.212426 systemd[1]: sshd@90-40-172.31.16.165:22-144.225.8.54:60342.service: Deactivated successfully. Jul 21 12:39:18.212000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@90-40-172.31.16.165:22-144.225.8.54:60342 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:18.214374 kernel: audit: type=1109 audit(1784637558.205:983): pid=6784 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:18.214440 kernel: audit: type=1131 audit(1784637558.212:984): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@90-40-172.31.16.165:22-144.225.8.54:60342 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:18.282926 systemd[1]: Started sshd@91-41-172.31.16.165:22-144.225.8.54:60350.service - OpenSSH per-connection server daemon (144.225.8.54:60350). Jul 21 12:39:18.281000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@91-41-172.31.16.165:22-144.225.8.54:60350 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:18.293264 kernel: audit: type=1130 audit(1784637558.281:985): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@91-41-172.31.16.165:22-144.225.8.54:60350 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:18.608877 sshd[6794]: Connection closed by authenticating user root 144.225.8.54 port 60350 [preauth] Jul 21 12:39:18.608000 audit[6794]: AUDIT1109 pid=6794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:18.615324 systemd[1]: sshd@91-41-172.31.16.165:22-144.225.8.54:60350.service: Deactivated successfully. Jul 21 12:39:18.614000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@91-41-172.31.16.165:22-144.225.8.54:60350 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:18.622930 kernel: audit: type=1109 audit(1784637558.608:986): pid=6794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:18.623041 kernel: audit: type=1131 audit(1784637558.614:987): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@91-41-172.31.16.165:22-144.225.8.54:60350 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:18.684939 systemd[1]: Started sshd@92-42-172.31.16.165:22-144.225.8.54:60354.service - OpenSSH per-connection server daemon (144.225.8.54:60354). Jul 21 12:39:18.683000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@92-42-172.31.16.165:22-144.225.8.54:60354 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:18.693338 kernel: audit: type=1130 audit(1784637558.683:988): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@92-42-172.31.16.165:22-144.225.8.54:60354 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:18.844821 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount3589482627.mount: Deactivated successfully. Jul 21 12:39:19.025040 sshd[6800]: Connection closed by authenticating user root 144.225.8.54 port 60354 [preauth] Jul 21 12:39:19.025000 audit[6800]: AUDIT1109 pid=6800 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:19.034417 kernel: audit: type=1109 audit(1784637559.025:989): pid=6800 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:19.035611 systemd[1]: sshd@92-42-172.31.16.165:22-144.225.8.54:60354.service: Deactivated successfully. Jul 21 12:39:19.037000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@92-42-172.31.16.165:22-144.225.8.54:60354 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:19.104979 systemd[1]: Started sshd@93-4148-172.31.16.165:22-144.225.8.54:60356.service - OpenSSH per-connection server daemon (144.225.8.54:60356). Jul 21 12:39:19.104000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@93-4148-172.31.16.165:22-144.225.8.54:60356 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:19.440068 sshd[6810]: Connection closed by authenticating user root 144.225.8.54 port 60356 [preauth] Jul 21 12:39:19.440000 audit[6810]: AUDIT1109 pid=6810 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:19.448078 systemd[1]: sshd@93-4148-172.31.16.165:22-144.225.8.54:60356.service: Deactivated successfully. Jul 21 12:39:19.448000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@93-4148-172.31.16.165:22-144.225.8.54:60356 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:19.517847 systemd[1]: Started sshd@94-4149-172.31.16.165:22-144.225.8.54:60364.service - OpenSSH per-connection server daemon (144.225.8.54:60364). Jul 21 12:39:19.516000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@94-4149-172.31.16.165:22-144.225.8.54:60364 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:19.557327 containerd[2389]: time="2026-07-21T12:39:19.556715153Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/goldmane:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:19.562159 containerd[2389]: time="2026-07-21T12:39:19.562031297Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/goldmane:v3.32.1: active requests=1, bytes read=42999190" Jul 21 12:39:19.563941 containerd[2389]: time="2026-07-21T12:39:19.563769857Z" level=info msg="ImageCreate event name:\"sha256:591c3f5a623394ae1a2d906e82fd859ea23f51577a17b3ed4a45b5bfb04cf612\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:19.573166 containerd[2389]: time="2026-07-21T12:39:19.573066557Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/goldmane@sha256:9f05a289a8345e847362359570ad2706ccc8ff57e6e1bec4e72c93abaeff58f4\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:19.576338 containerd[2389]: time="2026-07-21T12:39:19.575525717Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/goldmane:v3.32.1\" with image id \"sha256:591c3f5a623394ae1a2d906e82fd859ea23f51577a17b3ed4a45b5bfb04cf612\", repo tag \"ghcr.io/flatcar/calico/goldmane:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/goldmane@sha256:9f05a289a8345e847362359570ad2706ccc8ff57e6e1bec4e72c93abaeff58f4\", size \"47949303\" in 4.394871226s" Jul 21 12:39:19.576590 containerd[2389]: time="2026-07-21T12:39:19.576294557Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/goldmane:v3.32.1\" returns image reference \"sha256:591c3f5a623394ae1a2d906e82fd859ea23f51577a17b3ed4a45b5bfb04cf612\"" Jul 21 12:39:19.580944 containerd[2389]: time="2026-07-21T12:39:19.580678697Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/apiserver:v3.32.1\"" Jul 21 12:39:19.588065 containerd[2389]: time="2026-07-21T12:39:19.587284745Z" level=info msg="CreateContainer within sandbox \"8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043\" for container name:\"goldmane\"" Jul 21 12:39:19.626823 containerd[2389]: time="2026-07-21T12:39:19.626716721Z" level=info msg="CreateContainer within sandbox \"8873c3294f99e4676d9bd96a1944dff04db07b1c931a399dc57d57df62369043\" for name:\"goldmane\" returns container id \"22fed56625bd488e78bedff6b5832c246667233784312bdbd9cfa83afc664417\"" Jul 21 12:39:19.628981 containerd[2389]: time="2026-07-21T12:39:19.628863185Z" level=info msg="StartContainer for \"22fed56625bd488e78bedff6b5832c246667233784312bdbd9cfa83afc664417\"" Jul 21 12:39:19.632927 containerd[2389]: time="2026-07-21T12:39:19.632624957Z" level=info msg="connecting to shim 22fed56625bd488e78bedff6b5832c246667233784312bdbd9cfa83afc664417" address="unix:///run/containerd/s/7aa86f7ececf34cd74682f0598f58ef38f741902e4406124b68c4b87b97bf516" protocol=ttrpc version=3 Jul 21 12:39:19.689627 systemd[1]: Started cri-containerd-22fed56625bd488e78bedff6b5832c246667233784312bdbd9cfa83afc664417.scope - libcontainer container 22fed56625bd488e78bedff6b5832c246667233784312bdbd9cfa83afc664417. Jul 21 12:39:19.738000 audit: BPF prog-id=266 op=LOAD Jul 21 12:39:19.740000 audit: BPF prog-id=267 op=LOAD Jul 21 12:39:19.740000 audit[6823]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=68a5cf41bf90 a2=98 a3=0 items=0 ppid=6101 pid=6823 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:19.740000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3232666564353636323562643438386537386265646666366235383332 Jul 21 12:39:19.741000 audit: BPF prog-id=267 op=UNLOAD Jul 21 12:39:19.741000 audit[6823]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6101 pid=6823 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:19.741000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3232666564353636323562643438386537386265646666366235383332 Jul 21 12:39:19.741000 audit: BPF prog-id=268 op=LOAD Jul 21 12:39:19.741000 audit[6823]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=68a5cf41c268 a2=98 a3=0 items=0 ppid=6101 pid=6823 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:19.741000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3232666564353636323562643438386537386265646666366235383332 Jul 21 12:39:19.741000 audit: BPF prog-id=269 op=LOAD Jul 21 12:39:19.741000 audit[6823]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=68a5cf41bfa8 a2=98 a3=0 items=0 ppid=6101 pid=6823 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:19.741000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3232666564353636323562643438386537386265646666366235383332 Jul 21 12:39:19.741000 audit: BPF prog-id=269 op=UNLOAD Jul 21 12:39:19.741000 audit[6823]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=6101 pid=6823 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:19.741000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3232666564353636323562643438386537386265646666366235383332 Jul 21 12:39:19.741000 audit: BPF prog-id=268 op=UNLOAD Jul 21 12:39:19.741000 audit[6823]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6101 pid=6823 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:19.741000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3232666564353636323562643438386537386265646666366235383332 Jul 21 12:39:19.742000 audit: BPF prog-id=270 op=LOAD Jul 21 12:39:19.742000 audit[6823]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=68a5cf41c4b8 a2=98 a3=0 items=0 ppid=6101 pid=6823 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:19.742000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3232666564353636323562643438386537386265646666366235383332 Jul 21 12:39:19.813927 containerd[2389]: time="2026-07-21T12:39:19.813398478Z" level=info msg="StartContainer for \"22fed56625bd488e78bedff6b5832c246667233784312bdbd9cfa83afc664417\" returns successfully" Jul 21 12:39:19.834807 sshd[6816]: Connection closed by authenticating user root 144.225.8.54 port 60364 [preauth] Jul 21 12:39:19.835000 audit[6816]: AUDIT1109 pid=6816 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:19.840348 systemd[1]: sshd@94-4149-172.31.16.165:22-144.225.8.54:60364.service: Deactivated successfully. Jul 21 12:39:19.841000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@94-4149-172.31.16.165:22-144.225.8.54:60364 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:19.915000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@95-4150-172.31.16.165:22-144.225.8.54:60368 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:19.916887 systemd[1]: Started sshd@95-4150-172.31.16.165:22-144.225.8.54:60368.service - OpenSSH per-connection server daemon (144.225.8.54:60368). Jul 21 12:39:20.057279 containerd[2389]: time="2026-07-21T12:39:20.057025707Z" level=info msg="ImageUpdate event name:\"ghcr.io/flatcar/calico/apiserver:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:20.059507 containerd[2389]: time="2026-07-21T12:39:20.059418807Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/apiserver:v3.32.1: active requests=0, bytes read=0" Jul 21 12:39:20.069544 containerd[2389]: time="2026-07-21T12:39:20.069478527Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/apiserver:v3.32.1\" with image id \"sha256:7927104786f4d9c3e94554376a5bd883ff48769e526cebab512a744e42536f4b\", repo tag \"ghcr.io/flatcar/calico/apiserver:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/apiserver@sha256:6c8b0e82ab9fc24e3d6734f470ff09ff034fda95e632da592891ea79f40e2c05\", size \"46859304\" in 488.74367ms" Jul 21 12:39:20.069544 containerd[2389]: time="2026-07-21T12:39:20.069539475Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/apiserver:v3.32.1\" returns image reference \"sha256:7927104786f4d9c3e94554376a5bd883ff48769e526cebab512a744e42536f4b\"" Jul 21 12:39:20.072007 containerd[2389]: time="2026-07-21T12:39:20.071963211Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/kube-controllers:v3.32.1\"" Jul 21 12:39:20.081393 containerd[2389]: time="2026-07-21T12:39:20.081335403Z" level=info msg="CreateContainer within sandbox \"fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d\" for container name:\"calico-apiserver\"" Jul 21 12:39:20.133661 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount4262281996.mount: Deactivated successfully. Jul 21 12:39:20.152101 containerd[2389]: time="2026-07-21T12:39:20.152025304Z" level=info msg="CreateContainer within sandbox \"fa422ae28a1b7bf4cdd30a8bab8bbac6abcb89d694f8454f9a70d037ac7b449d\" for name:\"calico-apiserver\" returns container id \"d311bdf20149299873bb47e7443971459784c25d0cfb5fe2937f515236d6d1dc\"" Jul 21 12:39:20.154433 containerd[2389]: time="2026-07-21T12:39:20.153551800Z" level=info msg="StartContainer for \"d311bdf20149299873bb47e7443971459784c25d0cfb5fe2937f515236d6d1dc\"" Jul 21 12:39:20.158776 containerd[2389]: time="2026-07-21T12:39:20.158721244Z" level=info msg="connecting to shim d311bdf20149299873bb47e7443971459784c25d0cfb5fe2937f515236d6d1dc" address="unix:///run/containerd/s/8945df67554362404de5b5b1b5e00929c059c5df475077268516219eddafc2d9" protocol=ttrpc version=3 Jul 21 12:39:20.181940 sshd[6857]: Invalid user user from 144.225.8.54 port 60368 Jul 21 12:39:20.233980 systemd[1]: Started cri-containerd-d311bdf20149299873bb47e7443971459784c25d0cfb5fe2937f515236d6d1dc.scope - libcontainer container d311bdf20149299873bb47e7443971459784c25d0cfb5fe2937f515236d6d1dc. Jul 21 12:39:20.245388 sshd[6857]: Connection closed by invalid user user 144.225.8.54 port 60368 [preauth] Jul 21 12:39:20.252000 audit[6857]: AUDIT1109 pid=6857 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:20.257886 systemd[1]: sshd@95-4150-172.31.16.165:22-144.225.8.54:60368.service: Deactivated successfully. Jul 21 12:39:20.260000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@95-4150-172.31.16.165:22-144.225.8.54:60368 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:20.314000 audit[6882]: NETFILTER_CFG table=filter:131 family=2 entries=12 op=nft_register_rule pid=6882 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:20.314000 audit[6882]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=4504 a0=3 a1=ffffd770e7b0 a2=0 a3=1 items=0 ppid=4148 pid=6882 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:20.314000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:20.320000 audit[6882]: NETFILTER_CFG table=nat:132 family=2 entries=22 op=nft_register_rule pid=6882 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:20.320000 audit[6882]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=6540 a0=3 a1=ffffd770e7b0 a2=0 a3=1 items=0 ppid=4148 pid=6882 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:20.320000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:20.325000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@96-4151-172.31.16.165:22-144.225.8.54:60378 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:20.326020 systemd[1]: Started sshd@96-4151-172.31.16.165:22-144.225.8.54:60378.service - OpenSSH per-connection server daemon (144.225.8.54:60378). Jul 21 12:39:20.336000 audit: BPF prog-id=271 op=LOAD Jul 21 12:39:20.341000 audit: BPF prog-id=272 op=LOAD Jul 21 12:39:20.341000 audit[6860]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2badd527bf90 a2=98 a3=0 items=0 ppid=6144 pid=6860 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:20.341000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6433313162646632303134393239393837336262343765373434333937 Jul 21 12:39:20.341000 audit: BPF prog-id=272 op=UNLOAD Jul 21 12:39:20.341000 audit[6860]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6144 pid=6860 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:20.341000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6433313162646632303134393239393837336262343765373434333937 Jul 21 12:39:20.342000 audit: BPF prog-id=273 op=LOAD Jul 21 12:39:20.342000 audit[6860]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2badd527c268 a2=98 a3=0 items=0 ppid=6144 pid=6860 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:20.342000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6433313162646632303134393239393837336262343765373434333937 Jul 21 12:39:20.342000 audit: BPF prog-id=274 op=LOAD Jul 21 12:39:20.342000 audit[6860]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=2badd527bfa8 a2=98 a3=0 items=0 ppid=6144 pid=6860 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:20.342000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6433313162646632303134393239393837336262343765373434333937 Jul 21 12:39:20.342000 audit: BPF prog-id=274 op=UNLOAD Jul 21 12:39:20.342000 audit[6860]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=6144 pid=6860 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:20.342000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6433313162646632303134393239393837336262343765373434333937 Jul 21 12:39:20.342000 audit: BPF prog-id=273 op=UNLOAD Jul 21 12:39:20.342000 audit[6860]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6144 pid=6860 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:20.342000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6433313162646632303134393239393837336262343765373434333937 Jul 21 12:39:20.342000 audit: BPF prog-id=275 op=LOAD Jul 21 12:39:20.342000 audit[6860]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=2badd527c4b8 a2=98 a3=0 items=0 ppid=6144 pid=6860 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:20.342000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6433313162646632303134393239393837336262343765373434333937 Jul 21 12:39:20.592575 containerd[2389]: time="2026-07-21T12:39:20.592294446Z" level=info msg="StartContainer for \"d311bdf20149299873bb47e7443971459784c25d0cfb5fe2937f515236d6d1dc\" returns successfully" Jul 21 12:39:20.654067 sshd[6883]: Invalid user user from 144.225.8.54 port 60378 Jul 21 12:39:20.715407 sshd[6883]: Connection closed by invalid user user 144.225.8.54 port 60378 [preauth] Jul 21 12:39:20.714000 audit[6883]: AUDIT1109 pid=6883 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:20.721524 systemd[1]: sshd@96-4151-172.31.16.165:22-144.225.8.54:60378.service: Deactivated successfully. Jul 21 12:39:20.723000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@96-4151-172.31.16.165:22-144.225.8.54:60378 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:20.768000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@97-43-172.31.16.165:22-20.76.1.115:53026 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:20.768775 systemd[1]: Started sshd@97-43-172.31.16.165:22-20.76.1.115:53026.service - OpenSSH per-connection server daemon (20.76.1.115:53026). Jul 21 12:39:20.799015 systemd[1]: Started sshd@98-4152-172.31.16.165:22-144.225.8.54:60382.service - OpenSSH per-connection server daemon (144.225.8.54:60382). Jul 21 12:39:20.798000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@98-4152-172.31.16.165:22-144.225.8.54:60382 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:21.086065 sshd[6928]: Invalid user user from 144.225.8.54 port 60382 Jul 21 12:39:21.146714 sshd[6928]: Connection closed by invalid user user 144.225.8.54 port 60382 [preauth] Jul 21 12:39:21.147000 audit[6928]: AUDIT1109 pid=6928 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:21.154774 systemd[1]: sshd@98-4152-172.31.16.165:22-144.225.8.54:60382.service: Deactivated successfully. Jul 21 12:39:21.155000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@98-4152-172.31.16.165:22-144.225.8.54:60382 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:21.213708 kubelet[4002]: I0721 12:39:21.213477 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="calico-system/calico-apiserver-6b46596bdc-djqpg" podStartSLOduration=44.351147463 podStartE2EDuration="55.213449861s" podCreationTimestamp="2026-07-21 12:38:26 +0000 UTC" firstStartedPulling="2026-07-21 12:39:09.208472369 +0000 UTC m=+66.161489705" lastFinishedPulling="2026-07-21 12:39:20.070774779 +0000 UTC m=+77.023792103" observedRunningTime="2026-07-21 12:39:21.204594257 +0000 UTC m=+78.157611617" watchObservedRunningTime="2026-07-21 12:39:21.213449861 +0000 UTC m=+78.166467221" Jul 21 12:39:21.215591 kubelet[4002]: I0721 12:39:21.214999 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="calico-system/goldmane-6ccc4cdfd5-djlw8" podStartSLOduration=44.702077433 podStartE2EDuration="55.214821773s" podCreationTimestamp="2026-07-21 12:38:26 +0000 UTC" firstStartedPulling="2026-07-21 12:39:09.066589541 +0000 UTC m=+66.019606877" lastFinishedPulling="2026-07-21 12:39:19.579333809 +0000 UTC m=+76.532351217" observedRunningTime="2026-07-21 12:39:20.251536288 +0000 UTC m=+77.204553624" watchObservedRunningTime="2026-07-21 12:39:21.214821773 +0000 UTC m=+78.167839181" Jul 21 12:39:21.245000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@99-4153-172.31.16.165:22-144.225.8.54:60394 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:21.246478 systemd[1]: Started sshd@99-4153-172.31.16.165:22-144.225.8.54:60394.service - OpenSSH per-connection server daemon (144.225.8.54:60394). Jul 21 12:39:21.383000 audit[6965]: NETFILTER_CFG table=filter:133 family=2 entries=12 op=nft_register_rule pid=6965 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:21.383000 audit[6965]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=4504 a0=3 a1=ffffe1cc4e70 a2=0 a3=1 items=0 ppid=4148 pid=6965 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:21.383000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:21.393000 audit[6965]: NETFILTER_CFG table=nat:134 family=2 entries=22 op=nft_register_rule pid=6965 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:21.393000 audit[6965]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=6540 a0=3 a1=ffffe1cc4e70 a2=0 a3=1 items=0 ppid=4148 pid=6965 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:21.393000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:21.671451 sshd[6955]: Invalid user user from 144.225.8.54 port 60394 Jul 21 12:39:21.677000 audit[6926]: AUDIT1101 pid=6926 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:21.679609 sshd[6926]: Accepted publickey for core from 20.76.1.115 port 53026 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:39:21.683000 audit[6926]: AUDIT1103 pid=6926 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:21.687000 audit[6926]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=fffff9920c70 a2=3 a3=0 items=0 ppid=1 pid=6926 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:21.687000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:39:21.703453 sshd-session[6926]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:39:21.726662 systemd-logind[2347]: New session '9' of user 'core' with class 'user' and type 'tty'. Jul 21 12:39:21.733391 systemd[1]: Started session-9.scope - Session 9 of User core. Jul 21 12:39:21.738803 sshd[6955]: Connection closed by invalid user user 144.225.8.54 port 60394 [preauth] Jul 21 12:39:21.740000 audit[6955]: AUDIT1109 pid=6955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:21.756015 systemd[1]: sshd@99-4153-172.31.16.165:22-144.225.8.54:60394.service: Deactivated successfully. Jul 21 12:39:21.758000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@99-4153-172.31.16.165:22-144.225.8.54:60394 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:21.768000 audit[6926]: AUDIT1105 pid=6926 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:21.777000 audit[6974]: AUDIT1103 pid=6974 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:21.814000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@100-4154-172.31.16.165:22-144.225.8.54:60400 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:21.815001 systemd[1]: Started sshd@100-4154-172.31.16.165:22-144.225.8.54:60400.service - OpenSSH per-connection server daemon (144.225.8.54:60400). Jul 21 12:39:22.167519 kubelet[4002]: I0721 12:39:22.167416 4002 prober_manager.go:312] "Failed to trigger a manual run" probe="Readiness" Jul 21 12:39:22.171960 sshd[6976]: Invalid user user from 144.225.8.54 port 60400 Jul 21 12:39:22.236457 sshd[6976]: Connection closed by invalid user user 144.225.8.54 port 60400 [preauth] Jul 21 12:39:22.238000 audit[6976]: AUDIT1109 pid=6976 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:22.249338 systemd[1]: sshd@100-4154-172.31.16.165:22-144.225.8.54:60400.service: Deactivated successfully. Jul 21 12:39:22.250000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@100-4154-172.31.16.165:22-144.225.8.54:60400 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:22.330135 systemd[1]: Started sshd@101-44-172.31.16.165:22-144.225.8.54:60416.service - OpenSSH per-connection server daemon (144.225.8.54:60416). Jul 21 12:39:22.329000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@101-44-172.31.16.165:22-144.225.8.54:60416 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:22.539335 sshd[6974]: Connection closed by 20.76.1.115 port 53026 Jul 21 12:39:22.543544 sshd-session[6926]: pam_unix(sshd:session): session closed for user core Jul 21 12:39:22.544000 audit[6926]: AUDIT1106 pid=6926 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:22.544000 audit[6926]: AUDIT1104 pid=6926 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:22.554502 systemd[1]: sshd@97-43-172.31.16.165:22-20.76.1.115:53026.service: Deactivated successfully. Jul 21 12:39:22.554000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@97-43-172.31.16.165:22-20.76.1.115:53026 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:22.562699 systemd[1]: session-9.scope: Deactivated successfully. Jul 21 12:39:22.571738 systemd-logind[2347]: Session 9 logged out. Waiting for processes to exit. Jul 21 12:39:22.578722 systemd-logind[2347]: Removed session 9. Jul 21 12:39:22.700693 sshd[7006]: Invalid user user from 144.225.8.54 port 60416 Jul 21 12:39:22.766248 sshd[7006]: Connection closed by invalid user user 144.225.8.54 port 60416 [preauth] Jul 21 12:39:22.766000 audit[7006]: AUDIT1109 pid=7006 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:22.771748 systemd[1]: sshd@101-44-172.31.16.165:22-144.225.8.54:60416.service: Deactivated successfully. Jul 21 12:39:22.774000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@101-44-172.31.16.165:22-144.225.8.54:60416 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:22.840000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@102-45-172.31.16.165:22-144.225.8.54:60432 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:22.841951 systemd[1]: Started sshd@102-45-172.31.16.165:22-144.225.8.54:60432.service - OpenSSH per-connection server daemon (144.225.8.54:60432). Jul 21 12:39:22.844918 kernel: kauditd_printk_skb: 92 callbacks suppressed Jul 21 12:39:22.844997 kernel: audit: type=1130 audit(1784637562.840:1044): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@102-45-172.31.16.165:22-144.225.8.54:60432 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:23.118500 sshd[7033]: Invalid user user from 144.225.8.54 port 60432 Jul 21 12:39:23.182135 sshd[7033]: Connection closed by invalid user user 144.225.8.54 port 60432 [preauth] Jul 21 12:39:23.181000 audit[7033]: AUDIT1109 pid=7033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:23.190661 systemd[1]: sshd@102-45-172.31.16.165:22-144.225.8.54:60432.service: Deactivated successfully. Jul 21 12:39:23.189000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@102-45-172.31.16.165:22-144.225.8.54:60432 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:23.198430 kernel: audit: type=1109 audit(1784637563.181:1045): pid=7033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:23.198541 kernel: audit: type=1131 audit(1784637563.189:1046): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@102-45-172.31.16.165:22-144.225.8.54:60432 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:23.262000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@103-4155-172.31.16.165:22-144.225.8.54:60438 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:23.263801 systemd[1]: Started sshd@103-4155-172.31.16.165:22-144.225.8.54:60438.service - OpenSSH per-connection server daemon (144.225.8.54:60438). Jul 21 12:39:23.276234 kernel: audit: type=1130 audit(1784637563.262:1047): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@103-4155-172.31.16.165:22-144.225.8.54:60438 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:23.573055 sshd[7040]: Invalid user user from 144.225.8.54 port 60438 Jul 21 12:39:23.633952 sshd[7040]: Connection closed by invalid user user 144.225.8.54 port 60438 [preauth] Jul 21 12:39:23.633000 audit[7040]: AUDIT1109 pid=7040 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:23.643435 kernel: audit: type=1109 audit(1784637563.633:1048): pid=7040 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:23.643904 systemd[1]: sshd@103-4155-172.31.16.165:22-144.225.8.54:60438.service: Deactivated successfully. Jul 21 12:39:23.645000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@103-4155-172.31.16.165:22-144.225.8.54:60438 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:23.656257 kernel: audit: type=1131 audit(1784637563.645:1049): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@103-4155-172.31.16.165:22-144.225.8.54:60438 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:23.728000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@104-4156-172.31.16.165:22-144.225.8.54:60440 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:23.729522 systemd[1]: Started sshd@104-4156-172.31.16.165:22-144.225.8.54:60440.service - OpenSSH per-connection server daemon (144.225.8.54:60440). Jul 21 12:39:23.740247 kernel: audit: type=1130 audit(1784637563.728:1050): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@104-4156-172.31.16.165:22-144.225.8.54:60440 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:24.093877 sshd[7046]: Invalid user user from 144.225.8.54 port 60440 Jul 21 12:39:24.158263 sshd[7046]: Connection closed by invalid user user 144.225.8.54 port 60440 [preauth] Jul 21 12:39:24.158000 audit[7046]: AUDIT1109 pid=7046 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:24.164752 systemd[1]: sshd@104-4156-172.31.16.165:22-144.225.8.54:60440.service: Deactivated successfully. Jul 21 12:39:24.164000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@104-4156-172.31.16.165:22-144.225.8.54:60440 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:24.173461 kernel: audit: type=1109 audit(1784637564.158:1051): pid=7046 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:24.173835 kernel: audit: type=1131 audit(1784637564.164:1052): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@104-4156-172.31.16.165:22-144.225.8.54:60440 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:24.242000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@105-46-172.31.16.165:22-144.225.8.54:60444 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:24.243835 systemd[1]: Started sshd@105-46-172.31.16.165:22-144.225.8.54:60444.service - OpenSSH per-connection server daemon (144.225.8.54:60444). Jul 21 12:39:24.255823 kernel: audit: type=1130 audit(1784637564.242:1053): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@105-46-172.31.16.165:22-144.225.8.54:60444 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:24.617441 sshd[7053]: Invalid user user from 144.225.8.54 port 60444 Jul 21 12:39:24.681974 sshd[7053]: Connection closed by invalid user user 144.225.8.54 port 60444 [preauth] Jul 21 12:39:24.682000 audit[7053]: AUDIT1109 pid=7053 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:24.689942 systemd[1]: sshd@105-46-172.31.16.165:22-144.225.8.54:60444.service: Deactivated successfully. Jul 21 12:39:24.689000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@105-46-172.31.16.165:22-144.225.8.54:60444 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:24.769854 systemd[1]: Started sshd@106-4157-172.31.16.165:22-144.225.8.54:60450.service - OpenSSH per-connection server daemon (144.225.8.54:60450). Jul 21 12:39:24.768000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@106-4157-172.31.16.165:22-144.225.8.54:60450 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:24.935437 containerd[2389]: time="2026-07-21T12:39:24.935160119Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/kube-controllers:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:24.945850 containerd[2389]: time="2026-07-21T12:39:24.945727895Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/kube-controllers:v3.32.1: active requests=1, bytes read=37748736" Jul 21 12:39:24.954515 containerd[2389]: time="2026-07-21T12:39:24.954441971Z" level=info msg="ImageCreate event name:\"sha256:964b0a9d69c41adf325b8da5d077bc6ab674d157a81775afa8b9a8513daeee1a\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:24.971040 containerd[2389]: time="2026-07-21T12:39:24.970928184Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/kube-controllers@sha256:f31c3386b00ff3b892f68627c3efba4d3bda7568a1631f991fbaab3e36eb830e\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:24.980410 containerd[2389]: time="2026-07-21T12:39:24.979649628Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/kube-controllers:v3.32.1\" with image id \"sha256:964b0a9d69c41adf325b8da5d077bc6ab674d157a81775afa8b9a8513daeee1a\", repo tag \"ghcr.io/flatcar/calico/kube-controllers:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/kube-controllers@sha256:f31c3386b00ff3b892f68627c3efba4d3bda7568a1631f991fbaab3e36eb830e\", size \"55968036\" in 4.907378413s" Jul 21 12:39:24.980410 containerd[2389]: time="2026-07-21T12:39:24.979711740Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/kube-controllers:v3.32.1\" returns image reference \"sha256:964b0a9d69c41adf325b8da5d077bc6ab674d157a81775afa8b9a8513daeee1a\"" Jul 21 12:39:24.987886 containerd[2389]: time="2026-07-21T12:39:24.987836088Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/node-driver-registrar:v3.32.1\"" Jul 21 12:39:25.044728 containerd[2389]: time="2026-07-21T12:39:25.044676968Z" level=info msg="CreateContainer within sandbox \"e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4\" for container name:\"calico-kube-controllers\"" Jul 21 12:39:25.109590 sshd[7059]: Invalid user user from 144.225.8.54 port 60450 Jul 21 12:39:25.122417 containerd[2389]: time="2026-07-21T12:39:25.122353184Z" level=info msg="CreateContainer within sandbox \"e9f71ab695c16b2b040c1aaab4630540941f9bc262304d1554fab0736696b3e4\" for name:\"calico-kube-controllers\" returns container id \"a47cf7d61884edb662f2ecaa055d8bacb423bebb0b76db93564e786246efc6f8\"" Jul 21 12:39:25.124020 containerd[2389]: time="2026-07-21T12:39:25.123964088Z" level=info msg="StartContainer for \"a47cf7d61884edb662f2ecaa055d8bacb423bebb0b76db93564e786246efc6f8\"" Jul 21 12:39:25.127661 containerd[2389]: time="2026-07-21T12:39:25.127530716Z" level=info msg="connecting to shim a47cf7d61884edb662f2ecaa055d8bacb423bebb0b76db93564e786246efc6f8" address="unix:///run/containerd/s/444b2f397d740223926cc462f0d80167124910910d96f175b87325709dea04f5" protocol=ttrpc version=3 Jul 21 12:39:25.171996 sshd[7059]: Connection closed by invalid user user 144.225.8.54 port 60450 [preauth] Jul 21 12:39:25.175000 audit[7059]: AUDIT1109 pid=7059 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:25.182604 systemd[1]: Started cri-containerd-a47cf7d61884edb662f2ecaa055d8bacb423bebb0b76db93564e786246efc6f8.scope - libcontainer container a47cf7d61884edb662f2ecaa055d8bacb423bebb0b76db93564e786246efc6f8. Jul 21 12:39:25.183568 systemd[1]: sshd@106-4157-172.31.16.165:22-144.225.8.54:60450.service: Deactivated successfully. Jul 21 12:39:25.187000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@106-4157-172.31.16.165:22-144.225.8.54:60450 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:25.256382 systemd[1]: Started sshd@107-47-172.31.16.165:22-144.225.8.54:60464.service - OpenSSH per-connection server daemon (144.225.8.54:60464). Jul 21 12:39:25.255000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@107-47-172.31.16.165:22-144.225.8.54:60464 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:25.279000 audit: BPF prog-id=276 op=LOAD Jul 21 12:39:25.281000 audit: BPF prog-id=277 op=LOAD Jul 21 12:39:25.281000 audit[7064]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=56e58309bf90 a2=98 a3=0 items=0 ppid=6549 pid=7064 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:25.281000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6134376366376436313838346564623636326632656361613035356438 Jul 21 12:39:25.281000 audit: BPF prog-id=277 op=UNLOAD Jul 21 12:39:25.281000 audit[7064]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6549 pid=7064 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:25.281000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6134376366376436313838346564623636326632656361613035356438 Jul 21 12:39:25.281000 audit: BPF prog-id=278 op=LOAD Jul 21 12:39:25.281000 audit[7064]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=56e58309c268 a2=98 a3=0 items=0 ppid=6549 pid=7064 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:25.281000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6134376366376436313838346564623636326632656361613035356438 Jul 21 12:39:25.282000 audit: BPF prog-id=279 op=LOAD Jul 21 12:39:25.282000 audit[7064]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=56e58309bfa8 a2=98 a3=0 items=0 ppid=6549 pid=7064 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:25.282000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6134376366376436313838346564623636326632656361613035356438 Jul 21 12:39:25.282000 audit: BPF prog-id=279 op=UNLOAD Jul 21 12:39:25.282000 audit[7064]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=6549 pid=7064 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:25.282000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6134376366376436313838346564623636326632656361613035356438 Jul 21 12:39:25.282000 audit: BPF prog-id=278 op=UNLOAD Jul 21 12:39:25.282000 audit[7064]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=6549 pid=7064 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:25.282000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6134376366376436313838346564623636326632656361613035356438 Jul 21 12:39:25.282000 audit: BPF prog-id=280 op=LOAD Jul 21 12:39:25.282000 audit[7064]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=56e58309c4b8 a2=98 a3=0 items=0 ppid=6549 pid=7064 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:25.282000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6134376366376436313838346564623636326632656361613035356438 Jul 21 12:39:25.443324 containerd[2389]: time="2026-07-21T12:39:25.442760206Z" level=info msg="StartContainer for \"a47cf7d61884edb662f2ecaa055d8bacb423bebb0b76db93564e786246efc6f8\" returns successfully" Jul 21 12:39:25.536723 sshd[7088]: Invalid user user from 144.225.8.54 port 60464 Jul 21 12:39:25.599362 sshd[7088]: Connection closed by invalid user user 144.225.8.54 port 60464 [preauth] Jul 21 12:39:25.599000 audit[7088]: AUDIT1109 pid=7088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:25.604404 systemd[1]: sshd@107-47-172.31.16.165:22-144.225.8.54:60464.service: Deactivated successfully. Jul 21 12:39:25.606000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@107-47-172.31.16.165:22-144.225.8.54:60464 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:25.681000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@108-4158-172.31.16.165:22-144.225.8.54:60478 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:25.682811 systemd[1]: Started sshd@108-4158-172.31.16.165:22-144.225.8.54:60478.service - OpenSSH per-connection server daemon (144.225.8.54:60478). Jul 21 12:39:25.976596 sshd[7112]: Invalid user user from 144.225.8.54 port 60478 Jul 21 12:39:26.039786 sshd[7112]: Connection closed by invalid user user 144.225.8.54 port 60478 [preauth] Jul 21 12:39:26.040000 audit[7112]: AUDIT1109 pid=7112 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:26.044993 systemd[1]: sshd@108-4158-172.31.16.165:22-144.225.8.54:60478.service: Deactivated successfully. Jul 21 12:39:26.047000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@108-4158-172.31.16.165:22-144.225.8.54:60478 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:26.119000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@109-48-172.31.16.165:22-144.225.8.54:60482 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:26.120442 systemd[1]: Started sshd@109-48-172.31.16.165:22-144.225.8.54:60482.service - OpenSSH per-connection server daemon (144.225.8.54:60482). Jul 21 12:39:26.461284 sshd[7144]: Invalid user user from 144.225.8.54 port 60482 Jul 21 12:39:26.494245 kubelet[4002]: I0721 12:39:26.493514 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="calico-system/calico-kube-controllers-cbf695f-b4zcr" podStartSLOduration=44.058494405 podStartE2EDuration="56.493486727s" podCreationTimestamp="2026-07-21 12:38:30 +0000 UTC" firstStartedPulling="2026-07-21 12:39:12.552501262 +0000 UTC m=+69.505518598" lastFinishedPulling="2026-07-21 12:39:24.987493584 +0000 UTC m=+81.940510920" observedRunningTime="2026-07-21 12:39:26.326129266 +0000 UTC m=+83.279146614" watchObservedRunningTime="2026-07-21 12:39:26.493486727 +0000 UTC m=+83.446504123" Jul 21 12:39:26.523519 sshd[7144]: Connection closed by invalid user user 144.225.8.54 port 60482 [preauth] Jul 21 12:39:26.522000 audit[7144]: AUDIT1109 pid=7144 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:26.528512 systemd[1]: sshd@109-48-172.31.16.165:22-144.225.8.54:60482.service: Deactivated successfully. Jul 21 12:39:26.529000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@109-48-172.31.16.165:22-144.225.8.54:60482 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:26.599000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@110-4159-172.31.16.165:22-144.225.8.54:60484 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:26.600609 systemd[1]: Started sshd@110-4159-172.31.16.165:22-144.225.8.54:60484.service - OpenSSH per-connection server daemon (144.225.8.54:60484). Jul 21 12:39:26.868240 sshd[7178]: Invalid user user from 144.225.8.54 port 60484 Jul 21 12:39:26.929579 sshd[7178]: Connection closed by invalid user user 144.225.8.54 port 60484 [preauth] Jul 21 12:39:26.930000 audit[7178]: AUDIT1109 pid=7178 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:26.936117 systemd[1]: sshd@110-4159-172.31.16.165:22-144.225.8.54:60484.service: Deactivated successfully. Jul 21 12:39:26.939000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@110-4159-172.31.16.165:22-144.225.8.54:60484 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:27.014000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@111-49-172.31.16.165:22-144.225.8.54:60496 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:27.015132 systemd[1]: Started sshd@111-49-172.31.16.165:22-144.225.8.54:60496.service - OpenSSH per-connection server daemon (144.225.8.54:60496). Jul 21 12:39:27.381335 sshd[7188]: Invalid user user from 144.225.8.54 port 60496 Jul 21 12:39:27.443445 sshd[7188]: Connection closed by invalid user user 144.225.8.54 port 60496 [preauth] Jul 21 12:39:27.443000 audit[7188]: AUDIT1109 pid=7188 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:27.448531 systemd[1]: sshd@111-49-172.31.16.165:22-144.225.8.54:60496.service: Deactivated successfully. Jul 21 12:39:27.450015 containerd[2389]: time="2026-07-21T12:39:27.449570856Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/node-driver-registrar:v3.32.1\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:27.449000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@111-49-172.31.16.165:22-144.225.8.54:60496 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:27.455837 containerd[2389]: time="2026-07-21T12:39:27.455708700Z" level=info msg="stop pulling image ghcr.io/flatcar/calico/node-driver-registrar:v3.32.1: active requests=1, bytes read=6291456" Jul 21 12:39:27.458701 containerd[2389]: time="2026-07-21T12:39:27.458458476Z" level=info msg="ImageCreate event name:\"sha256:7f1d01d9551510191a8bc51fc5a55de756f4bd1c1f85973dcbd3e892adf717a0\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:27.470228 containerd[2389]: time="2026-07-21T12:39:27.468871200Z" level=info msg="ImageCreate event name:\"ghcr.io/flatcar/calico/node-driver-registrar@sha256:32f7936f9c880fce16a4087dde65de23d2fabefbdc4702c812e0e9dc573c3d3a\" labels:{key:\"io.cri-containerd.image\" value:\"managed\"}" Jul 21 12:39:27.472851 containerd[2389]: time="2026-07-21T12:39:27.472751736Z" level=info msg="Pulled image \"ghcr.io/flatcar/calico/node-driver-registrar:v3.32.1\" with image id \"sha256:7f1d01d9551510191a8bc51fc5a55de756f4bd1c1f85973dcbd3e892adf717a0\", repo tag \"ghcr.io/flatcar/calico/node-driver-registrar:v3.32.1\", repo digest \"ghcr.io/flatcar/calico/node-driver-registrar@sha256:32f7936f9c880fce16a4087dde65de23d2fabefbdc4702c812e0e9dc573c3d3a\", size \"15092803\" in 2.4839487s" Jul 21 12:39:27.473062 containerd[2389]: time="2026-07-21T12:39:27.473030580Z" level=info msg="PullImage \"ghcr.io/flatcar/calico/node-driver-registrar:v3.32.1\" returns image reference \"sha256:7f1d01d9551510191a8bc51fc5a55de756f4bd1c1f85973dcbd3e892adf717a0\"" Jul 21 12:39:27.482659 containerd[2389]: time="2026-07-21T12:39:27.482611356Z" level=info msg="CreateContainer within sandbox \"336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e\" for container name:\"csi-node-driver-registrar\"" Jul 21 12:39:27.526000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@112-4160-172.31.16.165:22-144.225.8.54:60504 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:27.526166 systemd[1]: Started sshd@112-4160-172.31.16.165:22-144.225.8.54:60504.service - OpenSSH per-connection server daemon (144.225.8.54:60504). Jul 21 12:39:27.547485 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount2401057340.mount: Deactivated successfully. Jul 21 12:39:27.600851 containerd[2389]: time="2026-07-21T12:39:27.600525517Z" level=info msg="CreateContainer within sandbox \"336cbfc37abd7f6389eec02472e12c41ebda9134c1ba86c22ec73d07ebd0645e\" for name:\"csi-node-driver-registrar\" returns container id \"63bfbea4a64108ab174e1fefe607bd17bc040eafcba475df678c151e6b949534\"" Jul 21 12:39:27.603887 containerd[2389]: time="2026-07-21T12:39:27.603821485Z" level=info msg="StartContainer for \"63bfbea4a64108ab174e1fefe607bd17bc040eafcba475df678c151e6b949534\"" Jul 21 12:39:27.612451 containerd[2389]: time="2026-07-21T12:39:27.612335977Z" level=info msg="connecting to shim 63bfbea4a64108ab174e1fefe607bd17bc040eafcba475df678c151e6b949534" address="unix:///run/containerd/s/4b17f696d5f099a854edff7db3a04f9a670cb9817840980ffedb2fe99f11e712" protocol=ttrpc version=3 Jul 21 12:39:27.670771 systemd[1]: Started cri-containerd-63bfbea4a64108ab174e1fefe607bd17bc040eafcba475df678c151e6b949534.scope - libcontainer container 63bfbea4a64108ab174e1fefe607bd17bc040eafcba475df678c151e6b949534. Jul 21 12:39:27.727000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@113-50-172.31.16.165:22-20.76.1.115:36092 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:27.728838 systemd[1]: Started sshd@113-50-172.31.16.165:22-20.76.1.115:36092.service - OpenSSH per-connection server daemon (20.76.1.115:36092). Jul 21 12:39:27.847839 sshd[7194]: Invalid user user from 144.225.8.54 port 60504 Jul 21 12:39:27.887000 audit: BPF prog-id=281 op=LOAD Jul 21 12:39:27.890162 kernel: kauditd_printk_skb: 44 callbacks suppressed Jul 21 12:39:27.890278 kernel: audit: type=1334 audit(1784637567.887:1084): prog-id=281 op=LOAD Jul 21 12:39:27.887000 audit[7196]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=781296e0e268 a2=98 a3=0 items=0 ppid=6041 pid=7196 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:27.898140 kernel: audit: type=1300 audit(1784637567.887:1084): arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=781296e0e268 a2=98 a3=0 items=0 ppid=6041 pid=7196 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:27.887000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3633626662656134613634313038616231373465316665666536303762 Jul 21 12:39:27.905865 kernel: audit: type=1327 audit(1784637567.887:1084): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3633626662656134613634313038616231373465316665666536303762 Jul 21 12:39:27.888000 audit: BPF prog-id=282 op=LOAD Jul 21 12:39:27.911184 kernel: audit: type=1334 audit(1784637567.888:1085): prog-id=282 op=LOAD Jul 21 12:39:27.912507 sshd[7194]: Connection closed by invalid user user 144.225.8.54 port 60504 [preauth] Jul 21 12:39:27.888000 audit[7196]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=781296e0dfa8 a2=98 a3=0 items=0 ppid=6041 pid=7196 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:27.919326 kernel: audit: type=1300 audit(1784637567.888:1085): arch=c00000b7 syscall=280 success=yes exit=21 a0=5 a1=781296e0dfa8 a2=98 a3=0 items=0 ppid=6041 pid=7196 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:27.921784 systemd[1]: sshd@112-4160-172.31.16.165:22-144.225.8.54:60504.service: Deactivated successfully. Jul 21 12:39:27.888000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3633626662656134613634313038616231373465316665666536303762 Jul 21 12:39:27.932053 kernel: audit: type=1327 audit(1784637567.888:1085): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3633626662656134613634313038616231373465316665666536303762 Jul 21 12:39:27.890000 audit: BPF prog-id=282 op=UNLOAD Jul 21 12:39:27.944934 kernel: audit: type=1334 audit(1784637567.890:1086): prog-id=282 op=UNLOAD Jul 21 12:39:27.890000 audit[7196]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6041 pid=7196 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:27.951331 kernel: audit: type=1300 audit(1784637567.890:1086): arch=c00000b7 syscall=57 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=6041 pid=7196 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:27.890000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3633626662656134613634313038616231373465316665666536303762 Jul 21 12:39:27.961191 kernel: audit: type=1327 audit(1784637567.890:1086): proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3633626662656134613634313038616231373465316665666536303762 Jul 21 12:39:27.891000 audit: BPF prog-id=281 op=UNLOAD Jul 21 12:39:27.965754 kernel: audit: type=1334 audit(1784637567.891:1087): prog-id=281 op=UNLOAD Jul 21 12:39:27.891000 audit[7196]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=13 a1=0 a2=0 a3=0 items=0 ppid=6041 pid=7196 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:27.891000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3633626662656134613634313038616231373465316665666536303762 Jul 21 12:39:27.891000 audit: BPF prog-id=283 op=LOAD Jul 21 12:39:27.891000 audit[7196]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=19 a0=5 a1=781296e0e4b8 a2=98 a3=0 items=0 ppid=6041 pid=7196 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:27.891000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3633626662656134613634313038616231373465316665666536303762 Jul 21 12:39:27.912000 audit[7194]: AUDIT1109 pid=7194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:27.921000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@112-4160-172.31.16.165:22-144.225.8.54:60504 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:27.986000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@114-51-172.31.16.165:22-144.225.8.54:44374 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:27.987826 systemd[1]: Started sshd@114-51-172.31.16.165:22-144.225.8.54:44374.service - OpenSSH per-connection server daemon (144.225.8.54:44374). Jul 21 12:39:28.078264 containerd[2389]: time="2026-07-21T12:39:28.077352791Z" level=info msg="StartContainer for \"63bfbea4a64108ab174e1fefe607bd17bc040eafcba475df678c151e6b949534\" returns successfully" Jul 21 12:39:28.309184 sshd[7229]: Invalid user user from 144.225.8.54 port 44374 Jul 21 12:39:28.372070 sshd[7229]: Connection closed by invalid user user 144.225.8.54 port 44374 [preauth] Jul 21 12:39:28.374000 audit[7229]: AUDIT1109 pid=7229 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:28.380779 systemd[1]: sshd@114-51-172.31.16.165:22-144.225.8.54:44374.service: Deactivated successfully. Jul 21 12:39:28.380000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@114-51-172.31.16.165:22-144.225.8.54:44374 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:28.453000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@115-52-172.31.16.165:22-144.225.8.54:44376 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:28.454814 systemd[1]: Started sshd@115-52-172.31.16.165:22-144.225.8.54:44376.service - OpenSSH per-connection server daemon (144.225.8.54:44376). Jul 21 12:39:28.577581 kubelet[4002]: I0721 12:39:28.577007 4002 csi_plugin.go:106] kubernetes.io/csi: Trying to validate a new CSI Driver with name: csi.tigera.io endpoint: /var/lib/kubelet/plugins/csi.tigera.io/csi.sock versions: 1.0.0 Jul 21 12:39:28.577581 kubelet[4002]: I0721 12:39:28.577092 4002 csi_plugin.go:119] kubernetes.io/csi: Register new plugin with name: csi.tigera.io at endpoint: /var/lib/kubelet/plugins/csi.tigera.io/csi.sock Jul 21 12:39:28.696000 audit[7217]: AUDIT1101 pid=7217 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:28.700302 sshd[7217]: Accepted publickey for core from 20.76.1.115 port 36092 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:39:28.701000 audit[7217]: AUDIT1103 pid=7217 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:28.701000 audit[7217]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=fffff9b889a0 a2=3 a3=0 items=0 ppid=1 pid=7217 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=10 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:28.701000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:39:28.705390 sshd-session[7217]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:39:28.724943 systemd-logind[2347]: New session '10' of user 'core' with class 'user' and type 'tty'. Jul 21 12:39:28.738579 systemd[1]: Started session-10.scope - Session 10 of User core. Jul 21 12:39:28.761239 sshd[7241]: Invalid user user from 144.225.8.54 port 44376 Jul 21 12:39:28.769000 audit[7217]: AUDIT1105 pid=7217 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:28.774000 audit[7245]: AUDIT1103 pid=7245 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:28.821053 sshd[7241]: Connection closed by invalid user user 144.225.8.54 port 44376 [preauth] Jul 21 12:39:28.820000 audit[7241]: AUDIT1109 pid=7241 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:28.827833 systemd[1]: sshd@115-52-172.31.16.165:22-144.225.8.54:44376.service: Deactivated successfully. Jul 21 12:39:28.830000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@115-52-172.31.16.165:22-144.225.8.54:44376 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:28.897000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@116-53-172.31.16.165:22-144.225.8.54:44388 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:28.898824 systemd[1]: Started sshd@116-53-172.31.16.165:22-144.225.8.54:44388.service - OpenSSH per-connection server daemon (144.225.8.54:44388). Jul 21 12:39:29.206484 sshd[7249]: Invalid user user from 144.225.8.54 port 44388 Jul 21 12:39:29.266627 sshd[7249]: Connection closed by invalid user user 144.225.8.54 port 44388 [preauth] Jul 21 12:39:29.266000 audit[7249]: AUDIT1109 pid=7249 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:29.272440 systemd[1]: sshd@116-53-172.31.16.165:22-144.225.8.54:44388.service: Deactivated successfully. Jul 21 12:39:29.271000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@116-53-172.31.16.165:22-144.225.8.54:44388 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:29.339000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@117-54-172.31.16.165:22-144.225.8.54:44402 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:29.340755 systemd[1]: Started sshd@117-54-172.31.16.165:22-144.225.8.54:44402.service - OpenSSH per-connection server daemon (144.225.8.54:44402). Jul 21 12:39:29.364323 sshd[7245]: Connection closed by 20.76.1.115 port 36092 Jul 21 12:39:29.364000 audit[7217]: AUDIT1106 pid=7217 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:29.364000 audit[7217]: AUDIT1104 pid=7217 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:29.364786 sshd-session[7217]: pam_unix(sshd:session): session closed for user core Jul 21 12:39:29.374102 systemd[1]: sshd@113-50-172.31.16.165:22-20.76.1.115:36092.service: Deactivated successfully. Jul 21 12:39:29.374000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@113-50-172.31.16.165:22-20.76.1.115:36092 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:29.381265 systemd[1]: session-10.scope: Deactivated successfully. Jul 21 12:39:29.390294 systemd-logind[2347]: Session 10 logged out. Waiting for processes to exit. Jul 21 12:39:29.397103 systemd-logind[2347]: Removed session 10. Jul 21 12:39:29.607065 sshd[7263]: Invalid user user from 144.225.8.54 port 44402 Jul 21 12:39:29.666666 sshd[7263]: Connection closed by invalid user user 144.225.8.54 port 44402 [preauth] Jul 21 12:39:29.666000 audit[7263]: AUDIT1109 pid=7263 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:29.670903 systemd[1]: sshd@117-54-172.31.16.165:22-144.225.8.54:44402.service: Deactivated successfully. Jul 21 12:39:29.670000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@117-54-172.31.16.165:22-144.225.8.54:44402 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:29.747323 systemd[1]: Started sshd@118-55-172.31.16.165:22-144.225.8.54:44412.service - OpenSSH per-connection server daemon (144.225.8.54:44412). Jul 21 12:39:29.746000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@118-55-172.31.16.165:22-144.225.8.54:44412 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:29.997885 sshd[7272]: Invalid user user from 144.225.8.54 port 44412 Jul 21 12:39:30.058018 sshd[7272]: Connection closed by invalid user user 144.225.8.54 port 44412 [preauth] Jul 21 12:39:30.057000 audit[7272]: AUDIT1109 pid=7272 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:30.061867 systemd[1]: sshd@118-55-172.31.16.165:22-144.225.8.54:44412.service: Deactivated successfully. Jul 21 12:39:30.062000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@118-55-172.31.16.165:22-144.225.8.54:44412 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:30.135000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@119-4161-172.31.16.165:22-144.225.8.54:44424 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:30.135694 systemd[1]: Started sshd@119-4161-172.31.16.165:22-144.225.8.54:44424.service - OpenSSH per-connection server daemon (144.225.8.54:44424). Jul 21 12:39:30.396580 sshd[7278]: Invalid user user from 144.225.8.54 port 44424 Jul 21 12:39:30.458738 sshd[7278]: Connection closed by invalid user user 144.225.8.54 port 44424 [preauth] Jul 21 12:39:30.458000 audit[7278]: AUDIT1109 pid=7278 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:30.463779 systemd[1]: sshd@119-4161-172.31.16.165:22-144.225.8.54:44424.service: Deactivated successfully. Jul 21 12:39:30.464000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@119-4161-172.31.16.165:22-144.225.8.54:44424 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:30.533900 systemd[1]: Started sshd@120-4162-172.31.16.165:22-144.225.8.54:44426.service - OpenSSH per-connection server daemon (144.225.8.54:44426). Jul 21 12:39:30.532000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@120-4162-172.31.16.165:22-144.225.8.54:44426 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:30.794482 sshd[7284]: Invalid user user from 144.225.8.54 port 44426 Jul 21 12:39:30.855272 sshd[7284]: Connection closed by invalid user user 144.225.8.54 port 44426 [preauth] Jul 21 12:39:30.854000 audit[7284]: AUDIT1109 pid=7284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:30.859415 systemd[1]: sshd@120-4162-172.31.16.165:22-144.225.8.54:44426.service: Deactivated successfully. Jul 21 12:39:30.858000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@120-4162-172.31.16.165:22-144.225.8.54:44426 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:30.931789 systemd[1]: Started sshd@121-4163-172.31.16.165:22-144.225.8.54:44428.service - OpenSSH per-connection server daemon (144.225.8.54:44428). Jul 21 12:39:30.930000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@121-4163-172.31.16.165:22-144.225.8.54:44428 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:31.184723 sshd[7290]: Invalid user user from 144.225.8.54 port 44428 Jul 21 12:39:31.244589 sshd[7290]: Connection closed by invalid user user 144.225.8.54 port 44428 [preauth] Jul 21 12:39:31.244000 audit[7290]: AUDIT1109 pid=7290 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:31.248738 systemd[1]: sshd@121-4163-172.31.16.165:22-144.225.8.54:44428.service: Deactivated successfully. Jul 21 12:39:31.250000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@121-4163-172.31.16.165:22-144.225.8.54:44428 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:31.323000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@122-56-172.31.16.165:22-144.225.8.54:44442 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:31.324065 systemd[1]: Started sshd@122-56-172.31.16.165:22-144.225.8.54:44442.service - OpenSSH per-connection server daemon (144.225.8.54:44442). Jul 21 12:39:31.575932 sshd[7296]: Invalid user user from 144.225.8.54 port 44442 Jul 21 12:39:31.636660 sshd[7296]: Connection closed by invalid user user 144.225.8.54 port 44442 [preauth] Jul 21 12:39:31.635000 audit[7296]: AUDIT1109 pid=7296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:31.640157 systemd[1]: sshd@122-56-172.31.16.165:22-144.225.8.54:44442.service: Deactivated successfully. Jul 21 12:39:31.639000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@122-56-172.31.16.165:22-144.225.8.54:44442 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:31.710146 systemd[1]: Started sshd@123-4164-172.31.16.165:22-144.225.8.54:44458.service - OpenSSH per-connection server daemon (144.225.8.54:44458). Jul 21 12:39:31.711000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@123-4164-172.31.16.165:22-144.225.8.54:44458 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:31.962810 sshd[7302]: Invalid user user from 144.225.8.54 port 44458 Jul 21 12:39:32.026113 sshd[7302]: Connection closed by invalid user user 144.225.8.54 port 44458 [preauth] Jul 21 12:39:32.025000 audit[7302]: AUDIT1109 pid=7302 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:32.031184 systemd[1]: sshd@123-4164-172.31.16.165:22-144.225.8.54:44458.service: Deactivated successfully. Jul 21 12:39:32.033000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@123-4164-172.31.16.165:22-144.225.8.54:44458 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:32.103819 systemd[1]: Started sshd@124-4165-172.31.16.165:22-144.225.8.54:44462.service - OpenSSH per-connection server daemon (144.225.8.54:44462). Jul 21 12:39:32.102000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@124-4165-172.31.16.165:22-144.225.8.54:44462 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:32.307572 kubelet[4002]: I0721 12:39:32.307127 4002 prober_manager.go:312] "Failed to trigger a manual run" probe="Readiness" Jul 21 12:39:32.364919 sshd[7331]: Invalid user user from 144.225.8.54 port 44462 Jul 21 12:39:32.388631 kubelet[4002]: I0721 12:39:32.388493 4002 pod_startup_latency_tracker.go:104] "Observed pod startup duration" pod="calico-system/csi-node-driver-4np6n" podStartSLOduration=43.897938016 podStartE2EDuration="1m2.38846368s" podCreationTimestamp="2026-07-21 12:38:30 +0000 UTC" firstStartedPulling="2026-07-21 12:39:08.984792932 +0000 UTC m=+65.937810268" lastFinishedPulling="2026-07-21 12:39:27.475318596 +0000 UTC m=+84.428335932" observedRunningTime="2026-07-21 12:39:28.307290444 +0000 UTC m=+85.260307804" watchObservedRunningTime="2026-07-21 12:39:32.38846368 +0000 UTC m=+89.341481112" Jul 21 12:39:32.426305 sshd[7331]: Connection closed by invalid user user 144.225.8.54 port 44462 [preauth] Jul 21 12:39:32.425000 audit[7331]: AUDIT1109 pid=7331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:32.433730 systemd[1]: sshd@124-4165-172.31.16.165:22-144.225.8.54:44462.service: Deactivated successfully. Jul 21 12:39:32.434000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@124-4165-172.31.16.165:22-144.225.8.54:44462 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:32.456000 audit[7337]: NETFILTER_CFG table=filter:135 family=2 entries=11 op=nft_register_rule pid=7337 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:32.456000 audit[7337]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=3760 a0=3 a1=ffffc605dd80 a2=0 a3=1 items=0 ppid=4148 pid=7337 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:32.456000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:32.465000 audit[7337]: NETFILTER_CFG table=nat:136 family=2 entries=29 op=nft_register_chain pid=7337 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:32.465000 audit[7337]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=10116 a0=3 a1=ffffc605dd80 a2=0 a3=1 items=0 ppid=4148 pid=7337 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:32.465000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:32.507910 systemd[1]: Started sshd@125-4166-172.31.16.165:22-144.225.8.54:44470.service - OpenSSH per-connection server daemon (144.225.8.54:44470). Jul 21 12:39:32.508000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@125-4166-172.31.16.165:22-144.225.8.54:44470 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:32.798642 sshd[7342]: Invalid user user from 144.225.8.54 port 44470 Jul 21 12:39:32.859596 sshd[7342]: Connection closed by invalid user user 144.225.8.54 port 44470 [preauth] Jul 21 12:39:32.860000 audit[7342]: AUDIT1109 pid=7342 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:32.865243 systemd[1]: sshd@125-4166-172.31.16.165:22-144.225.8.54:44470.service: Deactivated successfully. Jul 21 12:39:32.865000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@125-4166-172.31.16.165:22-144.225.8.54:44470 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:32.941000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@126-4167-172.31.16.165:22-144.225.8.54:44476 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:32.949189 kernel: kauditd_printk_skb: 59 callbacks suppressed Jul 21 12:39:32.942061 systemd[1]: Started sshd@126-4167-172.31.16.165:22-144.225.8.54:44476.service - OpenSSH per-connection server daemon (144.225.8.54:44476). Jul 21 12:39:32.949457 kernel: audit: type=1130 audit(1784637572.941:1137): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@126-4167-172.31.16.165:22-144.225.8.54:44476 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:33.219628 sshd[7353]: Invalid user user from 144.225.8.54 port 44476 Jul 21 12:39:33.284035 sshd[7353]: Connection closed by invalid user user 144.225.8.54 port 44476 [preauth] Jul 21 12:39:33.283000 audit[7353]: AUDIT1109 pid=7353 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:33.295263 kernel: audit: type=1109 audit(1784637573.283:1138): pid=7353 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:33.299222 systemd[1]: sshd@126-4167-172.31.16.165:22-144.225.8.54:44476.service: Deactivated successfully. Jul 21 12:39:33.302000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@126-4167-172.31.16.165:22-144.225.8.54:44476 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:33.320418 kernel: audit: type=1131 audit(1784637573.302:1139): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@126-4167-172.31.16.165:22-144.225.8.54:44476 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:33.363781 systemd[1]: Started sshd@127-57-172.31.16.165:22-144.225.8.54:44478.service - OpenSSH per-connection server daemon (144.225.8.54:44478). Jul 21 12:39:33.362000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@127-57-172.31.16.165:22-144.225.8.54:44478 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:33.377364 kernel: audit: type=1130 audit(1784637573.362:1140): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@127-57-172.31.16.165:22-144.225.8.54:44478 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:33.684722 sshd[7359]: Invalid user user from 144.225.8.54 port 44478 Jul 21 12:39:33.745438 sshd[7359]: Connection closed by invalid user user 144.225.8.54 port 44478 [preauth] Jul 21 12:39:33.745000 audit[7359]: AUDIT1109 pid=7359 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:33.751349 systemd[1]: sshd@127-57-172.31.16.165:22-144.225.8.54:44478.service: Deactivated successfully. Jul 21 12:39:33.750000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@127-57-172.31.16.165:22-144.225.8.54:44478 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:33.760722 kernel: audit: type=1109 audit(1784637573.745:1141): pid=7359 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:33.760978 kernel: audit: type=1131 audit(1784637573.750:1142): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@127-57-172.31.16.165:22-144.225.8.54:44478 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:33.825699 systemd[1]: Started sshd@128-58-172.31.16.165:22-144.225.8.54:44480.service - OpenSSH per-connection server daemon (144.225.8.54:44480). Jul 21 12:39:33.824000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@128-58-172.31.16.165:22-144.225.8.54:44480 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:33.834242 kernel: audit: type=1130 audit(1784637573.824:1143): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@128-58-172.31.16.165:22-144.225.8.54:44480 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:34.093828 sshd[7365]: Invalid user user from 144.225.8.54 port 44480 Jul 21 12:39:34.155057 sshd[7365]: Connection closed by invalid user user 144.225.8.54 port 44480 [preauth] Jul 21 12:39:34.155000 audit[7365]: AUDIT1109 pid=7365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:34.159769 systemd[1]: sshd@128-58-172.31.16.165:22-144.225.8.54:44480.service: Deactivated successfully. Jul 21 12:39:34.159000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@128-58-172.31.16.165:22-144.225.8.54:44480 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:34.169430 kernel: audit: type=1109 audit(1784637574.155:1144): pid=7365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:34.169580 kernel: audit: type=1131 audit(1784637574.159:1145): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@128-58-172.31.16.165:22-144.225.8.54:44480 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:34.239000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@129-59-172.31.16.165:22-144.225.8.54:44496 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:34.240864 systemd[1]: Started sshd@129-59-172.31.16.165:22-144.225.8.54:44496.service - OpenSSH per-connection server daemon (144.225.8.54:44496). Jul 21 12:39:34.254085 kernel: audit: type=1130 audit(1784637574.239:1146): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@129-59-172.31.16.165:22-144.225.8.54:44496 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:34.541000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@130-60-172.31.16.165:22-20.76.1.115:55520 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:34.540504 systemd[1]: Started sshd@130-60-172.31.16.165:22-20.76.1.115:55520.service - OpenSSH per-connection server daemon (20.76.1.115:55520). Jul 21 12:39:34.550605 sshd[7371]: Invalid user user from 144.225.8.54 port 44496 Jul 21 12:39:34.616292 sshd[7371]: Connection closed by invalid user user 144.225.8.54 port 44496 [preauth] Jul 21 12:39:34.617000 audit[7371]: AUDIT1109 pid=7371 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:34.628840 systemd[1]: sshd@129-59-172.31.16.165:22-144.225.8.54:44496.service: Deactivated successfully. Jul 21 12:39:34.630000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@129-59-172.31.16.165:22-144.225.8.54:44496 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:34.696000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@131-4168-172.31.16.165:22-144.225.8.54:44498 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:34.697169 systemd[1]: Started sshd@131-4168-172.31.16.165:22-144.225.8.54:44498.service - OpenSSH per-connection server daemon (144.225.8.54:44498). Jul 21 12:39:34.970326 sshd[7381]: Invalid user user from 144.225.8.54 port 44498 Jul 21 12:39:35.032703 sshd[7381]: Connection closed by invalid user user 144.225.8.54 port 44498 [preauth] Jul 21 12:39:35.031000 audit[7381]: AUDIT1109 pid=7381 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:35.038059 systemd[1]: sshd@131-4168-172.31.16.165:22-144.225.8.54:44498.service: Deactivated successfully. Jul 21 12:39:35.038000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@131-4168-172.31.16.165:22-144.225.8.54:44498 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:35.113620 systemd[1]: Started sshd@132-61-172.31.16.165:22-144.225.8.54:44506.service - OpenSSH per-connection server daemon (144.225.8.54:44506). Jul 21 12:39:35.113000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@132-61-172.31.16.165:22-144.225.8.54:44506 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:35.395509 sshd[7387]: Invalid user user from 144.225.8.54 port 44506 Jul 21 12:39:35.459171 sshd[7387]: Connection closed by invalid user user 144.225.8.54 port 44506 [preauth] Jul 21 12:39:35.458000 audit[7387]: AUDIT1109 pid=7387 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:35.462035 systemd[1]: sshd@132-61-172.31.16.165:22-144.225.8.54:44506.service: Deactivated successfully. Jul 21 12:39:35.461000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@132-61-172.31.16.165:22-144.225.8.54:44506 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:35.464000 audit[7375]: AUDIT1101 pid=7375 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:35.468446 sshd[7375]: Accepted publickey for core from 20.76.1.115 port 55520 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:39:35.473000 audit[7375]: AUDIT1103 pid=7375 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:35.473000 audit[7375]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffdaaa35e0 a2=3 a3=0 items=0 ppid=1 pid=7375 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=11 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:35.473000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:39:35.477992 sshd-session[7375]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:39:35.496029 systemd-logind[2347]: New session '11' of user 'core' with class 'user' and type 'tty'. Jul 21 12:39:35.501535 systemd[1]: Started session-11.scope - Session 11 of User core. Jul 21 12:39:35.538000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@133-62-172.31.16.165:22-144.225.8.54:44512 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:35.539000 audit[7375]: AUDIT1105 pid=7375 uid=0 auid=500 ses=11 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:35.539565 systemd[1]: Started sshd@133-62-172.31.16.165:22-144.225.8.54:44512.service - OpenSSH per-connection server daemon (144.225.8.54:44512). Jul 21 12:39:35.546000 audit[7395]: AUDIT1103 pid=7395 uid=0 auid=500 ses=11 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:35.805722 sshd[7394]: Invalid user user from 144.225.8.54 port 44512 Jul 21 12:39:35.868435 sshd[7394]: Connection closed by invalid user user 144.225.8.54 port 44512 [preauth] Jul 21 12:39:35.868000 audit[7394]: AUDIT1109 pid=7394 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:35.874000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@133-62-172.31.16.165:22-144.225.8.54:44512 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:35.875314 systemd[1]: sshd@133-62-172.31.16.165:22-144.225.8.54:44512.service: Deactivated successfully. Jul 21 12:39:35.953939 systemd[1]: Started sshd@134-63-172.31.16.165:22-144.225.8.54:44522.service - OpenSSH per-connection server daemon (144.225.8.54:44522). Jul 21 12:39:35.953000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@134-63-172.31.16.165:22-144.225.8.54:44522 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:36.146896 sshd[7395]: Connection closed by 20.76.1.115 port 55520 Jul 21 12:39:36.149499 sshd-session[7375]: pam_unix(sshd:session): session closed for user core Jul 21 12:39:36.149000 audit[7375]: AUDIT1106 pid=7375 uid=0 auid=500 ses=11 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:36.149000 audit[7375]: AUDIT1104 pid=7375 uid=0 auid=500 ses=11 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:36.157539 systemd[1]: sshd@130-60-172.31.16.165:22-20.76.1.115:55520.service: Deactivated successfully. Jul 21 12:39:36.158000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@130-60-172.31.16.165:22-20.76.1.115:55520 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:36.164464 systemd[1]: session-11.scope: Deactivated successfully. Jul 21 12:39:36.172305 systemd-logind[2347]: Session 11 logged out. Waiting for processes to exit. Jul 21 12:39:36.178719 systemd-logind[2347]: Removed session 11. Jul 21 12:39:36.254252 sshd[7409]: Invalid user user from 144.225.8.54 port 44522 Jul 21 12:39:36.316369 sshd[7409]: Connection closed by invalid user user 144.225.8.54 port 44522 [preauth] Jul 21 12:39:36.315000 audit[7409]: AUDIT1109 pid=7409 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:36.322780 systemd[1]: sshd@134-63-172.31.16.165:22-144.225.8.54:44522.service: Deactivated successfully. Jul 21 12:39:36.322000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@134-63-172.31.16.165:22-144.225.8.54:44522 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:36.396000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@135-4169-172.31.16.165:22-144.225.8.54:44534 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:36.397226 systemd[1]: Started sshd@135-4169-172.31.16.165:22-144.225.8.54:44534.service - OpenSSH per-connection server daemon (144.225.8.54:44534). Jul 21 12:39:36.658139 sshd[7418]: Invalid user user from 144.225.8.54 port 44534 Jul 21 12:39:36.719153 sshd[7418]: Connection closed by invalid user user 144.225.8.54 port 44534 [preauth] Jul 21 12:39:36.718000 audit[7418]: AUDIT1109 pid=7418 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:36.725926 systemd[1]: sshd@135-4169-172.31.16.165:22-144.225.8.54:44534.service: Deactivated successfully. Jul 21 12:39:36.725000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@135-4169-172.31.16.165:22-144.225.8.54:44534 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:36.798000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@136-4170-172.31.16.165:22-144.225.8.54:44536 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:36.799112 systemd[1]: Started sshd@136-4170-172.31.16.165:22-144.225.8.54:44536.service - OpenSSH per-connection server daemon (144.225.8.54:44536). Jul 21 12:39:37.085311 sshd[7424]: Invalid user user from 144.225.8.54 port 44536 Jul 21 12:39:37.150096 sshd[7424]: Connection closed by invalid user user 144.225.8.54 port 44536 [preauth] Jul 21 12:39:37.150000 audit[7424]: AUDIT1109 pid=7424 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:37.156095 systemd[1]: sshd@136-4170-172.31.16.165:22-144.225.8.54:44536.service: Deactivated successfully. Jul 21 12:39:37.155000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@136-4170-172.31.16.165:22-144.225.8.54:44536 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:37.233797 systemd[1]: Started sshd@137-4171-172.31.16.165:22-144.225.8.54:44542.service - OpenSSH per-connection server daemon (144.225.8.54:44542). Jul 21 12:39:37.232000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@137-4171-172.31.16.165:22-144.225.8.54:44542 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:37.514939 sshd[7430]: Invalid user user from 144.225.8.54 port 44542 Jul 21 12:39:37.577872 sshd[7430]: Connection closed by invalid user user 144.225.8.54 port 44542 [preauth] Jul 21 12:39:37.577000 audit[7430]: AUDIT1109 pid=7430 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:37.582187 systemd[1]: sshd@137-4171-172.31.16.165:22-144.225.8.54:44542.service: Deactivated successfully. Jul 21 12:39:37.581000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@137-4171-172.31.16.165:22-144.225.8.54:44542 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:37.653781 systemd[1]: Started sshd@138-4172-172.31.16.165:22-144.225.8.54:44554.service - OpenSSH per-connection server daemon (144.225.8.54:44554). Jul 21 12:39:37.652000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@138-4172-172.31.16.165:22-144.225.8.54:44554 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:37.919944 sshd[7436]: Invalid user user from 144.225.8.54 port 44554 Jul 21 12:39:37.982108 sshd[7436]: Connection closed by invalid user user 144.225.8.54 port 44554 [preauth] Jul 21 12:39:37.982000 audit[7436]: AUDIT1109 pid=7436 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:37.984509 kernel: kauditd_printk_skb: 35 callbacks suppressed Jul 21 12:39:37.984584 kernel: audit: type=1109 audit(1784637577.982:1180): pid=7436 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:37.990669 systemd[1]: sshd@138-4172-172.31.16.165:22-144.225.8.54:44554.service: Deactivated successfully. Jul 21 12:39:37.990000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@138-4172-172.31.16.165:22-144.225.8.54:44554 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.004352 kernel: audit: type=1131 audit(1784637577.990:1181): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@138-4172-172.31.16.165:22-144.225.8.54:44554 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.059000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@139-4173-172.31.16.165:22-144.225.8.54:56868 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.060906 systemd[1]: Started sshd@139-4173-172.31.16.165:22-144.225.8.54:56868.service - OpenSSH per-connection server daemon (144.225.8.54:56868). Jul 21 12:39:38.072253 kernel: audit: type=1130 audit(1784637578.059:1182): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@139-4173-172.31.16.165:22-144.225.8.54:56868 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.384862 sshd[7442]: Invalid user user from 144.225.8.54 port 56868 Jul 21 12:39:38.445803 sshd[7442]: Connection closed by invalid user user 144.225.8.54 port 56868 [preauth] Jul 21 12:39:38.445000 audit[7442]: AUDIT1109 pid=7442 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:38.452359 systemd[1]: sshd@139-4173-172.31.16.165:22-144.225.8.54:56868.service: Deactivated successfully. Jul 21 12:39:38.451000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@139-4173-172.31.16.165:22-144.225.8.54:56868 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.454398 kernel: audit: type=1109 audit(1784637578.445:1183): pid=7442 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:38.454456 kernel: audit: type=1131 audit(1784637578.451:1184): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@139-4173-172.31.16.165:22-144.225.8.54:56868 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.524262 systemd[1]: Started sshd@140-4174-172.31.16.165:22-144.225.8.54:56878.service - OpenSSH per-connection server daemon (144.225.8.54:56878). Jul 21 12:39:38.523000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@140-4174-172.31.16.165:22-144.225.8.54:56878 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.538345 kernel: audit: type=1130 audit(1784637578.523:1185): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@140-4174-172.31.16.165:22-144.225.8.54:56878 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.780049 sshd[7448]: Invalid user user from 144.225.8.54 port 56878 Jul 21 12:39:38.840907 sshd[7448]: Connection closed by invalid user user 144.225.8.54 port 56878 [preauth] Jul 21 12:39:38.840000 audit[7448]: AUDIT1109 pid=7448 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:38.846247 kernel: audit: type=1109 audit(1784637578.840:1186): pid=7448 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:38.846843 systemd[1]: sshd@140-4174-172.31.16.165:22-144.225.8.54:56878.service: Deactivated successfully. Jul 21 12:39:38.846000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@140-4174-172.31.16.165:22-144.225.8.54:56878 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.853256 kernel: audit: type=1131 audit(1784637578.846:1187): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@140-4174-172.31.16.165:22-144.225.8.54:56878 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.919060 systemd[1]: Started sshd@141-64-172.31.16.165:22-144.225.8.54:56888.service - OpenSSH per-connection server daemon (144.225.8.54:56888). Jul 21 12:39:38.918000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@141-64-172.31.16.165:22-144.225.8.54:56888 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:38.928273 kernel: audit: type=1130 audit(1784637578.918:1188): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@141-64-172.31.16.165:22-144.225.8.54:56888 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:39.167936 sshd[7457]: Invalid user user from 144.225.8.54 port 56888 Jul 21 12:39:39.228319 sshd[7457]: Connection closed by invalid user user 144.225.8.54 port 56888 [preauth] Jul 21 12:39:39.228000 audit[7457]: AUDIT1109 pid=7457 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:39.234710 systemd[1]: sshd@141-64-172.31.16.165:22-144.225.8.54:56888.service: Deactivated successfully. Jul 21 12:39:39.234000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@141-64-172.31.16.165:22-144.225.8.54:56888 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:39.236238 kernel: audit: type=1109 audit(1784637579.228:1189): pid=7457 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:39.302908 systemd[1]: Started sshd@142-65-172.31.16.165:22-144.225.8.54:56892.service - OpenSSH per-connection server daemon (144.225.8.54:56892). Jul 21 12:39:39.301000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@142-65-172.31.16.165:22-144.225.8.54:56892 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:39.555151 sshd[7463]: Invalid user user from 144.225.8.54 port 56892 Jul 21 12:39:39.615393 sshd[7463]: Connection closed by invalid user user 144.225.8.54 port 56892 [preauth] Jul 21 12:39:39.614000 audit[7463]: AUDIT1109 pid=7463 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:39.619424 systemd[1]: sshd@142-65-172.31.16.165:22-144.225.8.54:56892.service: Deactivated successfully. Jul 21 12:39:39.620000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@142-65-172.31.16.165:22-144.225.8.54:56892 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:39.688000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@143-66-172.31.16.165:22-144.225.8.54:56902 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:39.689888 systemd[1]: Started sshd@143-66-172.31.16.165:22-144.225.8.54:56902.service - OpenSSH per-connection server daemon (144.225.8.54:56902). Jul 21 12:39:39.949502 sshd[7469]: Invalid user user from 144.225.8.54 port 56902 Jul 21 12:39:40.011244 sshd[7469]: Connection closed by invalid user user 144.225.8.54 port 56902 [preauth] Jul 21 12:39:40.011000 audit[7469]: AUDIT1109 pid=7469 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:40.015880 systemd[1]: sshd@143-66-172.31.16.165:22-144.225.8.54:56902.service: Deactivated successfully. Jul 21 12:39:40.017000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@143-66-172.31.16.165:22-144.225.8.54:56902 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:40.096240 systemd[1]: Started sshd@144-4175-172.31.16.165:22-144.225.8.54:56916.service - OpenSSH per-connection server daemon (144.225.8.54:56916). Jul 21 12:39:40.095000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@144-4175-172.31.16.165:22-144.225.8.54:56916 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:40.377156 sshd[7486]: Invalid user user from 144.225.8.54 port 56916 Jul 21 12:39:40.438352 sshd[7486]: Connection closed by invalid user user 144.225.8.54 port 56916 [preauth] Jul 21 12:39:40.438000 audit[7486]: AUDIT1109 pid=7486 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:40.444543 systemd[1]: sshd@144-4175-172.31.16.165:22-144.225.8.54:56916.service: Deactivated successfully. Jul 21 12:39:40.444000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@144-4175-172.31.16.165:22-144.225.8.54:56916 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:40.513780 systemd[1]: Started sshd@145-67-172.31.16.165:22-144.225.8.54:56930.service - OpenSSH per-connection server daemon (144.225.8.54:56930). Jul 21 12:39:40.512000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@145-67-172.31.16.165:22-144.225.8.54:56930 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:40.762310 sshd[7500]: Invalid user user from 144.225.8.54 port 56930 Jul 21 12:39:40.821381 sshd[7500]: Connection closed by invalid user user 144.225.8.54 port 56930 [preauth] Jul 21 12:39:40.821000 audit[7500]: AUDIT1109 pid=7500 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:40.825700 systemd[1]: sshd@145-67-172.31.16.165:22-144.225.8.54:56930.service: Deactivated successfully. Jul 21 12:39:40.826000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@145-67-172.31.16.165:22-144.225.8.54:56930 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:40.898751 systemd[1]: Started sshd@146-4176-172.31.16.165:22-144.225.8.54:56946.service - OpenSSH per-connection server daemon (144.225.8.54:56946). Jul 21 12:39:40.897000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@146-4176-172.31.16.165:22-144.225.8.54:56946 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:41.157806 sshd[7517]: Invalid user user from 144.225.8.54 port 56946 Jul 21 12:39:41.218275 sshd[7517]: Connection closed by invalid user user 144.225.8.54 port 56946 [preauth] Jul 21 12:39:41.217000 audit[7517]: AUDIT1109 pid=7517 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:41.222115 systemd[1]: sshd@146-4176-172.31.16.165:22-144.225.8.54:56946.service: Deactivated successfully. Jul 21 12:39:41.221000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@146-4176-172.31.16.165:22-144.225.8.54:56946 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:41.295017 systemd[1]: Started sshd@147-4177-172.31.16.165:22-144.225.8.54:56958.service - OpenSSH per-connection server daemon (144.225.8.54:56958). Jul 21 12:39:41.294000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@147-4177-172.31.16.165:22-144.225.8.54:56958 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:41.329000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@148-4178-172.31.16.165:22-20.76.1.115:55526 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:41.330269 systemd[1]: Started sshd@148-4178-172.31.16.165:22-20.76.1.115:55526.service - OpenSSH per-connection server daemon (20.76.1.115:55526). Jul 21 12:39:41.577010 sshd[7523]: Invalid user user from 144.225.8.54 port 56958 Jul 21 12:39:41.638022 sshd[7523]: Connection closed by invalid user user 144.225.8.54 port 56958 [preauth] Jul 21 12:39:41.637000 audit[7523]: AUDIT1109 pid=7523 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:41.642859 systemd[1]: sshd@147-4177-172.31.16.165:22-144.225.8.54:56958.service: Deactivated successfully. Jul 21 12:39:41.642000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@147-4177-172.31.16.165:22-144.225.8.54:56958 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:41.715024 systemd[1]: Started sshd@149-4179-172.31.16.165:22-144.225.8.54:56962.service - OpenSSH per-connection server daemon (144.225.8.54:56962). Jul 21 12:39:41.717000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@149-4179-172.31.16.165:22-144.225.8.54:56962 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:41.983091 sshd[7533]: Invalid user user from 144.225.8.54 port 56962 Jul 21 12:39:42.045081 sshd[7533]: Connection closed by invalid user user 144.225.8.54 port 56962 [preauth] Jul 21 12:39:42.045000 audit[7533]: AUDIT1109 pid=7533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:42.051980 systemd[1]: sshd@149-4179-172.31.16.165:22-144.225.8.54:56962.service: Deactivated successfully. Jul 21 12:39:42.053000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@149-4179-172.31.16.165:22-144.225.8.54:56962 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:42.122000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@150-68-172.31.16.165:22-144.225.8.54:56978 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:42.122918 systemd[1]: Started sshd@150-68-172.31.16.165:22-144.225.8.54:56978.service - OpenSSH per-connection server daemon (144.225.8.54:56978). Jul 21 12:39:42.207000 audit[7525]: AUDIT1101 pid=7525 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:42.208999 sshd[7525]: Accepted publickey for core from 20.76.1.115 port 55526 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:39:42.209000 audit[7525]: AUDIT1103 pid=7525 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:42.210000 audit[7525]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffe7b878f0 a2=3 a3=0 items=0 ppid=1 pid=7525 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=12 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:42.210000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:39:42.212940 sshd-session[7525]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:39:42.222950 systemd-logind[2347]: New session '12' of user 'core' with class 'user' and type 'tty'. Jul 21 12:39:42.229527 systemd[1]: Started session-12.scope - Session 12 of User core. Jul 21 12:39:42.241000 audit[7525]: AUDIT1105 pid=7525 uid=0 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:42.246000 audit[7543]: AUDIT1103 pid=7543 uid=0 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:42.374989 sshd[7539]: Invalid user user from 144.225.8.54 port 56978 Jul 21 12:39:42.435407 sshd[7539]: Connection closed by invalid user user 144.225.8.54 port 56978 [preauth] Jul 21 12:39:42.435000 audit[7539]: AUDIT1109 pid=7539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:42.439491 systemd[1]: sshd@150-68-172.31.16.165:22-144.225.8.54:56978.service: Deactivated successfully. Jul 21 12:39:42.439000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@150-68-172.31.16.165:22-144.225.8.54:56978 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:42.511750 systemd[1]: Started sshd@151-69-172.31.16.165:22-144.225.8.54:56988.service - OpenSSH per-connection server daemon (144.225.8.54:56988). Jul 21 12:39:42.512000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@151-69-172.31.16.165:22-144.225.8.54:56988 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:42.774354 sshd[7547]: Invalid user user from 144.225.8.54 port 56988 Jul 21 12:39:42.832124 sshd[7543]: Connection closed by 20.76.1.115 port 55526 Jul 21 12:39:42.833928 sshd[7547]: Connection closed by invalid user user 144.225.8.54 port 56988 [preauth] Jul 21 12:39:42.832000 audit[7547]: AUDIT1109 pid=7547 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:42.836112 sshd-session[7525]: pam_unix(sshd:session): session closed for user core Jul 21 12:39:42.839000 audit[7525]: AUDIT1106 pid=7525 uid=0 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:42.839000 audit[7525]: AUDIT1104 pid=7525 uid=0 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:42.842763 systemd[1]: sshd@151-69-172.31.16.165:22-144.225.8.54:56988.service: Deactivated successfully. Jul 21 12:39:42.844000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@151-69-172.31.16.165:22-144.225.8.54:56988 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:42.854071 systemd[1]: sshd@148-4178-172.31.16.165:22-20.76.1.115:55526.service: Deactivated successfully. Jul 21 12:39:42.853000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@148-4178-172.31.16.165:22-20.76.1.115:55526 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:42.860879 systemd[1]: session-12.scope: Deactivated successfully. Jul 21 12:39:42.870331 systemd-logind[2347]: Session 12 logged out. Waiting for processes to exit. Jul 21 12:39:42.877921 systemd-logind[2347]: Removed session 12. Jul 21 12:39:42.908000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@152-70-172.31.16.165:22-144.225.8.54:56992 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:42.909800 systemd[1]: Started sshd@152-70-172.31.16.165:22-144.225.8.54:56992.service - OpenSSH per-connection server daemon (144.225.8.54:56992). Jul 21 12:39:43.019000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@153-71-172.31.16.165:22-20.76.1.115:54820 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:43.019982 systemd[1]: Started sshd@153-71-172.31.16.165:22-20.76.1.115:54820.service - OpenSSH per-connection server daemon (20.76.1.115:54820). Jul 21 12:39:43.021938 kernel: kauditd_printk_skb: 40 callbacks suppressed Jul 21 12:39:43.022036 kernel: audit: type=1130 audit(1784637583.019:1228): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@153-71-172.31.16.165:22-20.76.1.115:54820 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:43.177977 sshd[7564]: Invalid user user from 144.225.8.54 port 56992 Jul 21 12:39:43.238379 sshd[7564]: Connection closed by invalid user user 144.225.8.54 port 56992 [preauth] Jul 21 12:39:43.238000 audit[7564]: AUDIT1109 pid=7564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:43.248278 kernel: audit: type=1109 audit(1784637583.238:1229): pid=7564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:43.249822 systemd[1]: sshd@152-70-172.31.16.165:22-144.225.8.54:56992.service: Deactivated successfully. Jul 21 12:39:43.250000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@152-70-172.31.16.165:22-144.225.8.54:56992 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:43.257587 kernel: audit: type=1131 audit(1784637583.250:1230): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@152-70-172.31.16.165:22-144.225.8.54:56992 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:43.327000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@154-72-172.31.16.165:22-144.225.8.54:57000 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:43.328755 systemd[1]: Started sshd@154-72-172.31.16.165:22-144.225.8.54:57000.service - OpenSSH per-connection server daemon (144.225.8.54:57000). Jul 21 12:39:43.340591 kernel: audit: type=1130 audit(1784637583.327:1231): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@154-72-172.31.16.165:22-144.225.8.54:57000 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:43.626055 sshd[7574]: Invalid user user from 144.225.8.54 port 57000 Jul 21 12:39:43.687434 sshd[7574]: Connection closed by invalid user user 144.225.8.54 port 57000 [preauth] Jul 21 12:39:43.686000 audit[7574]: AUDIT1109 pid=7574 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:43.693649 systemd[1]: sshd@154-72-172.31.16.165:22-144.225.8.54:57000.service: Deactivated successfully. Jul 21 12:39:43.693000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@154-72-172.31.16.165:22-144.225.8.54:57000 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:43.705073 kernel: audit: type=1109 audit(1784637583.686:1232): pid=7574 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:43.705131 kernel: audit: type=1131 audit(1784637583.693:1233): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@154-72-172.31.16.165:22-144.225.8.54:57000 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:43.761405 systemd[1]: Started sshd@155-73-172.31.16.165:22-144.225.8.54:57010.service - OpenSSH per-connection server daemon (144.225.8.54:57010). Jul 21 12:39:43.760000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@155-73-172.31.16.165:22-144.225.8.54:57010 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:43.772256 kernel: audit: type=1130 audit(1784637583.760:1234): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@155-73-172.31.16.165:22-144.225.8.54:57010 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:43.972000 audit[7568]: AUDIT1101 pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:43.979780 sshd[7568]: Accepted publickey for core from 20.76.1.115 port 54820 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:39:43.980453 kernel: audit: type=1101 audit(1784637583.972:1235): pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:43.980000 audit[7568]: AUDIT1103 pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:43.983561 sshd-session[7568]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:39:43.990329 kernel: audit: type=1103 audit(1784637583.980:1236): pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:43.990458 kernel: audit: type=1006 audit(1784637583.980:1237): pid=7568 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=13 res=1 Jul 21 12:39:43.980000 audit[7568]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=fffff74f6270 a2=3 a3=0 items=0 ppid=1 pid=7568 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=13 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:43.980000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:39:43.997762 systemd-logind[2347]: New session '13' of user 'core' with class 'user' and type 'tty'. Jul 21 12:39:44.005590 systemd[1]: Started session-13.scope - Session 13 of User core. Jul 21 12:39:44.011705 sshd[7580]: Invalid user user from 144.225.8.54 port 57010 Jul 21 12:39:44.020000 audit[7568]: AUDIT1105 pid=7568 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:44.023000 audit[7584]: AUDIT1103 pid=7584 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:44.077064 sshd[7580]: Connection closed by invalid user user 144.225.8.54 port 57010 [preauth] Jul 21 12:39:44.076000 audit[7580]: AUDIT1109 pid=7580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:44.082409 systemd[1]: sshd@155-73-172.31.16.165:22-144.225.8.54:57010.service: Deactivated successfully. Jul 21 12:39:44.082000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@155-73-172.31.16.165:22-144.225.8.54:57010 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:44.152368 systemd[1]: Started sshd@156-4180-172.31.16.165:22-144.225.8.54:57024.service - OpenSSH per-connection server daemon (144.225.8.54:57024). Jul 21 12:39:44.151000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@156-4180-172.31.16.165:22-144.225.8.54:57024 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:44.405984 sshd[7588]: Invalid user user from 144.225.8.54 port 57024 Jul 21 12:39:44.468408 sshd[7588]: Connection closed by invalid user user 144.225.8.54 port 57024 [preauth] Jul 21 12:39:44.467000 audit[7588]: AUDIT1109 pid=7588 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:44.473138 systemd[1]: sshd@156-4180-172.31.16.165:22-144.225.8.54:57024.service: Deactivated successfully. Jul 21 12:39:44.473000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@156-4180-172.31.16.165:22-144.225.8.54:57024 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:44.547937 systemd[1]: Started sshd@157-74-172.31.16.165:22-144.225.8.54:57034.service - OpenSSH per-connection server daemon (144.225.8.54:57034). Jul 21 12:39:44.546000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@157-74-172.31.16.165:22-144.225.8.54:57034 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:44.689934 sshd[7584]: Connection closed by 20.76.1.115 port 54820 Jul 21 12:39:44.691192 sshd-session[7568]: pam_unix(sshd:session): session closed for user core Jul 21 12:39:44.692000 audit[7568]: AUDIT1106 pid=7568 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:44.692000 audit[7568]: AUDIT1104 pid=7568 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:44.701700 systemd[1]: sshd@153-71-172.31.16.165:22-20.76.1.115:54820.service: Deactivated successfully. Jul 21 12:39:44.703000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@153-71-172.31.16.165:22-20.76.1.115:54820 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:44.709079 systemd[1]: session-13.scope: Deactivated successfully. Jul 21 12:39:44.719125 systemd-logind[2347]: Session 13 logged out. Waiting for processes to exit. Jul 21 12:39:44.725795 systemd-logind[2347]: Removed session 13. Jul 21 12:39:44.862000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@158-4181-172.31.16.165:22-20.76.1.115:54822 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:44.863588 systemd[1]: Started sshd@158-4181-172.31.16.165:22-20.76.1.115:54822.service - OpenSSH per-connection server daemon (20.76.1.115:54822). Jul 21 12:39:44.866280 sshd[7599]: Invalid user user from 144.225.8.54 port 57034 Jul 21 12:39:44.930048 sshd[7599]: Connection closed by invalid user user 144.225.8.54 port 57034 [preauth] Jul 21 12:39:44.929000 audit[7599]: AUDIT1109 pid=7599 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:44.934287 systemd[1]: sshd@157-74-172.31.16.165:22-144.225.8.54:57034.service: Deactivated successfully. Jul 21 12:39:44.935000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@157-74-172.31.16.165:22-144.225.8.54:57034 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:45.007000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@159-4182-172.31.16.165:22-144.225.8.54:57048 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:45.008649 systemd[1]: Started sshd@159-4182-172.31.16.165:22-144.225.8.54:57048.service - OpenSSH per-connection server daemon (144.225.8.54:57048). Jul 21 12:39:45.262506 sshd[7612]: Invalid user user from 144.225.8.54 port 57048 Jul 21 12:39:45.323472 sshd[7612]: Connection closed by invalid user user 144.225.8.54 port 57048 [preauth] Jul 21 12:39:45.322000 audit[7612]: AUDIT1109 pid=7612 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:45.328043 systemd[1]: sshd@159-4182-172.31.16.165:22-144.225.8.54:57048.service: Deactivated successfully. Jul 21 12:39:45.329000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@159-4182-172.31.16.165:22-144.225.8.54:57048 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:45.428898 systemd[1]: Started sshd@160-4183-172.31.16.165:22-144.225.8.54:57060.service - OpenSSH per-connection server daemon (144.225.8.54:57060). Jul 21 12:39:45.428000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@160-4183-172.31.16.165:22-144.225.8.54:57060 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:45.703565 sshd[7618]: Invalid user user from 144.225.8.54 port 57060 Jul 21 12:39:45.738000 audit[7606]: AUDIT1101 pid=7606 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:45.739724 sshd[7606]: Accepted publickey for core from 20.76.1.115 port 54822 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:39:45.740000 audit[7606]: AUDIT1103 pid=7606 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:45.740000 audit[7606]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffe832cc20 a2=3 a3=0 items=0 ppid=1 pid=7606 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=14 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:45.740000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:39:45.743614 sshd-session[7606]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:39:45.754289 systemd-logind[2347]: New session '14' of user 'core' with class 'user' and type 'tty'. Jul 21 12:39:45.760516 systemd[1]: Started session-14.scope - Session 14 of User core. Jul 21 12:39:45.764030 sshd[7618]: Connection closed by invalid user user 144.225.8.54 port 57060 [preauth] Jul 21 12:39:45.764000 audit[7618]: AUDIT1109 pid=7618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:45.767837 systemd[1]: sshd@160-4183-172.31.16.165:22-144.225.8.54:57060.service: Deactivated successfully. Jul 21 12:39:45.768000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@160-4183-172.31.16.165:22-144.225.8.54:57060 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:45.781000 audit[7606]: AUDIT1105 pid=7606 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:45.787000 audit[7624]: AUDIT1103 pid=7624 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:45.839000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@161-75-172.31.16.165:22-144.225.8.54:57072 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:45.840766 systemd[1]: Started sshd@161-75-172.31.16.165:22-144.225.8.54:57072.service - OpenSSH per-connection server daemon (144.225.8.54:57072). Jul 21 12:39:46.095821 sshd[7626]: Invalid user user from 144.225.8.54 port 57072 Jul 21 12:39:46.156945 sshd[7626]: Connection closed by invalid user user 144.225.8.54 port 57072 [preauth] Jul 21 12:39:46.158000 audit[7626]: AUDIT1109 pid=7626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:46.162553 systemd[1]: sshd@161-75-172.31.16.165:22-144.225.8.54:57072.service: Deactivated successfully. Jul 21 12:39:46.162000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@161-75-172.31.16.165:22-144.225.8.54:57072 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:46.237810 systemd[1]: Started sshd@162-4184-172.31.16.165:22-144.225.8.54:57074.service - OpenSSH per-connection server daemon (144.225.8.54:57074). Jul 21 12:39:46.236000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@162-4184-172.31.16.165:22-144.225.8.54:57074 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:46.407394 sshd[7624]: Connection closed by 20.76.1.115 port 54822 Jul 21 12:39:46.407804 sshd-session[7606]: pam_unix(sshd:session): session closed for user core Jul 21 12:39:46.407000 audit[7606]: AUDIT1106 pid=7606 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:46.408000 audit[7606]: AUDIT1104 pid=7606 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:46.413736 systemd[1]: sshd@158-4181-172.31.16.165:22-20.76.1.115:54822.service: Deactivated successfully. Jul 21 12:39:46.414000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@158-4181-172.31.16.165:22-20.76.1.115:54822 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:46.420639 systemd[1]: session-14.scope: Deactivated successfully. Jul 21 12:39:46.429352 systemd-logind[2347]: Session 14 logged out. Waiting for processes to exit. Jul 21 12:39:46.434061 systemd-logind[2347]: Removed session 14. Jul 21 12:39:46.496440 sshd[7639]: Invalid user user from 144.225.8.54 port 57074 Jul 21 12:39:46.557433 sshd[7639]: Connection closed by invalid user user 144.225.8.54 port 57074 [preauth] Jul 21 12:39:46.556000 audit[7639]: AUDIT1109 pid=7639 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:46.560598 systemd[1]: sshd@162-4184-172.31.16.165:22-144.225.8.54:57074.service: Deactivated successfully. Jul 21 12:39:46.560000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@162-4184-172.31.16.165:22-144.225.8.54:57074 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:46.631841 systemd[1]: Started sshd@163-4185-172.31.16.165:22-144.225.8.54:57076.service - OpenSSH per-connection server daemon (144.225.8.54:57076). Jul 21 12:39:46.632000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@163-4185-172.31.16.165:22-144.225.8.54:57076 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:46.877775 sshd[7648]: Invalid user user from 144.225.8.54 port 57076 Jul 21 12:39:46.938599 sshd[7648]: Connection closed by invalid user user 144.225.8.54 port 57076 [preauth] Jul 21 12:39:46.937000 audit[7648]: AUDIT1109 pid=7648 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:46.942255 systemd[1]: sshd@163-4185-172.31.16.165:22-144.225.8.54:57076.service: Deactivated successfully. Jul 21 12:39:46.944000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@163-4185-172.31.16.165:22-144.225.8.54:57076 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:47.014000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@164-76-172.31.16.165:22-144.225.8.54:57090 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:47.015642 systemd[1]: Started sshd@164-76-172.31.16.165:22-144.225.8.54:57090.service - OpenSSH per-connection server daemon (144.225.8.54:57090). Jul 21 12:39:47.261666 sshd[7655]: Invalid user user from 144.225.8.54 port 57090 Jul 21 12:39:47.322187 sshd[7655]: Connection closed by invalid user user 144.225.8.54 port 57090 [preauth] Jul 21 12:39:47.321000 audit[7655]: AUDIT1109 pid=7655 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:47.326104 systemd[1]: sshd@164-76-172.31.16.165:22-144.225.8.54:57090.service: Deactivated successfully. Jul 21 12:39:47.326000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@164-76-172.31.16.165:22-144.225.8.54:57090 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:47.402000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@165-4186-172.31.16.165:22-144.225.8.54:57106 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:47.401830 systemd[1]: Started sshd@165-4186-172.31.16.165:22-144.225.8.54:57106.service - OpenSSH per-connection server daemon (144.225.8.54:57106). Jul 21 12:39:47.652962 sshd[7663]: Invalid user user from 144.225.8.54 port 57106 Jul 21 12:39:47.712780 sshd[7663]: Connection closed by invalid user user 144.225.8.54 port 57106 [preauth] Jul 21 12:39:47.712000 audit[7663]: AUDIT1109 pid=7663 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:47.716972 systemd[1]: sshd@165-4186-172.31.16.165:22-144.225.8.54:57106.service: Deactivated successfully. Jul 21 12:39:47.716000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@165-4186-172.31.16.165:22-144.225.8.54:57106 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:47.787184 systemd[1]: Started sshd@166-4187-172.31.16.165:22-144.225.8.54:53130.service - OpenSSH per-connection server daemon (144.225.8.54:53130). Jul 21 12:39:47.786000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@166-4187-172.31.16.165:22-144.225.8.54:53130 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.036971 sshd[7669]: Invalid user user from 144.225.8.54 port 53130 Jul 21 12:39:48.097919 sshd[7669]: Connection closed by invalid user user 144.225.8.54 port 53130 [preauth] Jul 21 12:39:48.097000 audit[7669]: AUDIT1109 pid=7669 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:48.099377 kernel: kauditd_printk_skb: 48 callbacks suppressed Jul 21 12:39:48.099457 kernel: audit: type=1109 audit(1784637588.097:1282): pid=7669 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:48.105710 systemd[1]: sshd@166-4187-172.31.16.165:22-144.225.8.54:53130.service: Deactivated successfully. Jul 21 12:39:48.106000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@166-4187-172.31.16.165:22-144.225.8.54:53130 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.113261 kernel: audit: type=1131 audit(1784637588.106:1283): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@166-4187-172.31.16.165:22-144.225.8.54:53130 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.174306 systemd[1]: Started sshd@167-4188-172.31.16.165:22-144.225.8.54:53142.service - OpenSSH per-connection server daemon (144.225.8.54:53142). Jul 21 12:39:48.173000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@167-4188-172.31.16.165:22-144.225.8.54:53142 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.182266 kernel: audit: type=1130 audit(1784637588.173:1284): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@167-4188-172.31.16.165:22-144.225.8.54:53142 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.418027 sshd[7675]: Invalid user user from 144.225.8.54 port 53142 Jul 21 12:39:48.479989 sshd[7675]: Connection closed by invalid user user 144.225.8.54 port 53142 [preauth] Jul 21 12:39:48.479000 audit[7675]: AUDIT1109 pid=7675 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:48.484534 systemd[1]: sshd@167-4188-172.31.16.165:22-144.225.8.54:53142.service: Deactivated successfully. Jul 21 12:39:48.485000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@167-4188-172.31.16.165:22-144.225.8.54:53142 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.491248 kernel: audit: type=1109 audit(1784637588.479:1285): pid=7675 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:48.491363 kernel: audit: type=1131 audit(1784637588.485:1286): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@167-4188-172.31.16.165:22-144.225.8.54:53142 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.557000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@168-4189-172.31.16.165:22-144.225.8.54:53154 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.556945 systemd[1]: Started sshd@168-4189-172.31.16.165:22-144.225.8.54:53154.service - OpenSSH per-connection server daemon (144.225.8.54:53154). Jul 21 12:39:48.568398 kernel: audit: type=1130 audit(1784637588.557:1287): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@168-4189-172.31.16.165:22-144.225.8.54:53154 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.810190 sshd[7681]: Invalid user user from 144.225.8.54 port 53154 Jul 21 12:39:48.871183 sshd[7681]: Connection closed by invalid user user 144.225.8.54 port 53154 [preauth] Jul 21 12:39:48.870000 audit[7681]: AUDIT1109 pid=7681 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:48.878256 kernel: audit: type=1109 audit(1784637588.870:1288): pid=7681 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:48.878574 systemd[1]: sshd@168-4189-172.31.16.165:22-144.225.8.54:53154.service: Deactivated successfully. Jul 21 12:39:48.878000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@168-4189-172.31.16.165:22-144.225.8.54:53154 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.887246 kernel: audit: type=1131 audit(1784637588.878:1289): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@168-4189-172.31.16.165:22-144.225.8.54:53154 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.914046 kubelet[4002]: I0721 12:39:48.913554 4002 prober_manager.go:312] "Failed to trigger a manual run" probe="Readiness" Jul 21 12:39:48.954984 systemd[1]: Started sshd@169-4190-172.31.16.165:22-144.225.8.54:53168.service - OpenSSH per-connection server daemon (144.225.8.54:53168). Jul 21 12:39:48.954000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@169-4190-172.31.16.165:22-144.225.8.54:53168 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:48.969301 kernel: audit: type=1130 audit(1784637588.954:1290): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@169-4190-172.31.16.165:22-144.225.8.54:53168 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:49.078000 audit[7691]: NETFILTER_CFG table=filter:137 family=2 entries=10 op=nft_register_rule pid=7691 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:49.078000 audit[7691]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=3760 a0=3 a1=fffff3a8fbd0 a2=0 a3=1 items=0 ppid=4148 pid=7691 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:49.086355 kernel: audit: type=1325 audit(1784637589.078:1291): table=filter:137 family=2 entries=10 op=nft_register_rule pid=7691 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:49.078000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:49.100000 audit[7691]: NETFILTER_CFG table=nat:138 family=2 entries=36 op=nft_register_chain pid=7691 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:49.100000 audit[7691]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=12004 a0=3 a1=fffff3a8fbd0 a2=0 a3=1 items=0 ppid=4148 pid=7691 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:49.100000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:49.239167 sshd[7687]: Invalid user user from 144.225.8.54 port 53168 Jul 21 12:39:49.300000 audit[7687]: AUDIT1109 pid=7687 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:49.301736 sshd[7687]: Connection closed by invalid user user 144.225.8.54 port 53168 [preauth] Jul 21 12:39:49.305008 systemd[1]: sshd@169-4190-172.31.16.165:22-144.225.8.54:53168.service: Deactivated successfully. Jul 21 12:39:49.304000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@169-4190-172.31.16.165:22-144.225.8.54:53168 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:49.374766 systemd[1]: Started sshd@170-4191-172.31.16.165:22-144.225.8.54:53182.service - OpenSSH per-connection server daemon (144.225.8.54:53182). Jul 21 12:39:49.373000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@170-4191-172.31.16.165:22-144.225.8.54:53182 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:49.620010 sshd[7695]: Invalid user user from 144.225.8.54 port 53182 Jul 21 12:39:49.679694 sshd[7695]: Connection closed by invalid user user 144.225.8.54 port 53182 [preauth] Jul 21 12:39:49.679000 audit[7695]: AUDIT1109 pid=7695 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:49.683615 systemd[1]: sshd@170-4191-172.31.16.165:22-144.225.8.54:53182.service: Deactivated successfully. Jul 21 12:39:49.683000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@170-4191-172.31.16.165:22-144.225.8.54:53182 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:49.751000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@171-4192-172.31.16.165:22-144.225.8.54:53190 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:49.752727 systemd[1]: Started sshd@171-4192-172.31.16.165:22-144.225.8.54:53190.service - OpenSSH per-connection server daemon (144.225.8.54:53190). Jul 21 12:39:50.014895 sshd[7701]: Invalid user user from 144.225.8.54 port 53190 Jul 21 12:39:50.075429 sshd[7701]: Connection closed by invalid user user 144.225.8.54 port 53190 [preauth] Jul 21 12:39:50.074000 audit[7701]: AUDIT1109 pid=7701 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:50.084128 systemd[1]: sshd@171-4192-172.31.16.165:22-144.225.8.54:53190.service: Deactivated successfully. Jul 21 12:39:50.084000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@171-4192-172.31.16.165:22-144.225.8.54:53190 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:50.152798 systemd[1]: Started sshd@172-77-172.31.16.165:22-144.225.8.54:53204.service - OpenSSH per-connection server daemon (144.225.8.54:53204). Jul 21 12:39:50.151000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@172-77-172.31.16.165:22-144.225.8.54:53204 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:50.411663 sshd[7707]: Invalid user user from 144.225.8.54 port 53204 Jul 21 12:39:50.472273 sshd[7707]: Connection closed by invalid user user 144.225.8.54 port 53204 [preauth] Jul 21 12:39:50.472000 audit[7707]: AUDIT1109 pid=7707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:50.479023 systemd[1]: sshd@172-77-172.31.16.165:22-144.225.8.54:53204.service: Deactivated successfully. Jul 21 12:39:50.479000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@172-77-172.31.16.165:22-144.225.8.54:53204 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:50.548000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@173-4193-172.31.16.165:22-144.225.8.54:53206 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:50.549500 systemd[1]: Started sshd@173-4193-172.31.16.165:22-144.225.8.54:53206.service - OpenSSH per-connection server daemon (144.225.8.54:53206). Jul 21 12:39:50.802660 sshd[7713]: Invalid user user from 144.225.8.54 port 53206 Jul 21 12:39:50.863503 sshd[7713]: Connection closed by invalid user user 144.225.8.54 port 53206 [preauth] Jul 21 12:39:50.863000 audit[7713]: AUDIT1109 pid=7713 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:50.867494 systemd[1]: sshd@173-4193-172.31.16.165:22-144.225.8.54:53206.service: Deactivated successfully. Jul 21 12:39:50.868000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@173-4193-172.31.16.165:22-144.225.8.54:53206 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:50.938000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@174-4194-172.31.16.165:22-144.225.8.54:53214 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:50.939821 systemd[1]: Started sshd@174-4194-172.31.16.165:22-144.225.8.54:53214.service - OpenSSH per-connection server daemon (144.225.8.54:53214). Jul 21 12:39:51.194437 sshd[7719]: Invalid user user from 144.225.8.54 port 53214 Jul 21 12:39:51.256271 sshd[7719]: Connection closed by invalid user user 144.225.8.54 port 53214 [preauth] Jul 21 12:39:51.255000 audit[7719]: AUDIT1109 pid=7719 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:51.260050 systemd[1]: sshd@174-4194-172.31.16.165:22-144.225.8.54:53214.service: Deactivated successfully. Jul 21 12:39:51.259000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@174-4194-172.31.16.165:22-144.225.8.54:53214 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:51.331000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@175-4195-172.31.16.165:22-144.225.8.54:53218 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:51.332748 systemd[1]: Started sshd@175-4195-172.31.16.165:22-144.225.8.54:53218.service - OpenSSH per-connection server daemon (144.225.8.54:53218). Jul 21 12:39:51.578000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@176-4196-172.31.16.165:22-20.76.1.115:40134 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:51.579747 systemd[1]: Started sshd@176-4196-172.31.16.165:22-20.76.1.115:40134.service - OpenSSH per-connection server daemon (20.76.1.115:40134). Jul 21 12:39:51.592649 sshd[7725]: Invalid user user from 144.225.8.54 port 53218 Jul 21 12:39:51.652433 sshd[7725]: Connection closed by invalid user user 144.225.8.54 port 53218 [preauth] Jul 21 12:39:51.651000 audit[7725]: AUDIT1109 pid=7725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:51.656103 systemd[1]: sshd@175-4195-172.31.16.165:22-144.225.8.54:53218.service: Deactivated successfully. Jul 21 12:39:51.656000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@175-4195-172.31.16.165:22-144.225.8.54:53218 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:51.726000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@177-4197-172.31.16.165:22-144.225.8.54:53234 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:51.727531 systemd[1]: Started sshd@177-4197-172.31.16.165:22-144.225.8.54:53234.service - OpenSSH per-connection server daemon (144.225.8.54:53234). Jul 21 12:39:51.975440 sshd[7735]: Invalid user user from 144.225.8.54 port 53234 Jul 21 12:39:52.036561 sshd[7735]: Connection closed by invalid user user 144.225.8.54 port 53234 [preauth] Jul 21 12:39:52.036000 audit[7735]: AUDIT1109 pid=7735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:52.041322 systemd[1]: sshd@177-4197-172.31.16.165:22-144.225.8.54:53234.service: Deactivated successfully. Jul 21 12:39:52.041000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@177-4197-172.31.16.165:22-144.225.8.54:53234 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:52.111728 systemd[1]: Started sshd@178-4198-172.31.16.165:22-144.225.8.54:53246.service - OpenSSH per-connection server daemon (144.225.8.54:53246). Jul 21 12:39:52.110000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@178-4198-172.31.16.165:22-144.225.8.54:53246 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:52.369068 sshd[7741]: Invalid user user from 144.225.8.54 port 53246 Jul 21 12:39:52.369000 audit[7769]: NETFILTER_CFG table=filter:139 family=2 entries=9 op=nft_register_rule pid=7769 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:52.369000 audit[7769]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=3016 a0=3 a1=ffffde678850 a2=0 a3=1 items=0 ppid=4148 pid=7769 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:52.369000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:52.378000 audit[7769]: NETFILTER_CFG table=nat:140 family=2 entries=31 op=nft_register_chain pid=7769 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:39:52.378000 audit[7769]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=10884 a0=3 a1=ffffde678850 a2=0 a3=1 items=0 ppid=4148 pid=7769 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:52.378000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:39:52.430311 sshd[7741]: Connection closed by invalid user user 144.225.8.54 port 53246 [preauth] Jul 21 12:39:52.429000 audit[7741]: AUDIT1109 pid=7741 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:52.433901 systemd[1]: sshd@178-4198-172.31.16.165:22-144.225.8.54:53246.service: Deactivated successfully. Jul 21 12:39:52.436000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@178-4198-172.31.16.165:22-144.225.8.54:53246 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:52.457000 audit[7729]: AUDIT1101 pid=7729 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:52.458836 sshd[7729]: Accepted publickey for core from 20.76.1.115 port 40134 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:39:52.460000 audit[7729]: AUDIT1103 pid=7729 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:52.460000 audit[7729]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=fffff7df1310 a2=3 a3=0 items=0 ppid=1 pid=7729 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:52.460000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:39:52.463036 sshd-session[7729]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:39:52.477423 systemd-logind[2347]: New session '15' of user 'core' with class 'user' and type 'tty'. Jul 21 12:39:52.484545 systemd[1]: Started session-15.scope - Session 15 of User core. Jul 21 12:39:52.505000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@179-4199-172.31.16.165:22-144.225.8.54:53260 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:52.506804 systemd[1]: Started sshd@179-4199-172.31.16.165:22-144.225.8.54:53260.service - OpenSSH per-connection server daemon (144.225.8.54:53260). Jul 21 12:39:52.508000 audit[7729]: AUDIT1105 pid=7729 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:52.512000 audit[7782]: AUDIT1103 pid=7782 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:52.758494 sshd[7781]: Invalid user user from 144.225.8.54 port 53260 Jul 21 12:39:52.822123 sshd[7781]: Connection closed by invalid user user 144.225.8.54 port 53260 [preauth] Jul 21 12:39:52.821000 audit[7781]: AUDIT1109 pid=7781 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:52.826620 systemd[1]: sshd@179-4199-172.31.16.165:22-144.225.8.54:53260.service: Deactivated successfully. Jul 21 12:39:52.828000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@179-4199-172.31.16.165:22-144.225.8.54:53260 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:52.903104 systemd[1]: Started sshd@180-4200-172.31.16.165:22-144.225.8.54:53262.service - OpenSSH per-connection server daemon (144.225.8.54:53262). Jul 21 12:39:52.903000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@180-4200-172.31.16.165:22-144.225.8.54:53262 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.082450 sshd[7782]: Connection closed by 20.76.1.115 port 40134 Jul 21 12:39:53.086684 sshd-session[7729]: pam_unix(sshd:session): session closed for user core Jul 21 12:39:53.086000 audit[7729]: AUDIT1106 pid=7729 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:53.088000 audit[7729]: AUDIT1104 pid=7729 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:53.097622 systemd[1]: sshd@176-4196-172.31.16.165:22-20.76.1.115:40134.service: Deactivated successfully. Jul 21 12:39:53.099000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@176-4196-172.31.16.165:22-20.76.1.115:40134 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.106175 kernel: kauditd_printk_skb: 51 callbacks suppressed Jul 21 12:39:53.106662 kernel: audit: type=1131 audit(1784637593.099:1333): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@176-4196-172.31.16.165:22-20.76.1.115:40134 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.114180 systemd[1]: session-15.scope: Deactivated successfully. Jul 21 12:39:53.122192 systemd-logind[2347]: Session 15 logged out. Waiting for processes to exit. Jul 21 12:39:53.130141 systemd-logind[2347]: Removed session 15. Jul 21 12:39:53.173968 sshd[7795]: Invalid user user from 144.225.8.54 port 53262 Jul 21 12:39:53.233688 sshd[7795]: Connection closed by invalid user user 144.225.8.54 port 53262 [preauth] Jul 21 12:39:53.234000 audit[7795]: AUDIT1109 pid=7795 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:53.239289 systemd[1]: sshd@180-4200-172.31.16.165:22-144.225.8.54:53262.service: Deactivated successfully. Jul 21 12:39:53.239000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@180-4200-172.31.16.165:22-144.225.8.54:53262 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.249135 kernel: audit: type=1109 audit(1784637593.234:1334): pid=7795 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:53.249722 kernel: audit: type=1131 audit(1784637593.239:1335): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@180-4200-172.31.16.165:22-144.225.8.54:53262 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.268018 systemd[1]: Started sshd@181-4201-172.31.16.165:22-20.76.1.115:40138.service - OpenSSH per-connection server daemon (20.76.1.115:40138). Jul 21 12:39:53.268000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@181-4201-172.31.16.165:22-20.76.1.115:40138 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.280167 kernel: audit: type=1130 audit(1784637593.268:1336): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@181-4201-172.31.16.165:22-20.76.1.115:40138 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.315639 systemd[1]: Started sshd@182-4202-172.31.16.165:22-144.225.8.54:53266.service - OpenSSH per-connection server daemon (144.225.8.54:53266). Jul 21 12:39:53.316000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@182-4202-172.31.16.165:22-144.225.8.54:53266 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.326459 kernel: audit: type=1130 audit(1784637593.316:1337): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@182-4202-172.31.16.165:22-144.225.8.54:53266 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.659022 sshd[7806]: Invalid user user from 144.225.8.54 port 53266 Jul 21 12:39:53.720998 sshd[7806]: Connection closed by invalid user user 144.225.8.54 port 53266 [preauth] Jul 21 12:39:53.721000 audit[7806]: AUDIT1109 pid=7806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:53.730707 systemd[1]: sshd@182-4202-172.31.16.165:22-144.225.8.54:53266.service: Deactivated successfully. Jul 21 12:39:53.731332 kernel: audit: type=1109 audit(1784637593.721:1338): pid=7806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:53.733000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@182-4202-172.31.16.165:22-144.225.8.54:53266 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.744543 kernel: audit: type=1131 audit(1784637593.733:1339): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@182-4202-172.31.16.165:22-144.225.8.54:53266 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.794000 audit[7827]: NETFILTER_CFG table=filter:141 family=2 entries=233 op=nft_register_chain pid=7827 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:53.802681 systemd[1]: Started sshd@183-4203-172.31.16.165:22-144.225.8.54:53282.service - OpenSSH per-connection server daemon (144.225.8.54:53282). Jul 21 12:39:53.802000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@183-4203-172.31.16.165:22-144.225.8.54:53282 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.810364 kernel: audit: type=1325 audit(1784637593.794:1340): table=filter:141 family=2 entries=233 op=nft_register_chain pid=7827 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:53.810426 kernel: audit: type=1130 audit(1784637593.802:1341): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@183-4203-172.31.16.165:22-144.225.8.54:53282 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:53.794000 audit[7827]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=107604 a0=3 a1=ffffc1370800 a2=0 a3=ffff918037e0 items=0 ppid=5430 pid=7827 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:53.821671 kernel: audit: type=1300 audit(1784637593.794:1340): arch=c00000b7 syscall=211 success=yes exit=107604 a0=3 a1=ffffc1370800 a2=0 a3=ffff918037e0 items=0 ppid=5430 pid=7827 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:53.794000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:54.056000 audit[7846]: NETFILTER_CFG table=filter:142 family=2 entries=223 op=nft_register_chain pid=7846 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:39:54.056000 audit[7846]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=101624 a0=3 a1=ffffeba50cd0 a2=0 a3=ffffa7df27e0 items=0 ppid=5430 pid=7846 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:54.056000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:39:54.081383 sshd[7829]: Invalid user user from 144.225.8.54 port 53282 Jul 21 12:39:54.144612 sshd[7829]: Connection closed by invalid user user 144.225.8.54 port 53282 [preauth] Jul 21 12:39:54.144000 audit[7829]: AUDIT1109 pid=7829 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:54.150805 systemd[1]: sshd@183-4203-172.31.16.165:22-144.225.8.54:53282.service: Deactivated successfully. Jul 21 12:39:54.152000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@183-4203-172.31.16.165:22-144.225.8.54:53282 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:54.224000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@184-4204-172.31.16.165:22-144.225.8.54:53290 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:54.224452 systemd[1]: Started sshd@184-4204-172.31.16.165:22-144.225.8.54:53290.service - OpenSSH per-connection server daemon (144.225.8.54:53290). Jul 21 12:39:54.229000 audit[7804]: AUDIT1101 pid=7804 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:54.231532 sshd[7804]: Accepted publickey for core from 20.76.1.115 port 40138 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:39:54.233000 audit[7804]: AUDIT1103 pid=7804 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:54.234000 audit[7804]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffc09058e0 a2=3 a3=0 items=0 ppid=1 pid=7804 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=16 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:54.234000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:39:54.237689 sshd-session[7804]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:39:54.261185 systemd-logind[2347]: New session '16' of user 'core' with class 'user' and type 'tty'. Jul 21 12:39:54.266567 systemd[1]: Started session-16.scope - Session 16 of User core. Jul 21 12:39:54.313000 audit[7804]: AUDIT1105 pid=7804 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:54.321000 audit[7854]: AUDIT1103 pid=7854 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:54.538411 sshd[7851]: Invalid user user from 144.225.8.54 port 53290 Jul 21 12:39:54.599000 audit[7851]: AUDIT1109 pid=7851 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:54.599990 sshd[7851]: Connection closed by invalid user user 144.225.8.54 port 53290 [preauth] Jul 21 12:39:54.602935 systemd[1]: sshd@184-4204-172.31.16.165:22-144.225.8.54:53290.service: Deactivated successfully. Jul 21 12:39:54.603000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@184-4204-172.31.16.165:22-144.225.8.54:53290 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:54.692764 systemd[1]: Started sshd@185-4205-172.31.16.165:22-144.225.8.54:53292.service - OpenSSH per-connection server daemon (144.225.8.54:53292). Jul 21 12:39:54.692000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@185-4205-172.31.16.165:22-144.225.8.54:53292 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:54.953396 sshd[7860]: Invalid user user from 144.225.8.54 port 53292 Jul 21 12:39:55.013375 sshd[7860]: Connection closed by invalid user user 144.225.8.54 port 53292 [preauth] Jul 21 12:39:55.013000 audit[7860]: AUDIT1109 pid=7860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:55.016403 systemd[1]: sshd@185-4205-172.31.16.165:22-144.225.8.54:53292.service: Deactivated successfully. Jul 21 12:39:55.016000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@185-4205-172.31.16.165:22-144.225.8.54:53292 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:55.093000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@186-4206-172.31.16.165:22-144.225.8.54:53304 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:55.093810 systemd[1]: Started sshd@186-4206-172.31.16.165:22-144.225.8.54:53304.service - OpenSSH per-connection server daemon (144.225.8.54:53304). Jul 21 12:39:55.351076 sshd[7866]: Invalid user user from 144.225.8.54 port 53304 Jul 21 12:39:55.411647 sshd[7866]: Connection closed by invalid user user 144.225.8.54 port 53304 [preauth] Jul 21 12:39:55.412000 audit[7866]: AUDIT1109 pid=7866 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:55.415486 systemd[1]: sshd@186-4206-172.31.16.165:22-144.225.8.54:53304.service: Deactivated successfully. Jul 21 12:39:55.416000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@186-4206-172.31.16.165:22-144.225.8.54:53304 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:55.488892 systemd[1]: Started sshd@187-78-172.31.16.165:22-144.225.8.54:53320.service - OpenSSH per-connection server daemon (144.225.8.54:53320). Jul 21 12:39:55.489000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@187-78-172.31.16.165:22-144.225.8.54:53320 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:55.737885 sshd[7876]: Invalid user user from 144.225.8.54 port 53320 Jul 21 12:39:55.801561 sshd[7876]: Connection closed by invalid user user 144.225.8.54 port 53320 [preauth] Jul 21 12:39:55.801000 audit[7876]: AUDIT1109 pid=7876 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:55.806175 systemd[1]: sshd@187-78-172.31.16.165:22-144.225.8.54:53320.service: Deactivated successfully. Jul 21 12:39:55.808000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@187-78-172.31.16.165:22-144.225.8.54:53320 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:55.879000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@188-79-172.31.16.165:22-144.225.8.54:53324 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:55.879827 systemd[1]: Started sshd@188-79-172.31.16.165:22-144.225.8.54:53324.service - OpenSSH per-connection server daemon (144.225.8.54:53324). Jul 21 12:39:56.162587 sshd[7904]: Invalid user user from 144.225.8.54 port 53324 Jul 21 12:39:56.224178 sshd[7904]: Connection closed by invalid user user 144.225.8.54 port 53324 [preauth] Jul 21 12:39:56.224000 audit[7904]: AUDIT1109 pid=7904 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:56.228041 systemd[1]: sshd@188-79-172.31.16.165:22-144.225.8.54:53324.service: Deactivated successfully. Jul 21 12:39:56.228000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@188-79-172.31.16.165:22-144.225.8.54:53324 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:56.317000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@189-4207-172.31.16.165:22-144.225.8.54:53340 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:56.317272 systemd[1]: Started sshd@189-4207-172.31.16.165:22-144.225.8.54:53340.service - OpenSSH per-connection server daemon (144.225.8.54:53340). Jul 21 12:39:56.590301 sshd[7930]: Invalid user user from 144.225.8.54 port 53340 Jul 21 12:39:56.650960 sshd[7930]: Connection closed by invalid user user 144.225.8.54 port 53340 [preauth] Jul 21 12:39:56.651000 audit[7930]: AUDIT1109 pid=7930 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:56.654746 systemd[1]: sshd@189-4207-172.31.16.165:22-144.225.8.54:53340.service: Deactivated successfully. Jul 21 12:39:56.655000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@189-4207-172.31.16.165:22-144.225.8.54:53340 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:56.724000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@190-80-172.31.16.165:22-144.225.8.54:53346 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:56.724751 systemd[1]: Started sshd@190-80-172.31.16.165:22-144.225.8.54:53346.service - OpenSSH per-connection server daemon (144.225.8.54:53346). Jul 21 12:39:56.981395 sshd[7940]: Invalid user user from 144.225.8.54 port 53346 Jul 21 12:39:57.040795 sshd[7940]: Connection closed by invalid user user 144.225.8.54 port 53346 [preauth] Jul 21 12:39:57.042000 audit[7940]: AUDIT1109 pid=7940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:57.047818 systemd[1]: sshd@190-80-172.31.16.165:22-144.225.8.54:53346.service: Deactivated successfully. Jul 21 12:39:57.050000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@190-80-172.31.16.165:22-144.225.8.54:53346 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:57.129039 systemd[1]: Started sshd@191-81-172.31.16.165:22-144.225.8.54:53348.service - OpenSSH per-connection server daemon (144.225.8.54:53348). Jul 21 12:39:57.129000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@191-81-172.31.16.165:22-144.225.8.54:53348 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:57.292247 sshd[7854]: Connection closed by 20.76.1.115 port 40138 Jul 21 12:39:57.292495 sshd-session[7804]: pam_unix(sshd:session): session closed for user core Jul 21 12:39:57.295000 audit[7804]: AUDIT1106 pid=7804 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:57.296000 audit[7804]: AUDIT1104 pid=7804 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:57.300496 systemd[1]: sshd@181-4201-172.31.16.165:22-20.76.1.115:40138.service: Deactivated successfully. Jul 21 12:39:57.303000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@181-4201-172.31.16.165:22-20.76.1.115:40138 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:57.309702 systemd[1]: session-16.scope: Deactivated successfully. Jul 21 12:39:57.319874 systemd-logind[2347]: Session 16 logged out. Waiting for processes to exit. Jul 21 12:39:57.325399 systemd-logind[2347]: Removed session 16. Jul 21 12:39:57.409135 sshd[7947]: Invalid user ubuntu from 144.225.8.54 port 53348 Jul 21 12:39:57.472039 systemd[1]: Started sshd@192-4208-172.31.16.165:22-20.76.1.115:40144.service - OpenSSH per-connection server daemon (20.76.1.115:40144). Jul 21 12:39:57.472000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@192-4208-172.31.16.165:22-20.76.1.115:40144 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:57.473824 sshd[7947]: Connection closed by invalid user ubuntu 144.225.8.54 port 53348 [preauth] Jul 21 12:39:57.475000 audit[7947]: AUDIT1109 pid=7947 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:57.481961 systemd[1]: sshd@191-81-172.31.16.165:22-144.225.8.54:53348.service: Deactivated successfully. Jul 21 12:39:57.485000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@191-81-172.31.16.165:22-144.225.8.54:53348 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:57.549000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@193-4209-172.31.16.165:22-144.225.8.54:53350 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:57.549812 systemd[1]: Started sshd@193-4209-172.31.16.165:22-144.225.8.54:53350.service - OpenSSH per-connection server daemon (144.225.8.54:53350). Jul 21 12:39:57.800412 sshd[7960]: Invalid user ubuntu from 144.225.8.54 port 53350 Jul 21 12:39:57.859722 sshd[7960]: Connection closed by invalid user ubuntu 144.225.8.54 port 53350 [preauth] Jul 21 12:39:57.860000 audit[7960]: AUDIT1109 pid=7960 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:57.863540 systemd[1]: sshd@193-4209-172.31.16.165:22-144.225.8.54:53350.service: Deactivated successfully. Jul 21 12:39:57.864000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@193-4209-172.31.16.165:22-144.225.8.54:53350 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:57.938799 systemd[1]: Started sshd@194-4210-172.31.16.165:22-144.225.8.54:46638.service - OpenSSH per-connection server daemon (144.225.8.54:46638). Jul 21 12:39:57.938000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@194-4210-172.31.16.165:22-144.225.8.54:46638 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:58.199998 sshd[7966]: Invalid user ubuntu from 144.225.8.54 port 46638 Jul 21 12:39:58.262094 sshd[7966]: Connection closed by invalid user ubuntu 144.225.8.54 port 46638 [preauth] Jul 21 12:39:58.262000 audit[7966]: AUDIT1109 pid=7966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:58.264606 kernel: kauditd_printk_skb: 45 callbacks suppressed Jul 21 12:39:58.264782 kernel: audit: type=1109 audit(1784637598.262:1382): pid=7966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:58.268875 systemd[1]: sshd@194-4210-172.31.16.165:22-144.225.8.54:46638.service: Deactivated successfully. Jul 21 12:39:58.269000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@194-4210-172.31.16.165:22-144.225.8.54:46638 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:58.274796 kernel: audit: type=1131 audit(1784637598.269:1383): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@194-4210-172.31.16.165:22-144.225.8.54:46638 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:58.338454 systemd[1]: Started sshd@195-4211-172.31.16.165:22-144.225.8.54:46650.service - OpenSSH per-connection server daemon (144.225.8.54:46650). Jul 21 12:39:58.338000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@195-4211-172.31.16.165:22-144.225.8.54:46650 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:58.348365 kernel: audit: type=1130 audit(1784637598.338:1384): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@195-4211-172.31.16.165:22-144.225.8.54:46650 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:58.364000 audit[7954]: AUDIT1101 pid=7954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:58.371348 sshd[7954]: Accepted publickey for core from 20.76.1.115 port 40144 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:39:58.373000 audit[7954]: AUDIT1103 pid=7954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:58.381092 kernel: audit: type=1101 audit(1784637598.364:1385): pid=7954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:58.380760 sshd-session[7954]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:39:58.381277 kernel: audit: type=1103 audit(1784637598.373:1386): pid=7954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:58.385660 kernel: audit: type=1006 audit(1784637598.373:1387): pid=7954 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=17 res=1 Jul 21 12:39:58.373000 audit[7954]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffd0c74420 a2=3 a3=0 items=0 ppid=1 pid=7954 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=17 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:58.392526 kernel: audit: type=1300 audit(1784637598.373:1387): arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffd0c74420 a2=3 a3=0 items=0 ppid=1 pid=7954 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=17 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:39:58.373000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:39:58.396263 kernel: audit: type=1327 audit(1784637598.373:1387): proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:39:58.406320 systemd-logind[2347]: New session '17' of user 'core' with class 'user' and type 'tty'. Jul 21 12:39:58.411685 systemd[1]: Started session-17.scope - Session 17 of User core. Jul 21 12:39:58.429000 audit[7954]: AUDIT1105 pid=7954 uid=0 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:58.432000 audit[7976]: AUDIT1103 pid=7976 uid=0 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:58.441588 kernel: audit: type=1105 audit(1784637598.429:1388): pid=7954 uid=0 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:58.441698 kernel: audit: type=1103 audit(1784637598.432:1389): pid=7976 uid=0 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:39:58.604598 sshd[7972]: Invalid user ubuntu from 144.225.8.54 port 46650 Jul 21 12:39:58.664558 sshd[7972]: Connection closed by invalid user ubuntu 144.225.8.54 port 46650 [preauth] Jul 21 12:39:58.665000 audit[7972]: AUDIT1109 pid=7972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:58.668365 systemd[1]: sshd@195-4211-172.31.16.165:22-144.225.8.54:46650.service: Deactivated successfully. Jul 21 12:39:58.668000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@195-4211-172.31.16.165:22-144.225.8.54:46650 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:58.743483 systemd[1]: Started sshd@196-82-172.31.16.165:22-144.225.8.54:46662.service - OpenSSH per-connection server daemon (144.225.8.54:46662). Jul 21 12:39:58.743000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@196-82-172.31.16.165:22-144.225.8.54:46662 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:59.004855 sshd[7985]: Invalid user ubuntu from 144.225.8.54 port 46662 Jul 21 12:39:59.079280 sshd[7985]: Connection closed by invalid user ubuntu 144.225.8.54 port 46662 [preauth] Jul 21 12:39:59.080000 audit[7985]: AUDIT1109 pid=7985 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:59.084427 systemd[1]: sshd@196-82-172.31.16.165:22-144.225.8.54:46662.service: Deactivated successfully. Jul 21 12:39:59.086000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@196-82-172.31.16.165:22-144.225.8.54:46662 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:59.158000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@197-4212-172.31.16.165:22-144.225.8.54:46664 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:59.158540 systemd[1]: Started sshd@197-4212-172.31.16.165:22-144.225.8.54:46664.service - OpenSSH per-connection server daemon (144.225.8.54:46664). Jul 21 12:39:59.426834 sshd[7991]: Invalid user ubuntu from 144.225.8.54 port 46664 Jul 21 12:39:59.486742 sshd[7991]: Connection closed by invalid user ubuntu 144.225.8.54 port 46664 [preauth] Jul 21 12:39:59.488000 audit[7991]: AUDIT1109 pid=7991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:59.492830 systemd[1]: sshd@197-4212-172.31.16.165:22-144.225.8.54:46664.service: Deactivated successfully. Jul 21 12:39:59.494000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@197-4212-172.31.16.165:22-144.225.8.54:46664 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:59.561915 systemd[1]: Started sshd@198-83-172.31.16.165:22-144.225.8.54:46674.service - OpenSSH per-connection server daemon (144.225.8.54:46674). Jul 21 12:39:59.562000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@198-83-172.31.16.165:22-144.225.8.54:46674 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:39:59.888419 sshd[8011]: Invalid user ubuntu from 144.225.8.54 port 46674 Jul 21 12:39:59.949093 sshd[8011]: Connection closed by invalid user ubuntu 144.225.8.54 port 46674 [preauth] Jul 21 12:39:59.950000 audit[8011]: AUDIT1109 pid=8011 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:39:59.953519 systemd[1]: sshd@198-83-172.31.16.165:22-144.225.8.54:46674.service: Deactivated successfully. Jul 21 12:39:59.956000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@198-83-172.31.16.165:22-144.225.8.54:46674 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:00.037000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@199-84-172.31.16.165:22-144.225.8.54:46676 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:00.037523 systemd[1]: Started sshd@199-84-172.31.16.165:22-144.225.8.54:46676.service - OpenSSH per-connection server daemon (144.225.8.54:46676). Jul 21 12:40:00.257000 audit[8028]: NETFILTER_CFG table=filter:143 family=2 entries=20 op=nft_register_rule pid=8028 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:40:00.257000 audit[8028]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=11944 a0=3 a1=ffffdeb010a0 a2=0 a3=1 items=0 ppid=4148 pid=8028 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:00.257000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:40:00.263000 audit[8028]: NETFILTER_CFG table=nat:144 family=2 entries=26 op=nft_register_rule pid=8028 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:40:00.263000 audit[8028]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=8076 a0=3 a1=ffffdeb010a0 a2=0 a3=1 items=0 ppid=4148 pid=8028 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:00.263000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:40:00.317551 sshd[8017]: Invalid user ubuntu from 144.225.8.54 port 46676 Jul 21 12:40:00.368874 sshd[7976]: Connection closed by 20.76.1.115 port 40144 Jul 21 12:40:00.369308 sshd-session[7954]: pam_unix(sshd:session): session closed for user core Jul 21 12:40:00.370000 audit[7954]: AUDIT1106 pid=7954 uid=0 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:00.371000 audit[7954]: AUDIT1104 pid=7954 uid=0 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:00.375933 systemd[1]: sshd@192-4208-172.31.16.165:22-20.76.1.115:40144.service: Deactivated successfully. Jul 21 12:40:00.377000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@192-4208-172.31.16.165:22-20.76.1.115:40144 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:00.381413 sshd[8017]: Connection closed by invalid user ubuntu 144.225.8.54 port 46676 [preauth] Jul 21 12:40:00.381815 systemd[1]: session-17.scope: Deactivated successfully. Jul 21 12:40:00.383000 audit[8017]: AUDIT1109 pid=8017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:00.394150 systemd-logind[2347]: Session 17 logged out. Waiting for processes to exit. Jul 21 12:40:00.395000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@199-84-172.31.16.165:22-144.225.8.54:46676 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:00.394750 systemd[1]: sshd@199-84-172.31.16.165:22-144.225.8.54:46676.service: Deactivated successfully. Jul 21 12:40:00.412032 systemd-logind[2347]: Removed session 17. Jul 21 12:40:00.454773 systemd[1]: Started sshd@200-85-172.31.16.165:22-144.225.8.54:46686.service - OpenSSH per-connection server daemon (144.225.8.54:46686). Jul 21 12:40:00.454000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@200-85-172.31.16.165:22-144.225.8.54:46686 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:00.536000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@201-86-172.31.16.165:22-20.76.1.115:40146 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:00.536732 systemd[1]: Started sshd@201-86-172.31.16.165:22-20.76.1.115:40146.service - OpenSSH per-connection server daemon (20.76.1.115:40146). Jul 21 12:40:00.708088 sshd[8038]: Invalid user ubuntu from 144.225.8.54 port 46686 Jul 21 12:40:00.767744 sshd[8038]: Connection closed by invalid user ubuntu 144.225.8.54 port 46686 [preauth] Jul 21 12:40:00.768000 audit[8038]: AUDIT1109 pid=8038 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:00.772822 systemd[1]: sshd@200-85-172.31.16.165:22-144.225.8.54:46686.service: Deactivated successfully. Jul 21 12:40:00.775000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@200-85-172.31.16.165:22-144.225.8.54:46686 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:00.846000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@202-87-172.31.16.165:22-144.225.8.54:46702 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:00.846765 systemd[1]: Started sshd@202-87-172.31.16.165:22-144.225.8.54:46702.service - OpenSSH per-connection server daemon (144.225.8.54:46702). Jul 21 12:40:01.088014 sshd[8048]: Invalid user ubuntu from 144.225.8.54 port 46702 Jul 21 12:40:01.147803 sshd[8048]: Connection closed by invalid user ubuntu 144.225.8.54 port 46702 [preauth] Jul 21 12:40:01.148000 audit[8048]: AUDIT1109 pid=8048 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:01.152060 systemd[1]: sshd@202-87-172.31.16.165:22-144.225.8.54:46702.service: Deactivated successfully. Jul 21 12:40:01.152000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@202-87-172.31.16.165:22-144.225.8.54:46702 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:01.225012 systemd[1]: Started sshd@203-88-172.31.16.165:22-144.225.8.54:46718.service - OpenSSH per-connection server daemon (144.225.8.54:46718). Jul 21 12:40:01.225000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@203-88-172.31.16.165:22-144.225.8.54:46718 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:01.286000 audit[8058]: NETFILTER_CFG table=filter:145 family=2 entries=32 op=nft_register_rule pid=8058 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:40:01.286000 audit[8058]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=11944 a0=3 a1=fffff17bf460 a2=0 a3=1 items=0 ppid=4148 pid=8058 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:01.286000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:40:01.291000 audit[8058]: NETFILTER_CFG table=nat:146 family=2 entries=26 op=nft_register_rule pid=8058 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:40:01.291000 audit[8058]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=8076 a0=3 a1=fffff17bf460 a2=0 a3=1 items=0 ppid=4148 pid=8058 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:01.291000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:40:01.400000 audit[8042]: AUDIT1101 pid=8042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:01.401608 sshd[8042]: Accepted publickey for core from 20.76.1.115 port 40146 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:40:01.402000 audit[8042]: AUDIT1103 pid=8042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:01.403000 audit[8042]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffd0ea7160 a2=3 a3=0 items=0 ppid=1 pid=8042 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=18 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:01.403000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:40:01.405069 sshd-session[8042]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:40:01.419041 systemd-logind[2347]: New session '18' of user 'core' with class 'user' and type 'tty'. Jul 21 12:40:01.423592 systemd[1]: Started session-18.scope - Session 18 of User core. Jul 21 12:40:01.437000 audit[8042]: AUDIT1105 pid=8042 uid=0 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:01.440000 audit[8060]: AUDIT1103 pid=8060 uid=0 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:01.475298 sshd[8054]: Invalid user ubuntu from 144.225.8.54 port 46718 Jul 21 12:40:01.535694 sshd[8054]: Connection closed by invalid user ubuntu 144.225.8.54 port 46718 [preauth] Jul 21 12:40:01.536000 audit[8054]: AUDIT1109 pid=8054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:01.541529 systemd[1]: sshd@203-88-172.31.16.165:22-144.225.8.54:46718.service: Deactivated successfully. Jul 21 12:40:01.542000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@203-88-172.31.16.165:22-144.225.8.54:46718 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:01.612933 systemd[1]: Started sshd@204-4213-172.31.16.165:22-144.225.8.54:46724.service - OpenSSH per-connection server daemon (144.225.8.54:46724). Jul 21 12:40:01.615000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@204-4213-172.31.16.165:22-144.225.8.54:46724 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:01.859387 sshd[8064]: Invalid user ubuntu from 144.225.8.54 port 46724 Jul 21 12:40:01.921988 sshd[8064]: Connection closed by invalid user ubuntu 144.225.8.54 port 46724 [preauth] Jul 21 12:40:01.922000 audit[8064]: AUDIT1109 pid=8064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:01.926978 systemd[1]: sshd@204-4213-172.31.16.165:22-144.225.8.54:46724.service: Deactivated successfully. Jul 21 12:40:01.927000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@204-4213-172.31.16.165:22-144.225.8.54:46724 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:01.998000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@205-89-172.31.16.165:22-144.225.8.54:46728 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:01.998798 systemd[1]: Started sshd@205-89-172.31.16.165:22-144.225.8.54:46728.service - OpenSSH per-connection server daemon (144.225.8.54:46728). Jul 21 12:40:02.271843 sshd[8075]: Invalid user ubuntu from 144.225.8.54 port 46728 Jul 21 12:40:02.322377 sshd[8060]: Connection closed by 20.76.1.115 port 40146 Jul 21 12:40:02.322888 sshd-session[8042]: pam_unix(sshd:session): session closed for user core Jul 21 12:40:02.324000 audit[8042]: AUDIT1106 pid=8042 uid=0 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:02.324000 audit[8042]: AUDIT1104 pid=8042 uid=0 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:02.330188 systemd[1]: sshd@201-86-172.31.16.165:22-20.76.1.115:40146.service: Deactivated successfully. Jul 21 12:40:02.332560 sshd[8075]: Connection closed by invalid user ubuntu 144.225.8.54 port 46728 [preauth] Jul 21 12:40:02.333000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@201-86-172.31.16.165:22-20.76.1.115:40146 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:02.336000 audit[8075]: AUDIT1109 pid=8075 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:02.338482 systemd[1]: session-18.scope: Deactivated successfully. Jul 21 12:40:02.341719 systemd[1]: sshd@205-89-172.31.16.165:22-144.225.8.54:46728.service: Deactivated successfully. Jul 21 12:40:02.343000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@205-89-172.31.16.165:22-144.225.8.54:46728 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:02.351586 systemd-logind[2347]: Session 18 logged out. Waiting for processes to exit. Jul 21 12:40:02.357755 systemd-logind[2347]: Removed session 18. Jul 21 12:40:02.407180 systemd[1]: Started sshd@206-90-172.31.16.165:22-144.225.8.54:46738.service - OpenSSH per-connection server daemon (144.225.8.54:46738). Jul 21 12:40:02.408000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@206-90-172.31.16.165:22-144.225.8.54:46738 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:02.496000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@207-91-172.31.16.165:22-20.76.1.115:44960 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:02.496692 systemd[1]: Started sshd@207-91-172.31.16.165:22-20.76.1.115:44960.service - OpenSSH per-connection server daemon (20.76.1.115:44960). Jul 21 12:40:02.660682 sshd[8084]: Invalid user ubuntu from 144.225.8.54 port 46738 Jul 21 12:40:02.722743 sshd[8084]: Connection closed by invalid user ubuntu 144.225.8.54 port 46738 [preauth] Jul 21 12:40:02.723000 audit[8084]: AUDIT1109 pid=8084 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:02.727359 systemd[1]: sshd@206-90-172.31.16.165:22-144.225.8.54:46738.service: Deactivated successfully. Jul 21 12:40:02.727000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@206-90-172.31.16.165:22-144.225.8.54:46738 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:02.797945 systemd[1]: Started sshd@208-92-172.31.16.165:22-144.225.8.54:46744.service - OpenSSH per-connection server daemon (144.225.8.54:46744). Jul 21 12:40:02.798000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@208-92-172.31.16.165:22-144.225.8.54:46744 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:03.057773 sshd[8094]: Invalid user ubuntu from 144.225.8.54 port 46744 Jul 21 12:40:03.118334 sshd[8094]: Connection closed by invalid user ubuntu 144.225.8.54 port 46744 [preauth] Jul 21 12:40:03.118000 audit[8094]: AUDIT1109 pid=8094 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:03.123094 systemd[1]: sshd@208-92-172.31.16.165:22-144.225.8.54:46744.service: Deactivated successfully. Jul 21 12:40:03.123000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@208-92-172.31.16.165:22-144.225.8.54:46744 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:03.199000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@209-93-172.31.16.165:22-144.225.8.54:46750 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:03.199799 systemd[1]: Started sshd@209-93-172.31.16.165:22-144.225.8.54:46750.service - OpenSSH per-connection server daemon (144.225.8.54:46750). Jul 21 12:40:03.365000 audit[8088]: AUDIT1101 pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:03.369513 sshd-session[8088]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:40:03.373010 sshd[8088]: Accepted publickey for core from 20.76.1.115 port 44960 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:40:03.373083 kernel: kauditd_printk_skb: 63 callbacks suppressed Jul 21 12:40:03.373158 kernel: audit: type=1101 audit(1784637603.365:1443): pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:03.366000 audit[8088]: AUDIT1103 pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:03.380593 kernel: audit: type=1103 audit(1784637603.366:1444): pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:03.366000 audit[8088]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffc5462710 a2=3 a3=0 items=0 ppid=1 pid=8088 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=19 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:03.385101 kernel: audit: type=1006 audit(1784637603.366:1445): pid=8088 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=19 res=1 Jul 21 12:40:03.385159 kernel: audit: type=1300 audit(1784637603.366:1445): arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffc5462710 a2=3 a3=0 items=0 ppid=1 pid=8088 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=19 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:03.366000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:40:03.397519 kernel: audit: type=1327 audit(1784637603.366:1445): proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:40:03.404805 systemd-logind[2347]: New session '19' of user 'core' with class 'user' and type 'tty'. Jul 21 12:40:03.410545 systemd[1]: Started session-19.scope - Session 19 of User core. Jul 21 12:40:03.427000 audit[8088]: AUDIT1105 pid=8088 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:03.436372 kernel: audit: type=1105 audit(1784637603.427:1446): pid=8088 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:03.437000 audit[8106]: AUDIT1103 pid=8106 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:03.444236 kernel: audit: type=1103 audit(1784637603.437:1447): pid=8106 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:03.462846 sshd[8100]: Invalid user ubuntu from 144.225.8.54 port 46750 Jul 21 12:40:03.523509 sshd[8100]: Connection closed by invalid user ubuntu 144.225.8.54 port 46750 [preauth] Jul 21 12:40:03.525000 audit[8100]: AUDIT1109 pid=8100 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:03.533814 systemd[1]: sshd@209-93-172.31.16.165:22-144.225.8.54:46750.service: Deactivated successfully. Jul 21 12:40:03.534000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@209-93-172.31.16.165:22-144.225.8.54:46750 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:03.543077 kernel: audit: type=1109 audit(1784637603.525:1448): pid=8100 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:03.543240 kernel: audit: type=1131 audit(1784637603.534:1449): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@209-93-172.31.16.165:22-144.225.8.54:46750 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:03.608899 systemd[1]: Started sshd@210-4214-172.31.16.165:22-144.225.8.54:46762.service - OpenSSH per-connection server daemon (144.225.8.54:46762). Jul 21 12:40:03.608000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@210-4214-172.31.16.165:22-144.225.8.54:46762 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:03.622325 kernel: audit: type=1130 audit(1784637603.608:1450): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@210-4214-172.31.16.165:22-144.225.8.54:46762 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:03.916301 sshd[8110]: Invalid user ubuntu from 144.225.8.54 port 46762 Jul 21 12:40:03.981571 sshd[8110]: Connection closed by invalid user ubuntu 144.225.8.54 port 46762 [preauth] Jul 21 12:40:03.981000 audit[8110]: AUDIT1109 pid=8110 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:03.985722 systemd[1]: sshd@210-4214-172.31.16.165:22-144.225.8.54:46762.service: Deactivated successfully. Jul 21 12:40:03.986000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@210-4214-172.31.16.165:22-144.225.8.54:46762 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:04.034500 sshd[8106]: Connection closed by 20.76.1.115 port 44960 Jul 21 12:40:04.036000 audit[8088]: AUDIT1106 pid=8088 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:04.036000 audit[8088]: AUDIT1104 pid=8088 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:04.035814 sshd-session[8088]: pam_unix(sshd:session): session closed for user core Jul 21 12:40:04.056000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@207-91-172.31.16.165:22-20.76.1.115:44960 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:04.056064 systemd[1]: sshd@207-91-172.31.16.165:22-20.76.1.115:44960.service: Deactivated successfully. Jul 21 12:40:04.067091 systemd[1]: session-19.scope: Deactivated successfully. Jul 21 12:40:04.097711 systemd-logind[2347]: Session 19 logged out. Waiting for processes to exit. Jul 21 12:40:04.105000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@211-4215-172.31.16.165:22-144.225.8.54:46774 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:04.105902 systemd[1]: Started sshd@211-4215-172.31.16.165:22-144.225.8.54:46774.service - OpenSSH per-connection server daemon (144.225.8.54:46774). Jul 21 12:40:04.123316 systemd-logind[2347]: Removed session 19. Jul 21 12:40:04.408826 sshd[8127]: Invalid user ubuntu from 144.225.8.54 port 46774 Jul 21 12:40:04.469839 sshd[8127]: Connection closed by invalid user ubuntu 144.225.8.54 port 46774 [preauth] Jul 21 12:40:04.470000 audit[8127]: AUDIT1109 pid=8127 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:04.476002 systemd[1]: sshd@211-4215-172.31.16.165:22-144.225.8.54:46774.service: Deactivated successfully. Jul 21 12:40:04.478000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@211-4215-172.31.16.165:22-144.225.8.54:46774 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:04.544163 systemd[1]: Started sshd@212-4216-172.31.16.165:22-144.225.8.54:46790.service - OpenSSH per-connection server daemon (144.225.8.54:46790). Jul 21 12:40:04.545000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@212-4216-172.31.16.165:22-144.225.8.54:46790 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:04.841460 sshd[8140]: Invalid user ubuntu from 144.225.8.54 port 46790 Jul 21 12:40:04.903716 sshd[8140]: Connection closed by invalid user ubuntu 144.225.8.54 port 46790 [preauth] Jul 21 12:40:04.903000 audit[8140]: AUDIT1109 pid=8140 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:04.908020 systemd[1]: sshd@212-4216-172.31.16.165:22-144.225.8.54:46790.service: Deactivated successfully. Jul 21 12:40:04.910000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@212-4216-172.31.16.165:22-144.225.8.54:46790 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:04.982088 systemd[1]: Started sshd@213-4217-172.31.16.165:22-144.225.8.54:46794.service - OpenSSH per-connection server daemon (144.225.8.54:46794). Jul 21 12:40:04.982000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@213-4217-172.31.16.165:22-144.225.8.54:46794 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:05.252930 sshd[8147]: Invalid user ubuntu from 144.225.8.54 port 46794 Jul 21 12:40:05.314241 sshd[8147]: Connection closed by invalid user ubuntu 144.225.8.54 port 46794 [preauth] Jul 21 12:40:05.314000 audit[8147]: AUDIT1109 pid=8147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:05.318817 systemd[1]: sshd@213-4217-172.31.16.165:22-144.225.8.54:46794.service: Deactivated successfully. Jul 21 12:40:05.319000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@213-4217-172.31.16.165:22-144.225.8.54:46794 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:05.391000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@214-4218-172.31.16.165:22-144.225.8.54:46802 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:05.391763 systemd[1]: Started sshd@214-4218-172.31.16.165:22-144.225.8.54:46802.service - OpenSSH per-connection server daemon (144.225.8.54:46802). Jul 21 12:40:05.647459 sshd[8153]: Invalid user ubuntu from 144.225.8.54 port 46802 Jul 21 12:40:05.708902 sshd[8153]: Connection closed by invalid user ubuntu 144.225.8.54 port 46802 [preauth] Jul 21 12:40:05.710000 audit[8153]: AUDIT1109 pid=8153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:05.714890 systemd[1]: sshd@214-4218-172.31.16.165:22-144.225.8.54:46802.service: Deactivated successfully. Jul 21 12:40:05.715000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@214-4218-172.31.16.165:22-144.225.8.54:46802 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:05.787000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@215-4219-172.31.16.165:22-144.225.8.54:46814 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:05.787390 systemd[1]: Started sshd@215-4219-172.31.16.165:22-144.225.8.54:46814.service - OpenSSH per-connection server daemon (144.225.8.54:46814). Jul 21 12:40:06.050358 sshd[8160]: Invalid user ubuntu from 144.225.8.54 port 46814 Jul 21 12:40:06.110269 sshd[8160]: Connection closed by invalid user ubuntu 144.225.8.54 port 46814 [preauth] Jul 21 12:40:06.110000 audit[8160]: AUDIT1109 pid=8160 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:06.113026 systemd[1]: sshd@215-4219-172.31.16.165:22-144.225.8.54:46814.service: Deactivated successfully. Jul 21 12:40:06.114000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@215-4219-172.31.16.165:22-144.225.8.54:46814 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:06.190016 systemd[1]: Started sshd@216-4220-172.31.16.165:22-144.225.8.54:46824.service - OpenSSH per-connection server daemon (144.225.8.54:46824). Jul 21 12:40:06.192000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@216-4220-172.31.16.165:22-144.225.8.54:46824 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:06.474842 sshd[8166]: Invalid user ubuntu from 144.225.8.54 port 46824 Jul 21 12:40:06.534842 sshd[8166]: Connection closed by invalid user ubuntu 144.225.8.54 port 46824 [preauth] Jul 21 12:40:06.535000 audit[8166]: AUDIT1109 pid=8166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:06.539091 systemd[1]: sshd@216-4220-172.31.16.165:22-144.225.8.54:46824.service: Deactivated successfully. Jul 21 12:40:06.540000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@216-4220-172.31.16.165:22-144.225.8.54:46824 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:06.613558 systemd[1]: Started sshd@217-94-172.31.16.165:22-144.225.8.54:46838.service - OpenSSH per-connection server daemon (144.225.8.54:46838). Jul 21 12:40:06.615000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@217-94-172.31.16.165:22-144.225.8.54:46838 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:06.895345 sshd[8173]: Invalid user ubuntu from 144.225.8.54 port 46838 Jul 21 12:40:06.955866 sshd[8173]: Connection closed by invalid user ubuntu 144.225.8.54 port 46838 [preauth] Jul 21 12:40:06.956000 audit[8173]: AUDIT1109 pid=8173 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:06.960555 systemd[1]: sshd@217-94-172.31.16.165:22-144.225.8.54:46838.service: Deactivated successfully. Jul 21 12:40:06.961000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@217-94-172.31.16.165:22-144.225.8.54:46838 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:07.034029 systemd[1]: Started sshd@218-4221-172.31.16.165:22-144.225.8.54:46852.service - OpenSSH per-connection server daemon (144.225.8.54:46852). Jul 21 12:40:07.034000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@218-4221-172.31.16.165:22-144.225.8.54:46852 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:07.311126 sshd[8179]: Invalid user ubuntu from 144.225.8.54 port 46852 Jul 21 12:40:07.373595 sshd[8179]: Connection closed by invalid user ubuntu 144.225.8.54 port 46852 [preauth] Jul 21 12:40:07.373000 audit[8179]: AUDIT1109 pid=8179 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:07.377074 systemd[1]: sshd@218-4221-172.31.16.165:22-144.225.8.54:46852.service: Deactivated successfully. Jul 21 12:40:07.377000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@218-4221-172.31.16.165:22-144.225.8.54:46852 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:07.456000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@219-4222-172.31.16.165:22-144.225.8.54:46854 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:07.455957 systemd[1]: Started sshd@219-4222-172.31.16.165:22-144.225.8.54:46854.service - OpenSSH per-connection server daemon (144.225.8.54:46854). Jul 21 12:40:07.612000 audit[8190]: NETFILTER_CFG table=filter:147 family=2 entries=20 op=nft_register_rule pid=8190 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:40:07.612000 audit[8190]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=3016 a0=3 a1=fffff322abf0 a2=0 a3=1 items=0 ppid=4148 pid=8190 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:07.612000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:40:07.621000 audit[8190]: NETFILTER_CFG table=nat:148 family=2 entries=110 op=nft_register_chain pid=8190 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" Jul 21 12:40:07.621000 audit[8190]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=50988 a0=3 a1=fffff322abf0 a2=0 a3=1 items=0 ppid=4148 pid=8190 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:07.621000 audit: PROCTITLE proctitle=69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 Jul 21 12:40:07.732556 sshd[8186]: Invalid user ubuntu from 144.225.8.54 port 46854 Jul 21 12:40:07.794969 sshd[8186]: Connection closed by invalid user ubuntu 144.225.8.54 port 46854 [preauth] Jul 21 12:40:07.795000 audit[8186]: AUDIT1109 pid=8186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:07.800013 systemd[1]: sshd@219-4222-172.31.16.165:22-144.225.8.54:46854.service: Deactivated successfully. Jul 21 12:40:07.801000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@219-4222-172.31.16.165:22-144.225.8.54:46854 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:07.871000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@220-4223-172.31.16.165:22-144.225.8.54:46232 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:07.871822 systemd[1]: Started sshd@220-4223-172.31.16.165:22-144.225.8.54:46232.service - OpenSSH per-connection server daemon (144.225.8.54:46232). Jul 21 12:40:08.123243 sshd[8194]: Invalid user ubuntu from 144.225.8.54 port 46232 Jul 21 12:40:08.184963 sshd[8194]: Connection closed by invalid user ubuntu 144.225.8.54 port 46232 [preauth] Jul 21 12:40:08.185000 audit[8194]: AUDIT1109 pid=8194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:08.188865 systemd[1]: sshd@220-4223-172.31.16.165:22-144.225.8.54:46232.service: Deactivated successfully. Jul 21 12:40:08.190000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@220-4223-172.31.16.165:22-144.225.8.54:46232 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:08.262000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@221-4224-172.31.16.165:22-144.225.8.54:46234 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:08.262605 systemd[1]: Started sshd@221-4224-172.31.16.165:22-144.225.8.54:46234.service - OpenSSH per-connection server daemon (144.225.8.54:46234). Jul 21 12:40:08.523916 sshd[8201]: Invalid user ubuntu from 144.225.8.54 port 46234 Jul 21 12:40:08.585462 sshd[8201]: Connection closed by invalid user ubuntu 144.225.8.54 port 46234 [preauth] Jul 21 12:40:08.586000 audit[8201]: AUDIT1109 pid=8201 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:08.590419 systemd[1]: sshd@221-4224-172.31.16.165:22-144.225.8.54:46234.service: Deactivated successfully. Jul 21 12:40:08.592849 kernel: kauditd_printk_skb: 42 callbacks suppressed Jul 21 12:40:08.592921 kernel: audit: type=1109 audit(1784637608.586:1489): pid=8201 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:08.592000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@221-4224-172.31.16.165:22-144.225.8.54:46234 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:08.602048 kernel: audit: type=1131 audit(1784637608.592:1490): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@221-4224-172.31.16.165:22-144.225.8.54:46234 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:08.661785 systemd[1]: Started sshd@222-4225-172.31.16.165:22-144.225.8.54:46238.service - OpenSSH per-connection server daemon (144.225.8.54:46238). Jul 21 12:40:08.661000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@222-4225-172.31.16.165:22-144.225.8.54:46238 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:08.672262 kernel: audit: type=1130 audit(1784637608.661:1491): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@222-4225-172.31.16.165:22-144.225.8.54:46238 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:08.915901 sshd[8207]: Invalid user ubuntu from 144.225.8.54 port 46238 Jul 21 12:40:08.976000 audit[8207]: AUDIT1109 pid=8207 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:08.977098 sshd[8207]: Connection closed by invalid user ubuntu 144.225.8.54 port 46238 [preauth] Jul 21 12:40:08.982056 systemd[1]: sshd@222-4225-172.31.16.165:22-144.225.8.54:46238.service: Deactivated successfully. Jul 21 12:40:08.982000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@222-4225-172.31.16.165:22-144.225.8.54:46238 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:08.988138 kernel: audit: type=1109 audit(1784637608.976:1492): pid=8207 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:08.988212 kernel: audit: type=1131 audit(1784637608.982:1493): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@222-4225-172.31.16.165:22-144.225.8.54:46238 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.050733 systemd[1]: Started sshd@223-4226-172.31.16.165:22-144.225.8.54:46242.service - OpenSSH per-connection server daemon (144.225.8.54:46242). Jul 21 12:40:09.050000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@223-4226-172.31.16.165:22-144.225.8.54:46242 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.062345 kernel: audit: type=1130 audit(1784637609.050:1494): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@223-4226-172.31.16.165:22-144.225.8.54:46242 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.211766 systemd[1]: Started sshd@224-4227-172.31.16.165:22-20.76.1.115:44966.service - OpenSSH per-connection server daemon (20.76.1.115:44966). Jul 21 12:40:09.212000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@224-4227-172.31.16.165:22-20.76.1.115:44966 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.221294 kernel: audit: type=1130 audit(1784637609.212:1495): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@224-4227-172.31.16.165:22-20.76.1.115:44966 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.308556 sshd[8215]: Invalid user ubuntu from 144.225.8.54 port 46242 Jul 21 12:40:09.368674 sshd[8215]: Connection closed by invalid user ubuntu 144.225.8.54 port 46242 [preauth] Jul 21 12:40:09.369000 audit[8215]: AUDIT1109 pid=8215 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:09.372888 systemd[1]: sshd@223-4226-172.31.16.165:22-144.225.8.54:46242.service: Deactivated successfully. Jul 21 12:40:09.369000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@223-4226-172.31.16.165:22-144.225.8.54:46242 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.380596 kernel: audit: type=1109 audit(1784637609.369:1496): pid=8215 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:09.380703 kernel: audit: type=1131 audit(1784637609.369:1497): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@223-4226-172.31.16.165:22-144.225.8.54:46242 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.442784 systemd[1]: Started sshd@225-95-172.31.16.165:22-144.225.8.54:46256.service - OpenSSH per-connection server daemon (144.225.8.54:46256). Jul 21 12:40:09.442000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@225-95-172.31.16.165:22-144.225.8.54:46256 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.453268 kernel: audit: type=1130 audit(1784637609.442:1498): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@225-95-172.31.16.165:22-144.225.8.54:46256 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.696249 sshd[8225]: Invalid user ubuntu from 144.225.8.54 port 46256 Jul 21 12:40:09.758004 sshd[8225]: Connection closed by invalid user ubuntu 144.225.8.54 port 46256 [preauth] Jul 21 12:40:09.758000 audit[8225]: AUDIT1109 pid=8225 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:09.761018 systemd[1]: sshd@225-95-172.31.16.165:22-144.225.8.54:46256.service: Deactivated successfully. Jul 21 12:40:09.762000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@225-95-172.31.16.165:22-144.225.8.54:46256 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.833000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@226-4228-172.31.16.165:22-144.225.8.54:46258 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:09.833426 systemd[1]: Started sshd@226-4228-172.31.16.165:22-144.225.8.54:46258.service - OpenSSH per-connection server daemon (144.225.8.54:46258). Jul 21 12:40:10.075000 audit[8219]: AUDIT1101 pid=8219 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:10.076821 sshd[8219]: Accepted publickey for core from 20.76.1.115 port 44966 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:40:10.079920 sshd[8231]: Invalid user ubuntu from 144.225.8.54 port 46258 Jul 21 12:40:10.082000 audit[8219]: AUDIT1103 pid=8219 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:10.084000 audit[8219]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffc86a5820 a2=3 a3=0 items=0 ppid=1 pid=8219 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=20 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:10.084000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:40:10.087352 sshd-session[8219]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:40:10.109037 systemd-logind[2347]: New session '20' of user 'core' with class 'user' and type 'tty'. Jul 21 12:40:10.112972 systemd[1]: Started session-20.scope - Session 20 of User core. Jul 21 12:40:10.130000 audit[8219]: AUDIT1105 pid=8219 uid=0 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:10.134000 audit[8235]: AUDIT1103 pid=8235 uid=0 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:10.144867 sshd[8231]: Connection closed by invalid user ubuntu 144.225.8.54 port 46258 [preauth] Jul 21 12:40:10.145000 audit[8231]: AUDIT1109 pid=8231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:10.149029 systemd[1]: sshd@226-4228-172.31.16.165:22-144.225.8.54:46258.service: Deactivated successfully. Jul 21 12:40:10.149000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@226-4228-172.31.16.165:22-144.225.8.54:46258 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:10.221000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@227-4229-172.31.16.165:22-144.225.8.54:46266 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:10.220733 systemd[1]: Started sshd@227-4229-172.31.16.165:22-144.225.8.54:46266.service - OpenSSH per-connection server daemon (144.225.8.54:46266). Jul 21 12:40:10.477604 sshd[8239]: Invalid user ubuntu from 144.225.8.54 port 46266 Jul 21 12:40:10.538227 sshd[8239]: Connection closed by invalid user ubuntu 144.225.8.54 port 46266 [preauth] Jul 21 12:40:10.539000 audit[8239]: AUDIT1109 pid=8239 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:10.543978 systemd[1]: sshd@227-4229-172.31.16.165:22-144.225.8.54:46266.service: Deactivated successfully. Jul 21 12:40:10.546000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@227-4229-172.31.16.165:22-144.225.8.54:46266 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:10.617840 systemd[1]: Started sshd@228-96-172.31.16.165:22-144.225.8.54:46270.service - OpenSSH per-connection server daemon (144.225.8.54:46270). Jul 21 12:40:10.617000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@228-96-172.31.16.165:22-144.225.8.54:46270 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:10.699976 sshd[8235]: Connection closed by 20.76.1.115 port 44966 Jul 21 12:40:10.700394 sshd-session[8219]: pam_unix(sshd:session): session closed for user core Jul 21 12:40:10.701000 audit[8219]: AUDIT1106 pid=8219 uid=0 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:10.702000 audit[8219]: AUDIT1104 pid=8219 uid=0 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:10.709475 systemd[1]: sshd@224-4227-172.31.16.165:22-20.76.1.115:44966.service: Deactivated successfully. Jul 21 12:40:10.710000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@224-4227-172.31.16.165:22-20.76.1.115:44966 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:10.716152 systemd[1]: session-20.scope: Deactivated successfully. Jul 21 12:40:10.723010 systemd-logind[2347]: Session 20 logged out. Waiting for processes to exit. Jul 21 12:40:10.728085 systemd-logind[2347]: Removed session 20. Jul 21 12:40:10.867159 sshd[8252]: Invalid user ubuntu from 144.225.8.54 port 46270 Jul 21 12:40:10.928135 sshd[8252]: Connection closed by invalid user ubuntu 144.225.8.54 port 46270 [preauth] Jul 21 12:40:10.928000 audit[8252]: AUDIT1109 pid=8252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:10.931655 systemd[1]: sshd@228-96-172.31.16.165:22-144.225.8.54:46270.service: Deactivated successfully. Jul 21 12:40:10.932000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@228-96-172.31.16.165:22-144.225.8.54:46270 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:11.002000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@229-97-172.31.16.165:22-144.225.8.54:46282 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:11.002765 systemd[1]: Started sshd@229-97-172.31.16.165:22-144.225.8.54:46282.service - OpenSSH per-connection server daemon (144.225.8.54:46282). Jul 21 12:40:11.263835 sshd[8261]: Invalid user ubuntu from 144.225.8.54 port 46282 Jul 21 12:40:11.324152 sshd[8261]: Connection closed by invalid user ubuntu 144.225.8.54 port 46282 [preauth] Jul 21 12:40:11.324000 audit[8261]: AUDIT1109 pid=8261 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:11.328082 systemd[1]: sshd@229-97-172.31.16.165:22-144.225.8.54:46282.service: Deactivated successfully. Jul 21 12:40:11.329000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@229-97-172.31.16.165:22-144.225.8.54:46282 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:11.398782 systemd[1]: Started sshd@230-4230-172.31.16.165:22-144.225.8.54:46284.service - OpenSSH per-connection server daemon (144.225.8.54:46284). Jul 21 12:40:11.398000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@230-4230-172.31.16.165:22-144.225.8.54:46284 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:11.642953 sshd[8267]: Invalid user ubuntu from 144.225.8.54 port 46284 Jul 21 12:40:11.703409 sshd[8267]: Connection closed by invalid user ubuntu 144.225.8.54 port 46284 [preauth] Jul 21 12:40:11.703000 audit[8267]: AUDIT1109 pid=8267 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:11.707876 systemd[1]: sshd@230-4230-172.31.16.165:22-144.225.8.54:46284.service: Deactivated successfully. Jul 21 12:40:11.709000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@230-4230-172.31.16.165:22-144.225.8.54:46284 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:11.778000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@231-4231-172.31.16.165:22-144.225.8.54:46294 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:11.778868 systemd[1]: Started sshd@231-4231-172.31.16.165:22-144.225.8.54:46294.service - OpenSSH per-connection server daemon (144.225.8.54:46294). Jul 21 12:40:12.033178 sshd[8273]: Invalid user ubuntu from 144.225.8.54 port 46294 Jul 21 12:40:12.100973 sshd[8273]: Connection closed by invalid user ubuntu 144.225.8.54 port 46294 [preauth] Jul 21 12:40:12.101000 audit[8273]: AUDIT1109 pid=8273 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:12.105140 systemd[1]: sshd@231-4231-172.31.16.165:22-144.225.8.54:46294.service: Deactivated successfully. Jul 21 12:40:12.105000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@231-4231-172.31.16.165:22-144.225.8.54:46294 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:12.176769 systemd[1]: Started sshd@232-4232-172.31.16.165:22-144.225.8.54:46306.service - OpenSSH per-connection server daemon (144.225.8.54:46306). Jul 21 12:40:12.176000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@232-4232-172.31.16.165:22-144.225.8.54:46306 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:12.426715 sshd[8301]: Invalid user ubuntu from 144.225.8.54 port 46306 Jul 21 12:40:12.487979 sshd[8301]: Connection closed by invalid user ubuntu 144.225.8.54 port 46306 [preauth] Jul 21 12:40:12.488000 audit[8301]: AUDIT1109 pid=8301 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:12.492000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@232-4232-172.31.16.165:22-144.225.8.54:46306 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:12.491807 systemd[1]: sshd@232-4232-172.31.16.165:22-144.225.8.54:46306.service: Deactivated successfully. Jul 21 12:40:12.568799 systemd[1]: Started sshd@233-4233-172.31.16.165:22-144.225.8.54:46320.service - OpenSSH per-connection server daemon (144.225.8.54:46320). Jul 21 12:40:12.568000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@233-4233-172.31.16.165:22-144.225.8.54:46320 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:12.829080 sshd[8307]: Invalid user ubuntu from 144.225.8.54 port 46320 Jul 21 12:40:12.889393 sshd[8307]: Connection closed by invalid user ubuntu 144.225.8.54 port 46320 [preauth] Jul 21 12:40:12.890000 audit[8307]: AUDIT1109 pid=8307 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:12.894554 systemd[1]: sshd@233-4233-172.31.16.165:22-144.225.8.54:46320.service: Deactivated successfully. Jul 21 12:40:12.898000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@233-4233-172.31.16.165:22-144.225.8.54:46320 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:12.977810 systemd[1]: Started sshd@234-98-172.31.16.165:22-144.225.8.54:46326.service - OpenSSH per-connection server daemon (144.225.8.54:46326). Jul 21 12:40:12.977000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@234-98-172.31.16.165:22-144.225.8.54:46326 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:12.975000 audit[8320]: NETFILTER_CFG table=filter:149 family=2 entries=73 op=nft_register_chain pid=8320 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:40:12.975000 audit[8320]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=30460 a0=3 a1=fffff40813d0 a2=0 a3=ffffb08157e0 items=0 ppid=5430 pid=8320 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:12.975000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:40:13.158000 audit[8331]: NETFILTER_CFG table=filter:150 family=2 entries=72 op=nft_register_chain pid=8331 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" Jul 21 12:40:13.158000 audit[8331]: SYSCALL arch=c00000b7 syscall=211 success=yes exit=29636 a0=3 a1=ffffca678660 a2=0 a3=ffffae5cf7e0 items=0 ppid=5430 pid=8331 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:13.158000 audit: PROCTITLE proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 Jul 21 12:40:13.281602 sshd[8321]: Invalid user ubuntu from 144.225.8.54 port 46326 Jul 21 12:40:13.342710 sshd[8321]: Connection closed by invalid user ubuntu 144.225.8.54 port 46326 [preauth] Jul 21 12:40:13.342000 audit[8321]: AUDIT1109 pid=8321 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:13.348599 systemd[1]: sshd@234-98-172.31.16.165:22-144.225.8.54:46326.service: Deactivated successfully. Jul 21 12:40:13.352000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@234-98-172.31.16.165:22-144.225.8.54:46326 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:13.422000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@235-99-172.31.16.165:22-144.225.8.54:46336 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:13.422122 systemd[1]: Started sshd@235-99-172.31.16.165:22-144.225.8.54:46336.service - OpenSSH per-connection server daemon (144.225.8.54:46336). Jul 21 12:40:13.741512 sshd[8336]: Invalid user ubuntu from 144.225.8.54 port 46336 Jul 21 12:40:13.802833 sshd[8336]: Connection closed by invalid user ubuntu 144.225.8.54 port 46336 [preauth] Jul 21 12:40:13.803000 audit[8336]: AUDIT1109 pid=8336 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:13.804918 kernel: kauditd_printk_skb: 46 callbacks suppressed Jul 21 12:40:13.805004 kernel: audit: type=1109 audit(1784637613.803:1539): pid=8336 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:13.811816 systemd[1]: sshd@235-99-172.31.16.165:22-144.225.8.54:46336.service: Deactivated successfully. Jul 21 12:40:13.814000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@235-99-172.31.16.165:22-144.225.8.54:46336 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:13.820464 kernel: audit: type=1131 audit(1784637613.814:1540): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@235-99-172.31.16.165:22-144.225.8.54:46336 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:13.887000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@236-100-172.31.16.165:22-144.225.8.54:46352 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:13.887531 systemd[1]: Started sshd@236-100-172.31.16.165:22-144.225.8.54:46352.service - OpenSSH per-connection server daemon (144.225.8.54:46352). Jul 21 12:40:13.899263 kernel: audit: type=1130 audit(1784637613.887:1541): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@236-100-172.31.16.165:22-144.225.8.54:46352 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:14.196508 sshd[8342]: Invalid user ubuntu from 144.225.8.54 port 46352 Jul 21 12:40:14.259682 sshd[8342]: Connection closed by invalid user ubuntu 144.225.8.54 port 46352 [preauth] Jul 21 12:40:14.260000 audit[8342]: AUDIT1109 pid=8342 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:14.266320 systemd[1]: sshd@236-100-172.31.16.165:22-144.225.8.54:46352.service: Deactivated successfully. Jul 21 12:40:14.266000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@236-100-172.31.16.165:22-144.225.8.54:46352 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:14.271787 kernel: audit: type=1109 audit(1784637614.260:1542): pid=8342 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:14.272286 kernel: audit: type=1131 audit(1784637614.266:1543): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@236-100-172.31.16.165:22-144.225.8.54:46352 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:14.339000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@237-101-172.31.16.165:22-144.225.8.54:46358 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:14.339868 systemd[1]: Started sshd@237-101-172.31.16.165:22-144.225.8.54:46358.service - OpenSSH per-connection server daemon (144.225.8.54:46358). Jul 21 12:40:14.349340 kernel: audit: type=1130 audit(1784637614.339:1544): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@237-101-172.31.16.165:22-144.225.8.54:46358 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:14.589378 sshd[8349]: Invalid user ubuntu from 144.225.8.54 port 46358 Jul 21 12:40:14.649701 sshd[8349]: Connection closed by invalid user ubuntu 144.225.8.54 port 46358 [preauth] Jul 21 12:40:14.650000 audit[8349]: AUDIT1109 pid=8349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:14.655816 systemd[1]: sshd@237-101-172.31.16.165:22-144.225.8.54:46358.service: Deactivated successfully. Jul 21 12:40:14.656000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@237-101-172.31.16.165:22-144.225.8.54:46358 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:14.662147 kernel: audit: type=1109 audit(1784637614.650:1545): pid=8349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:14.662351 kernel: audit: type=1131 audit(1784637614.656:1546): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@237-101-172.31.16.165:22-144.225.8.54:46358 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:14.726000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@238-4234-172.31.16.165:22-144.225.8.54:46366 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:14.726877 systemd[1]: Started sshd@238-4234-172.31.16.165:22-144.225.8.54:46366.service - OpenSSH per-connection server daemon (144.225.8.54:46366). Jul 21 12:40:14.737500 kernel: audit: type=1130 audit(1784637614.726:1547): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@238-4234-172.31.16.165:22-144.225.8.54:46366 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:14.977578 sshd[8355]: Invalid user ubuntu from 144.225.8.54 port 46366 Jul 21 12:40:15.037308 sshd[8355]: Connection closed by invalid user ubuntu 144.225.8.54 port 46366 [preauth] Jul 21 12:40:15.038000 audit[8355]: AUDIT1109 pid=8355 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:15.041896 systemd[1]: sshd@238-4234-172.31.16.165:22-144.225.8.54:46366.service: Deactivated successfully. Jul 21 12:40:15.038000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@238-4234-172.31.16.165:22-144.225.8.54:46366 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:15.045247 kernel: audit: type=1109 audit(1784637615.038:1548): pid=8355 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:15.114000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@239-102-172.31.16.165:22-144.225.8.54:46368 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:15.114786 systemd[1]: Started sshd@239-102-172.31.16.165:22-144.225.8.54:46368.service - OpenSSH per-connection server daemon (144.225.8.54:46368). Jul 21 12:40:15.359101 sshd[8361]: Invalid user ubuntu from 144.225.8.54 port 46368 Jul 21 12:40:15.420164 sshd[8361]: Connection closed by invalid user ubuntu 144.225.8.54 port 46368 [preauth] Jul 21 12:40:15.420000 audit[8361]: AUDIT1109 pid=8361 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:15.423536 systemd[1]: sshd@239-102-172.31.16.165:22-144.225.8.54:46368.service: Deactivated successfully. Jul 21 12:40:15.425000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@239-102-172.31.16.165:22-144.225.8.54:46368 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:15.496000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@240-4235-172.31.16.165:22-144.225.8.54:46384 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:15.495068 systemd[1]: Started sshd@240-4235-172.31.16.165:22-144.225.8.54:46384.service - OpenSSH per-connection server daemon (144.225.8.54:46384). Jul 21 12:40:15.750414 sshd[8367]: Invalid user ubuntu from 144.225.8.54 port 46384 Jul 21 12:40:15.810937 sshd[8367]: Connection closed by invalid user ubuntu 144.225.8.54 port 46384 [preauth] Jul 21 12:40:15.811000 audit[8367]: AUDIT1109 pid=8367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:15.814933 systemd[1]: sshd@240-4235-172.31.16.165:22-144.225.8.54:46384.service: Deactivated successfully. Jul 21 12:40:15.815000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@240-4235-172.31.16.165:22-144.225.8.54:46384 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:15.910000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@241-103-172.31.16.165:22-20.76.1.115:48644 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:15.910937 systemd[1]: Started sshd@241-103-172.31.16.165:22-20.76.1.115:48644.service - OpenSSH per-connection server daemon (20.76.1.115:48644). Jul 21 12:40:15.915000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@242-104-172.31.16.165:22-144.225.8.54:46392 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:15.915626 systemd[1]: Started sshd@242-104-172.31.16.165:22-144.225.8.54:46392.service - OpenSSH per-connection server daemon (144.225.8.54:46392). Jul 21 12:40:16.172253 sshd[8375]: Invalid user ubuntu from 144.225.8.54 port 46392 Jul 21 12:40:16.232043 sshd[8375]: Connection closed by invalid user ubuntu 144.225.8.54 port 46392 [preauth] Jul 21 12:40:16.232000 audit[8375]: AUDIT1109 pid=8375 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:16.237327 systemd[1]: sshd@242-104-172.31.16.165:22-144.225.8.54:46392.service: Deactivated successfully. Jul 21 12:40:16.238000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@242-104-172.31.16.165:22-144.225.8.54:46392 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:16.310000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@243-105-172.31.16.165:22-144.225.8.54:46406 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:16.310672 systemd[1]: Started sshd@243-105-172.31.16.165:22-144.225.8.54:46406.service - OpenSSH per-connection server daemon (144.225.8.54:46406). Jul 21 12:40:16.558246 sshd[8383]: Invalid user ubuntu from 144.225.8.54 port 46406 Jul 21 12:40:16.618683 sshd[8383]: Connection closed by invalid user ubuntu 144.225.8.54 port 46406 [preauth] Jul 21 12:40:16.619000 audit[8383]: AUDIT1109 pid=8383 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:16.622619 systemd[1]: sshd@243-105-172.31.16.165:22-144.225.8.54:46406.service: Deactivated successfully. Jul 21 12:40:16.623000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@243-105-172.31.16.165:22-144.225.8.54:46406 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:16.694247 systemd[1]: Started sshd@244-4236-172.31.16.165:22-144.225.8.54:46414.service - OpenSSH per-connection server daemon (144.225.8.54:46414). Jul 21 12:40:16.695000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@244-4236-172.31.16.165:22-144.225.8.54:46414 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:16.825000 audit[8374]: AUDIT1101 pid=8374 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:16.827579 sshd[8374]: Accepted publickey for core from 20.76.1.115 port 48644 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:40:16.828000 audit[8374]: AUDIT1103 pid=8374 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:16.828000 audit[8374]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=fffffa20c320 a2=3 a3=0 items=0 ppid=1 pid=8374 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=21 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:16.828000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:40:16.830569 sshd-session[8374]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:40:16.842349 systemd-logind[2347]: New session '21' of user 'core' with class 'user' and type 'tty'. Jul 21 12:40:16.847522 systemd[1]: Started session-21.scope - Session 21 of User core. Jul 21 12:40:16.859000 audit[8374]: AUDIT1105 pid=8374 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:16.863000 audit[8393]: AUDIT1103 pid=8393 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:16.950645 sshd[8389]: Invalid user ubuntu from 144.225.8.54 port 46414 Jul 21 12:40:17.011400 sshd[8389]: Connection closed by invalid user ubuntu 144.225.8.54 port 46414 [preauth] Jul 21 12:40:17.012000 audit[8389]: AUDIT1109 pid=8389 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:17.015275 systemd[1]: sshd@244-4236-172.31.16.165:22-144.225.8.54:46414.service: Deactivated successfully. Jul 21 12:40:17.015000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@244-4236-172.31.16.165:22-144.225.8.54:46414 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:17.089000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@245-4237-172.31.16.165:22-144.225.8.54:46430 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:17.089075 systemd[1]: Started sshd@245-4237-172.31.16.165:22-144.225.8.54:46430.service - OpenSSH per-connection server daemon (144.225.8.54:46430). Jul 21 12:40:17.344660 sshd[8398]: Invalid user ubuntu from 144.225.8.54 port 46430 Jul 21 12:40:17.404768 sshd[8398]: Connection closed by invalid user ubuntu 144.225.8.54 port 46430 [preauth] Jul 21 12:40:17.405000 audit[8398]: AUDIT1109 pid=8398 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:17.408723 systemd[1]: sshd@245-4237-172.31.16.165:22-144.225.8.54:46430.service: Deactivated successfully. Jul 21 12:40:17.409000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@245-4237-172.31.16.165:22-144.225.8.54:46430 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:17.441394 sshd[8393]: Connection closed by 20.76.1.115 port 48644 Jul 21 12:40:17.444574 sshd-session[8374]: pam_unix(sshd:session): session closed for user core Jul 21 12:40:17.446000 audit[8374]: AUDIT1106 pid=8374 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:17.447000 audit[8374]: AUDIT1104 pid=8374 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:17.452563 systemd[1]: sshd@241-103-172.31.16.165:22-20.76.1.115:48644.service: Deactivated successfully. Jul 21 12:40:17.453000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@241-103-172.31.16.165:22-20.76.1.115:48644 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:17.457018 systemd[1]: session-21.scope: Deactivated successfully. Jul 21 12:40:17.463614 systemd-logind[2347]: Session 21 logged out. Waiting for processes to exit. Jul 21 12:40:17.481785 systemd[1]: Started sshd@246-106-172.31.16.165:22-144.225.8.54:46446.service - OpenSSH per-connection server daemon (144.225.8.54:46446). Jul 21 12:40:17.481000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@246-106-172.31.16.165:22-144.225.8.54:46446 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:17.497318 systemd-logind[2347]: Removed session 21. Jul 21 12:40:17.729906 sshd[8413]: Invalid user ubuntu from 144.225.8.54 port 46446 Jul 21 12:40:17.789694 sshd[8413]: Connection closed by invalid user ubuntu 144.225.8.54 port 46446 [preauth] Jul 21 12:40:17.790000 audit[8413]: AUDIT1109 pid=8413 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:17.793529 systemd[1]: sshd@246-106-172.31.16.165:22-144.225.8.54:46446.service: Deactivated successfully. Jul 21 12:40:17.794000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@246-106-172.31.16.165:22-144.225.8.54:46446 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:17.870000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@247-4238-172.31.16.165:22-144.225.8.54:43560 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:17.870608 systemd[1]: Started sshd@247-4238-172.31.16.165:22-144.225.8.54:43560.service - OpenSSH per-connection server daemon (144.225.8.54:43560). Jul 21 12:40:18.124232 sshd[8419]: Invalid user ubuntu from 144.225.8.54 port 43560 Jul 21 12:40:18.185432 sshd[8419]: Connection closed by invalid user ubuntu 144.225.8.54 port 43560 [preauth] Jul 21 12:40:18.186000 audit[8419]: AUDIT1109 pid=8419 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:18.189656 systemd[1]: sshd@247-4238-172.31.16.165:22-144.225.8.54:43560.service: Deactivated successfully. Jul 21 12:40:18.190000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@247-4238-172.31.16.165:22-144.225.8.54:43560 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:18.263764 systemd[1]: Started sshd@248-4239-172.31.16.165:22-144.225.8.54:43572.service - OpenSSH per-connection server daemon (144.225.8.54:43572). Jul 21 12:40:18.263000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@248-4239-172.31.16.165:22-144.225.8.54:43572 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:18.518892 sshd[8425]: Invalid user ubuntu from 144.225.8.54 port 43572 Jul 21 12:40:18.580008 sshd[8425]: Connection closed by invalid user ubuntu 144.225.8.54 port 43572 [preauth] Jul 21 12:40:18.580000 audit[8425]: AUDIT1109 pid=8425 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:18.586241 systemd[1]: sshd@248-4239-172.31.16.165:22-144.225.8.54:43572.service: Deactivated successfully. Jul 21 12:40:18.586000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@248-4239-172.31.16.165:22-144.225.8.54:43572 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:18.660000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@249-4240-172.31.16.165:22-144.225.8.54:43580 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:18.660803 systemd[1]: Started sshd@249-4240-172.31.16.165:22-144.225.8.54:43580.service - OpenSSH per-connection server daemon (144.225.8.54:43580). Jul 21 12:40:18.915930 sshd[8438]: Invalid user ubuntu from 144.225.8.54 port 43580 Jul 21 12:40:18.977563 sshd[8438]: Connection closed by invalid user ubuntu 144.225.8.54 port 43580 [preauth] Jul 21 12:40:18.978000 audit[8438]: AUDIT1109 pid=8438 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:18.984727 kernel: kauditd_printk_skb: 40 callbacks suppressed Jul 21 12:40:18.984800 kernel: audit: type=1109 audit(1784637618.978:1587): pid=8438 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:18.985155 systemd[1]: sshd@249-4240-172.31.16.165:22-144.225.8.54:43580.service: Deactivated successfully. Jul 21 12:40:18.985000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@249-4240-172.31.16.165:22-144.225.8.54:43580 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:18.994595 kernel: audit: type=1131 audit(1784637618.985:1588): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@249-4240-172.31.16.165:22-144.225.8.54:43580 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:19.053822 systemd[1]: Started sshd@250-4241-172.31.16.165:22-144.225.8.54:43590.service - OpenSSH per-connection server daemon (144.225.8.54:43590). Jul 21 12:40:19.053000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@250-4241-172.31.16.165:22-144.225.8.54:43590 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:19.063255 kernel: audit: type=1130 audit(1784637619.053:1589): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@250-4241-172.31.16.165:22-144.225.8.54:43590 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:19.317256 sshd[8445]: Invalid user ubuntu from 144.225.8.54 port 43590 Jul 21 12:40:19.376662 sshd[8445]: Connection closed by invalid user ubuntu 144.225.8.54 port 43590 [preauth] Jul 21 12:40:19.377000 audit[8445]: AUDIT1109 pid=8445 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:19.377000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@250-4241-172.31.16.165:22-144.225.8.54:43590 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:19.382822 kernel: audit: type=1109 audit(1784637619.377:1590): pid=8445 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:19.381410 systemd[1]: sshd@250-4241-172.31.16.165:22-144.225.8.54:43590.service: Deactivated successfully. Jul 21 12:40:19.382983 kernel: audit: type=1131 audit(1784637619.377:1591): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@250-4241-172.31.16.165:22-144.225.8.54:43590 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:19.453000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@251-4242-172.31.16.165:22-144.225.8.54:43598 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:19.452765 systemd[1]: Started sshd@251-4242-172.31.16.165:22-144.225.8.54:43598.service - OpenSSH per-connection server daemon (144.225.8.54:43598). Jul 21 12:40:19.461590 kernel: audit: type=1130 audit(1784637619.453:1592): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@251-4242-172.31.16.165:22-144.225.8.54:43598 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:19.697891 sshd[8452]: Invalid user ubuntu from 144.225.8.54 port 43598 Jul 21 12:40:19.758352 sshd[8452]: Connection closed by invalid user ubuntu 144.225.8.54 port 43598 [preauth] Jul 21 12:40:19.758000 audit[8452]: AUDIT1109 pid=8452 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:19.762375 systemd[1]: sshd@251-4242-172.31.16.165:22-144.225.8.54:43598.service: Deactivated successfully. Jul 21 12:40:19.763000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@251-4242-172.31.16.165:22-144.225.8.54:43598 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:19.768691 kernel: audit: type=1109 audit(1784637619.758:1593): pid=8452 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:19.768819 kernel: audit: type=1131 audit(1784637619.763:1594): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@251-4242-172.31.16.165:22-144.225.8.54:43598 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:19.833779 systemd[1]: Started sshd@252-4243-172.31.16.165:22-144.225.8.54:43608.service - OpenSSH per-connection server daemon (144.225.8.54:43608). Jul 21 12:40:19.834000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@252-4243-172.31.16.165:22-144.225.8.54:43608 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:19.843258 kernel: audit: type=1130 audit(1784637619.834:1595): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@252-4243-172.31.16.165:22-144.225.8.54:43608 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:20.086899 sshd[8458]: Invalid user ubuntu from 144.225.8.54 port 43608 Jul 21 12:40:20.149341 sshd[8458]: Connection closed by invalid user ubuntu 144.225.8.54 port 43608 [preauth] Jul 21 12:40:20.149000 audit[8458]: AUDIT1109 pid=8458 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:20.153291 systemd[1]: sshd@252-4243-172.31.16.165:22-144.225.8.54:43608.service: Deactivated successfully. Jul 21 12:40:20.155000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@252-4243-172.31.16.165:22-144.225.8.54:43608 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:20.156249 kernel: audit: type=1109 audit(1784637620.149:1596): pid=8458 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:20.229503 systemd[1]: Started sshd@253-4244-172.31.16.165:22-144.225.8.54:43616.service - OpenSSH per-connection server daemon (144.225.8.54:43616). Jul 21 12:40:20.230000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@253-4244-172.31.16.165:22-144.225.8.54:43616 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:20.479730 sshd[8464]: Invalid user ubuntu from 144.225.8.54 port 43616 Jul 21 12:40:20.540540 sshd[8464]: Connection closed by invalid user ubuntu 144.225.8.54 port 43616 [preauth] Jul 21 12:40:20.540000 audit[8464]: AUDIT1109 pid=8464 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:20.543620 systemd[1]: sshd@253-4244-172.31.16.165:22-144.225.8.54:43616.service: Deactivated successfully. Jul 21 12:40:20.544000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@253-4244-172.31.16.165:22-144.225.8.54:43616 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:20.616000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@254-107-172.31.16.165:22-144.225.8.54:43630 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:20.616772 systemd[1]: Started sshd@254-107-172.31.16.165:22-144.225.8.54:43630.service - OpenSSH per-connection server daemon (144.225.8.54:43630). Jul 21 12:40:20.861151 sshd[8470]: Invalid user ubuntu from 144.225.8.54 port 43630 Jul 21 12:40:20.922843 sshd[8470]: Connection closed by invalid user ubuntu 144.225.8.54 port 43630 [preauth] Jul 21 12:40:20.922000 audit[8470]: AUDIT1109 pid=8470 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:20.926016 systemd[1]: sshd@254-107-172.31.16.165:22-144.225.8.54:43630.service: Deactivated successfully. Jul 21 12:40:20.926000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@254-107-172.31.16.165:22-144.225.8.54:43630 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:20.996940 systemd[1]: Started sshd@255-108-172.31.16.165:22-144.225.8.54:43642.service - OpenSSH per-connection server daemon (144.225.8.54:43642). Jul 21 12:40:20.997000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@255-108-172.31.16.165:22-144.225.8.54:43642 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:21.242503 sshd[8492]: Invalid user ubuntu from 144.225.8.54 port 43642 Jul 21 12:40:21.302318 sshd[8492]: Connection closed by invalid user ubuntu 144.225.8.54 port 43642 [preauth] Jul 21 12:40:21.302000 audit[8492]: AUDIT1109 pid=8492 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:21.305890 systemd[1]: sshd@255-108-172.31.16.165:22-144.225.8.54:43642.service: Deactivated successfully. Jul 21 12:40:21.307000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@255-108-172.31.16.165:22-144.225.8.54:43642 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:21.375122 systemd[1]: Started sshd@256-4245-172.31.16.165:22-144.225.8.54:43656.service - OpenSSH per-connection server daemon (144.225.8.54:43656). Jul 21 12:40:21.376000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@256-4245-172.31.16.165:22-144.225.8.54:43656 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:21.625037 sshd[8498]: Invalid user ubuntu from 144.225.8.54 port 43656 Jul 21 12:40:21.685319 sshd[8498]: Connection closed by invalid user ubuntu 144.225.8.54 port 43656 [preauth] Jul 21 12:40:21.685000 audit[8498]: AUDIT1109 pid=8498 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:21.688871 systemd[1]: sshd@256-4245-172.31.16.165:22-144.225.8.54:43656.service: Deactivated successfully. Jul 21 12:40:21.689000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@256-4245-172.31.16.165:22-144.225.8.54:43656 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:21.758000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@257-4246-172.31.16.165:22-144.225.8.54:43666 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:21.758794 systemd[1]: Started sshd@257-4246-172.31.16.165:22-144.225.8.54:43666.service - OpenSSH per-connection server daemon (144.225.8.54:43666). Jul 21 12:40:22.011264 sshd[8504]: Invalid user ubuntu from 144.225.8.54 port 43666 Jul 21 12:40:22.071011 sshd[8504]: Connection closed by invalid user ubuntu 144.225.8.54 port 43666 [preauth] Jul 21 12:40:22.071000 audit[8504]: AUDIT1109 pid=8504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:22.075918 systemd[1]: sshd@257-4246-172.31.16.165:22-144.225.8.54:43666.service: Deactivated successfully. Jul 21 12:40:22.076000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@257-4246-172.31.16.165:22-144.225.8.54:43666 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:22.148617 systemd[1]: Started sshd@258-4247-172.31.16.165:22-144.225.8.54:43670.service - OpenSSH per-connection server daemon (144.225.8.54:43670). Jul 21 12:40:22.148000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@258-4247-172.31.16.165:22-144.225.8.54:43670 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:22.419299 sshd[8510]: Invalid user ubuntu from 144.225.8.54 port 43670 Jul 21 12:40:22.480191 sshd[8510]: Connection closed by invalid user ubuntu 144.225.8.54 port 43670 [preauth] Jul 21 12:40:22.480000 audit[8510]: AUDIT1109 pid=8510 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:22.483519 systemd[1]: sshd@258-4247-172.31.16.165:22-144.225.8.54:43670.service: Deactivated successfully. Jul 21 12:40:22.484000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@258-4247-172.31.16.165:22-144.225.8.54:43670 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:22.557000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@259-4248-172.31.16.165:22-144.225.8.54:43676 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:22.557244 systemd[1]: Started sshd@259-4248-172.31.16.165:22-144.225.8.54:43676.service - OpenSSH per-connection server daemon (144.225.8.54:43676). Jul 21 12:40:22.614046 systemd[1]: Started sshd@260-4249-172.31.16.165:22-20.76.1.115:36132.service - OpenSSH per-connection server daemon (20.76.1.115:36132). Jul 21 12:40:22.614000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@260-4249-172.31.16.165:22-20.76.1.115:36132 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:22.844890 sshd[8537]: Invalid user ubuntu from 144.225.8.54 port 43676 Jul 21 12:40:22.906152 sshd[8537]: Connection closed by invalid user ubuntu 144.225.8.54 port 43676 [preauth] Jul 21 12:40:22.906000 audit[8537]: AUDIT1109 pid=8537 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:22.909855 systemd[1]: sshd@259-4248-172.31.16.165:22-144.225.8.54:43676.service: Deactivated successfully. Jul 21 12:40:22.910000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@259-4248-172.31.16.165:22-144.225.8.54:43676 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:22.981000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@261-109-172.31.16.165:22-144.225.8.54:43678 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:22.979266 systemd[1]: Started sshd@261-109-172.31.16.165:22-144.225.8.54:43678.service - OpenSSH per-connection server daemon (144.225.8.54:43678). Jul 21 12:40:23.228639 sshd[8547]: Invalid user ubuntu from 144.225.8.54 port 43678 Jul 21 12:40:23.289095 sshd[8547]: Connection closed by invalid user ubuntu 144.225.8.54 port 43678 [preauth] Jul 21 12:40:23.289000 audit[8547]: AUDIT1109 pid=8547 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:23.292926 systemd[1]: sshd@261-109-172.31.16.165:22-144.225.8.54:43678.service: Deactivated successfully. Jul 21 12:40:23.293000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@261-109-172.31.16.165:22-144.225.8.54:43678 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:23.364000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@262-110-172.31.16.165:22-144.225.8.54:43688 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:23.364776 systemd[1]: Started sshd@262-110-172.31.16.165:22-144.225.8.54:43688.service - OpenSSH per-connection server daemon (144.225.8.54:43688). Jul 21 12:40:23.489000 audit[8539]: AUDIT1101 pid=8539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:23.491854 sshd[8539]: Accepted publickey for core from 20.76.1.115 port 36132 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:40:23.493000 audit[8539]: AUDIT1103 pid=8539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:23.493000 audit[8539]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffec0dd700 a2=3 a3=0 items=0 ppid=1 pid=8539 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=22 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:23.493000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:40:23.496318 sshd-session[8539]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:40:23.511349 systemd-logind[2347]: New session '22' of user 'core' with class 'user' and type 'tty'. Jul 21 12:40:23.518512 systemd[1]: Started session-22.scope - Session 22 of User core. Jul 21 12:40:23.530000 audit[8539]: AUDIT1105 pid=8539 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:23.534000 audit[8564]: AUDIT1103 pid=8564 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:23.617650 sshd[8560]: Invalid user ubuntu from 144.225.8.54 port 43688 Jul 21 12:40:23.678268 sshd[8560]: Connection closed by invalid user ubuntu 144.225.8.54 port 43688 [preauth] Jul 21 12:40:23.678000 audit[8560]: AUDIT1109 pid=8560 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:23.682286 systemd[1]: sshd@262-110-172.31.16.165:22-144.225.8.54:43688.service: Deactivated successfully. Jul 21 12:40:23.682000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@262-110-172.31.16.165:22-144.225.8.54:43688 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:23.753745 systemd[1]: Started sshd@263-4250-172.31.16.165:22-144.225.8.54:43696.service - OpenSSH per-connection server daemon (144.225.8.54:43696). Jul 21 12:40:23.753000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@263-4250-172.31.16.165:22-144.225.8.54:43696 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.026312 sshd[8568]: Invalid user ubuntu from 144.225.8.54 port 43696 Jul 21 12:40:24.088549 sshd[8568]: Connection closed by invalid user ubuntu 144.225.8.54 port 43696 [preauth] Jul 21 12:40:24.090000 audit[8568]: AUDIT1109 pid=8568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:24.098712 kernel: kauditd_printk_skb: 37 callbacks suppressed Jul 21 12:40:24.094139 systemd[1]: sshd@263-4250-172.31.16.165:22-144.225.8.54:43696.service: Deactivated successfully. Jul 21 12:40:24.099096 kernel: audit: type=1109 audit(1784637624.090:1632): pid=8568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:24.106784 sshd[8564]: Connection closed by 20.76.1.115 port 36132 Jul 21 12:40:24.101987 sshd-session[8539]: pam_unix(sshd:session): session closed for user core Jul 21 12:40:24.094000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@263-4250-172.31.16.165:22-144.225.8.54:43696 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.116340 kernel: audit: type=1131 audit(1784637624.094:1633): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@263-4250-172.31.16.165:22-144.225.8.54:43696 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.112084 systemd[1]: sshd@260-4249-172.31.16.165:22-20.76.1.115:36132.service: Deactivated successfully. Jul 21 12:40:24.120332 systemd[1]: session-22.scope: Deactivated successfully. Jul 21 12:40:24.102000 audit[8539]: AUDIT1106 pid=8539 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:24.131717 kernel: audit: type=1106 audit(1784637624.102:1634): pid=8539 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:24.140676 systemd-logind[2347]: Session 22 logged out. Waiting for processes to exit. Jul 21 12:40:24.104000 audit[8539]: AUDIT1104 pid=8539 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:24.149487 kernel: audit: type=1104 audit(1784637624.104:1635): pid=8539 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:24.113000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@260-4249-172.31.16.165:22-20.76.1.115:36132 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.157947 kernel: audit: type=1131 audit(1784637624.113:1636): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@260-4249-172.31.16.165:22-20.76.1.115:36132 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.176692 systemd[1]: Started sshd@264-4251-172.31.16.165:22-144.225.8.54:43704.service - OpenSSH per-connection server daemon (144.225.8.54:43704). Jul 21 12:40:24.177000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@264-4251-172.31.16.165:22-144.225.8.54:43704 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.185479 kernel: audit: type=1130 audit(1784637624.177:1637): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@264-4251-172.31.16.165:22-144.225.8.54:43704 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.199462 systemd-logind[2347]: Removed session 22. Jul 21 12:40:24.449543 sshd[8584]: Invalid user ubuntu from 144.225.8.54 port 43704 Jul 21 12:40:24.521485 sshd[8584]: Connection closed by invalid user ubuntu 144.225.8.54 port 43704 [preauth] Jul 21 12:40:24.522000 audit[8584]: AUDIT1109 pid=8584 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:24.530252 systemd[1]: sshd@264-4251-172.31.16.165:22-144.225.8.54:43704.service: Deactivated successfully. Jul 21 12:40:24.530000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@264-4251-172.31.16.165:22-144.225.8.54:43704 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.538884 kernel: audit: type=1109 audit(1784637624.522:1638): pid=8584 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:24.539035 kernel: audit: type=1131 audit(1784637624.530:1639): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@264-4251-172.31.16.165:22-144.225.8.54:43704 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.604821 systemd[1]: Started sshd@265-4252-172.31.16.165:22-144.225.8.54:43720.service - OpenSSH per-connection server daemon (144.225.8.54:43720). Jul 21 12:40:24.604000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@265-4252-172.31.16.165:22-144.225.8.54:43720 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.615233 kernel: audit: type=1130 audit(1784637624.604:1640): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@265-4252-172.31.16.165:22-144.225.8.54:43720 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:24.861314 sshd[8590]: Invalid user ubuntu from 144.225.8.54 port 43720 Jul 21 12:40:24.920942 sshd[8590]: Connection closed by invalid user ubuntu 144.225.8.54 port 43720 [preauth] Jul 21 12:40:24.921000 audit[8590]: AUDIT1109 pid=8590 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:24.927238 kernel: audit: type=1109 audit(1784637624.921:1641): pid=8590 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:24.928085 systemd[1]: sshd@265-4252-172.31.16.165:22-144.225.8.54:43720.service: Deactivated successfully. Jul 21 12:40:24.929000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@265-4252-172.31.16.165:22-144.225.8.54:43720 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:25.000000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@266-4253-172.31.16.165:22-144.225.8.54:43722 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:25.000654 systemd[1]: Started sshd@266-4253-172.31.16.165:22-144.225.8.54:43722.service - OpenSSH per-connection server daemon (144.225.8.54:43722). Jul 21 12:40:25.299659 sshd[8596]: Invalid user ubuntu from 144.225.8.54 port 43722 Jul 21 12:40:25.359931 sshd[8596]: Connection closed by invalid user ubuntu 144.225.8.54 port 43722 [preauth] Jul 21 12:40:25.360000 audit[8596]: AUDIT1109 pid=8596 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:25.363976 systemd[1]: sshd@266-4253-172.31.16.165:22-144.225.8.54:43722.service: Deactivated successfully. Jul 21 12:40:25.364000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@266-4253-172.31.16.165:22-144.225.8.54:43722 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:25.433000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@267-4254-172.31.16.165:22-144.225.8.54:43724 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:25.433760 systemd[1]: Started sshd@267-4254-172.31.16.165:22-144.225.8.54:43724.service - OpenSSH per-connection server daemon (144.225.8.54:43724). Jul 21 12:40:25.679343 sshd[8603]: Invalid user ubuntu from 144.225.8.54 port 43724 Jul 21 12:40:25.739687 sshd[8603]: Connection closed by invalid user ubuntu 144.225.8.54 port 43724 [preauth] Jul 21 12:40:25.740000 audit[8603]: AUDIT1109 pid=8603 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:25.742501 systemd[1]: sshd@267-4254-172.31.16.165:22-144.225.8.54:43724.service: Deactivated successfully. Jul 21 12:40:25.743000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@267-4254-172.31.16.165:22-144.225.8.54:43724 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:25.823060 systemd[1]: Started sshd@268-4255-172.31.16.165:22-144.225.8.54:43734.service - OpenSSH per-connection server daemon (144.225.8.54:43734). Jul 21 12:40:25.823000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@268-4255-172.31.16.165:22-144.225.8.54:43734 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:26.118229 sshd[8626]: Invalid user ubuntu from 144.225.8.54 port 43734 Jul 21 12:40:26.180935 sshd[8626]: Connection closed by invalid user ubuntu 144.225.8.54 port 43734 [preauth] Jul 21 12:40:26.181000 audit[8626]: AUDIT1109 pid=8626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:26.184388 systemd[1]: sshd@268-4255-172.31.16.165:22-144.225.8.54:43734.service: Deactivated successfully. Jul 21 12:40:26.185000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@268-4255-172.31.16.165:22-144.225.8.54:43734 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:26.263000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@269-4256-172.31.16.165:22-144.225.8.54:43736 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:26.263896 systemd[1]: Started sshd@269-4256-172.31.16.165:22-144.225.8.54:43736.service - OpenSSH per-connection server daemon (144.225.8.54:43736). Jul 21 12:40:26.534813 sshd[8640]: Invalid user ubuntu from 144.225.8.54 port 43736 Jul 21 12:40:26.596216 sshd[8640]: Connection closed by invalid user ubuntu 144.225.8.54 port 43736 [preauth] Jul 21 12:40:26.596000 audit[8640]: AUDIT1109 pid=8640 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:26.601030 systemd[1]: sshd@269-4256-172.31.16.165:22-144.225.8.54:43736.service: Deactivated successfully. Jul 21 12:40:26.601000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@269-4256-172.31.16.165:22-144.225.8.54:43736 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:26.674000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@270-4257-172.31.16.165:22-144.225.8.54:43752 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:26.674739 systemd[1]: Started sshd@270-4257-172.31.16.165:22-144.225.8.54:43752.service - OpenSSH per-connection server daemon (144.225.8.54:43752). Jul 21 12:40:26.924959 sshd[8668]: Invalid user ubuntu from 144.225.8.54 port 43752 Jul 21 12:40:26.986447 sshd[8668]: Connection closed by invalid user ubuntu 144.225.8.54 port 43752 [preauth] Jul 21 12:40:26.987000 audit[8668]: AUDIT1109 pid=8668 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:26.990545 systemd[1]: sshd@270-4257-172.31.16.165:22-144.225.8.54:43752.service: Deactivated successfully. Jul 21 12:40:26.992000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@270-4257-172.31.16.165:22-144.225.8.54:43752 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:27.062000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@271-111-172.31.16.165:22-144.225.8.54:43768 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:27.062008 systemd[1]: Started sshd@271-111-172.31.16.165:22-144.225.8.54:43768.service - OpenSSH per-connection server daemon (144.225.8.54:43768). Jul 21 12:40:27.325985 sshd[8674]: Invalid user ubuntu from 144.225.8.54 port 43768 Jul 21 12:40:27.386100 sshd[8674]: Connection closed by invalid user ubuntu 144.225.8.54 port 43768 [preauth] Jul 21 12:40:27.386000 audit[8674]: AUDIT1109 pid=8674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:27.390724 systemd[1]: sshd@271-111-172.31.16.165:22-144.225.8.54:43768.service: Deactivated successfully. Jul 21 12:40:27.391000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@271-111-172.31.16.165:22-144.225.8.54:43768 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:27.463000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@272-112-172.31.16.165:22-144.225.8.54:43772 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:27.463860 systemd[1]: Started sshd@272-112-172.31.16.165:22-144.225.8.54:43772.service - OpenSSH per-connection server daemon (144.225.8.54:43772). Jul 21 12:40:27.730638 sshd[8680]: Invalid user ubuntu from 144.225.8.54 port 43772 Jul 21 12:40:27.792164 sshd[8680]: Connection closed by invalid user ubuntu 144.225.8.54 port 43772 [preauth] Jul 21 12:40:27.792000 audit[8680]: AUDIT1109 pid=8680 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:27.794783 systemd[1]: sshd@272-112-172.31.16.165:22-144.225.8.54:43772.service: Deactivated successfully. Jul 21 12:40:27.797000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@272-112-172.31.16.165:22-144.225.8.54:43772 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:27.866573 systemd[1]: Started sshd@273-113-172.31.16.165:22-144.225.8.54:36542.service - OpenSSH per-connection server daemon (144.225.8.54:36542). Jul 21 12:40:27.868000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@273-113-172.31.16.165:22-144.225.8.54:36542 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:28.111895 sshd[8686]: Invalid user ubuntu from 144.225.8.54 port 36542 Jul 21 12:40:28.171923 sshd[8686]: Connection closed by invalid user ubuntu 144.225.8.54 port 36542 [preauth] Jul 21 12:40:28.172000 audit[8686]: AUDIT1109 pid=8686 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:28.175777 systemd[1]: sshd@273-113-172.31.16.165:22-144.225.8.54:36542.service: Deactivated successfully. Jul 21 12:40:28.177000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@273-113-172.31.16.165:22-144.225.8.54:36542 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:28.245166 systemd[1]: Started sshd@274-114-172.31.16.165:22-144.225.8.54:36548.service - OpenSSH per-connection server daemon (144.225.8.54:36548). Jul 21 12:40:28.245000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@274-114-172.31.16.165:22-144.225.8.54:36548 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:28.501756 sshd[8692]: Invalid user ubuntu from 144.225.8.54 port 36548 Jul 21 12:40:28.562619 sshd[8692]: Connection closed by invalid user ubuntu 144.225.8.54 port 36548 [preauth] Jul 21 12:40:28.563000 audit[8692]: AUDIT1109 pid=8692 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:28.567031 systemd[1]: sshd@274-114-172.31.16.165:22-144.225.8.54:36548.service: Deactivated successfully. Jul 21 12:40:28.568000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@274-114-172.31.16.165:22-144.225.8.54:36548 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:28.636000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@275-115-172.31.16.165:22-144.225.8.54:36554 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:28.636412 systemd[1]: Started sshd@275-115-172.31.16.165:22-144.225.8.54:36554.service - OpenSSH per-connection server daemon (144.225.8.54:36554). Jul 21 12:40:28.881420 sshd[8698]: Invalid user ubuntu from 144.225.8.54 port 36554 Jul 21 12:40:28.941704 sshd[8698]: Connection closed by invalid user ubuntu 144.225.8.54 port 36554 [preauth] Jul 21 12:40:28.942000 audit[8698]: AUDIT1109 pid=8698 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:28.946134 systemd[1]: sshd@275-115-172.31.16.165:22-144.225.8.54:36554.service: Deactivated successfully. Jul 21 12:40:28.947000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@275-115-172.31.16.165:22-144.225.8.54:36554 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.019717 systemd[1]: Started sshd@276-4258-172.31.16.165:22-144.225.8.54:36560.service - OpenSSH per-connection server daemon (144.225.8.54:36560). Jul 21 12:40:29.021000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@276-4258-172.31.16.165:22-144.225.8.54:36560 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.273114 systemd[1]: Started sshd@277-4259-172.31.16.165:22-20.76.1.115:36148.service - OpenSSH per-connection server daemon (20.76.1.115:36148). Jul 21 12:40:29.273000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@277-4259-172.31.16.165:22-20.76.1.115:36148 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.280394 kernel: kauditd_printk_skb: 32 callbacks suppressed Jul 21 12:40:29.280460 kernel: audit: type=1130 audit(1784637629.273:1674): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@277-4259-172.31.16.165:22-20.76.1.115:36148 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.293152 sshd[8704]: Invalid user ubuntu from 144.225.8.54 port 36560 Jul 21 12:40:29.354037 sshd[8704]: Connection closed by invalid user ubuntu 144.225.8.54 port 36560 [preauth] Jul 21 12:40:29.355000 audit[8704]: AUDIT1109 pid=8704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:29.358707 systemd[1]: sshd@276-4258-172.31.16.165:22-144.225.8.54:36560.service: Deactivated successfully. Jul 21 12:40:29.360000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@276-4258-172.31.16.165:22-144.225.8.54:36560 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.367561 kernel: audit: type=1109 audit(1784637629.355:1675): pid=8704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:29.367691 kernel: audit: type=1131 audit(1784637629.360:1676): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@276-4258-172.31.16.165:22-144.225.8.54:36560 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.431348 systemd[1]: Started sshd@278-4260-172.31.16.165:22-144.225.8.54:36572.service - OpenSSH per-connection server daemon (144.225.8.54:36572). Jul 21 12:40:29.432000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@278-4260-172.31.16.165:22-144.225.8.54:36572 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.442394 kernel: audit: type=1130 audit(1784637629.432:1677): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@278-4260-172.31.16.165:22-144.225.8.54:36572 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.685334 sshd[8714]: Invalid user ubuntu from 144.225.8.54 port 36572 Jul 21 12:40:29.746273 sshd[8714]: Connection closed by invalid user ubuntu 144.225.8.54 port 36572 [preauth] Jul 21 12:40:29.746000 audit[8714]: AUDIT1109 pid=8714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:29.753344 kernel: audit: type=1109 audit(1784637629.746:1678): pid=8714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:29.754751 systemd[1]: sshd@278-4260-172.31.16.165:22-144.225.8.54:36572.service: Deactivated successfully. Jul 21 12:40:29.755000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@278-4260-172.31.16.165:22-144.225.8.54:36572 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.764255 kernel: audit: type=1131 audit(1784637629.755:1679): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@278-4260-172.31.16.165:22-144.225.8.54:36572 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.826000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@279-116-172.31.16.165:22-144.225.8.54:36578 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:29.826003 systemd[1]: Started sshd@279-116-172.31.16.165:22-144.225.8.54:36578.service - OpenSSH per-connection server daemon (144.225.8.54:36578). Jul 21 12:40:29.835270 kernel: audit: type=1130 audit(1784637629.826:1680): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@279-116-172.31.16.165:22-144.225.8.54:36578 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:30.082466 sshd[8720]: Invalid user ubuntu from 144.225.8.54 port 36578 Jul 21 12:40:30.131000 audit[8708]: AUDIT1101 pid=8708 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:30.137753 sshd[8708]: Accepted publickey for core from 20.76.1.115 port 36148 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:40:30.138716 kernel: audit: type=1101 audit(1784637630.131:1681): pid=8708 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:30.139000 audit[8708]: AUDIT1103 pid=8708 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:30.146416 sshd[8720]: Connection closed by invalid user ubuntu 144.225.8.54 port 36578 [preauth] Jul 21 12:40:30.147456 sshd-session[8708]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:40:30.155251 kernel: audit: type=1103 audit(1784637630.139:1682): pid=8708 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:30.155348 kernel: audit: type=1006 audit(1784637630.144:1683): pid=8708 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=23 res=1 Jul 21 12:40:30.144000 audit[8708]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffcdc2e380 a2=3 a3=0 items=0 ppid=1 pid=8708 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=23 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:30.144000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:40:30.148000 audit[8720]: AUDIT1109 pid=8720 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:30.158876 systemd[1]: sshd@279-116-172.31.16.165:22-144.225.8.54:36578.service: Deactivated successfully. Jul 21 12:40:30.159000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@279-116-172.31.16.165:22-144.225.8.54:36578 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:30.174306 systemd-logind[2347]: New session '23' of user 'core' with class 'user' and type 'tty'. Jul 21 12:40:30.180483 systemd[1]: Started session-23.scope - Session 23 of User core. Jul 21 12:40:30.191000 audit[8708]: AUDIT1105 pid=8708 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:30.195000 audit[8726]: AUDIT1103 pid=8726 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:30.235356 systemd[1]: Started sshd@280-117-172.31.16.165:22-144.225.8.54:36590.service - OpenSSH per-connection server daemon (144.225.8.54:36590). Jul 21 12:40:30.236000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@280-117-172.31.16.165:22-144.225.8.54:36590 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:30.485701 sshd[8728]: Invalid user ubuntu from 144.225.8.54 port 36590 Jul 21 12:40:30.549847 sshd[8728]: Connection closed by invalid user ubuntu 144.225.8.54 port 36590 [preauth] Jul 21 12:40:30.550000 audit[8728]: AUDIT1109 pid=8728 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:30.555563 systemd[1]: sshd@280-117-172.31.16.165:22-144.225.8.54:36590.service: Deactivated successfully. Jul 21 12:40:30.559000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@280-117-172.31.16.165:22-144.225.8.54:36590 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:30.629853 systemd[1]: Started sshd@281-118-172.31.16.165:22-144.225.8.54:36604.service - OpenSSH per-connection server daemon (144.225.8.54:36604). Jul 21 12:40:30.632000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@281-118-172.31.16.165:22-144.225.8.54:36604 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:30.741895 sshd[8726]: Connection closed by 20.76.1.115 port 36148 Jul 21 12:40:30.743180 sshd-session[8708]: pam_unix(sshd:session): session closed for user core Jul 21 12:40:30.744000 audit[8708]: AUDIT1106 pid=8708 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:30.744000 audit[8708]: AUDIT1104 pid=8708 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:30.750928 systemd[1]: sshd@277-4259-172.31.16.165:22-20.76.1.115:36148.service: Deactivated successfully. Jul 21 12:40:30.754000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@277-4259-172.31.16.165:22-20.76.1.115:36148 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:30.760337 systemd[1]: session-23.scope: Deactivated successfully. Jul 21 12:40:30.765657 systemd-logind[2347]: Session 23 logged out. Waiting for processes to exit. Jul 21 12:40:30.772334 systemd-logind[2347]: Removed session 23. Jul 21 12:40:30.885695 sshd[8741]: Invalid user ubuntu from 144.225.8.54 port 36604 Jul 21 12:40:30.945716 sshd[8741]: Connection closed by invalid user ubuntu 144.225.8.54 port 36604 [preauth] Jul 21 12:40:30.946000 audit[8741]: AUDIT1109 pid=8741 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:30.949810 systemd[1]: sshd@281-118-172.31.16.165:22-144.225.8.54:36604.service: Deactivated successfully. Jul 21 12:40:30.950000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@281-118-172.31.16.165:22-144.225.8.54:36604 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:31.021000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@282-4261-172.31.16.165:22-144.225.8.54:36620 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:31.021806 systemd[1]: Started sshd@282-4261-172.31.16.165:22-144.225.8.54:36620.service - OpenSSH per-connection server daemon (144.225.8.54:36620). Jul 21 12:40:31.276427 sshd[8750]: Invalid user ubuntu from 144.225.8.54 port 36620 Jul 21 12:40:31.336529 sshd[8750]: Connection closed by invalid user ubuntu 144.225.8.54 port 36620 [preauth] Jul 21 12:40:31.336000 audit[8750]: AUDIT1109 pid=8750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:31.340179 systemd[1]: sshd@282-4261-172.31.16.165:22-144.225.8.54:36620.service: Deactivated successfully. Jul 21 12:40:31.340000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@282-4261-172.31.16.165:22-144.225.8.54:36620 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:31.414055 systemd[1]: Started sshd@283-4262-172.31.16.165:22-144.225.8.54:36626.service - OpenSSH per-connection server daemon (144.225.8.54:36626). Jul 21 12:40:31.415000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@283-4262-172.31.16.165:22-144.225.8.54:36626 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:31.660003 sshd[8756]: Invalid user ubuntu from 144.225.8.54 port 36626 Jul 21 12:40:31.719832 sshd[8756]: Connection closed by invalid user ubuntu 144.225.8.54 port 36626 [preauth] Jul 21 12:40:31.720000 audit[8756]: AUDIT1109 pid=8756 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:31.723710 systemd[1]: sshd@283-4262-172.31.16.165:22-144.225.8.54:36626.service: Deactivated successfully. Jul 21 12:40:31.725000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@283-4262-172.31.16.165:22-144.225.8.54:36626 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:31.792777 systemd[1]: Started sshd@284-119-172.31.16.165:22-144.225.8.54:36628.service - OpenSSH per-connection server daemon (144.225.8.54:36628). Jul 21 12:40:31.792000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@284-119-172.31.16.165:22-144.225.8.54:36628 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:32.040465 sshd[8762]: Invalid user ubuntu from 144.225.8.54 port 36628 Jul 21 12:40:32.102441 sshd[8762]: Connection closed by invalid user ubuntu 144.225.8.54 port 36628 [preauth] Jul 21 12:40:32.102000 audit[8762]: AUDIT1109 pid=8762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:32.105837 systemd[1]: sshd@284-119-172.31.16.165:22-144.225.8.54:36628.service: Deactivated successfully. Jul 21 12:40:32.108000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@284-119-172.31.16.165:22-144.225.8.54:36628 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:32.177753 systemd[1]: Started sshd@285-120-172.31.16.165:22-144.225.8.54:36632.service - OpenSSH per-connection server daemon (144.225.8.54:36632). Jul 21 12:40:32.177000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@285-120-172.31.16.165:22-144.225.8.54:36632 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:32.435818 sshd[8791]: Invalid user ubuntu from 144.225.8.54 port 36632 Jul 21 12:40:32.496764 sshd[8791]: Connection closed by invalid user ubuntu 144.225.8.54 port 36632 [preauth] Jul 21 12:40:32.496000 audit[8791]: AUDIT1109 pid=8791 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:32.499971 systemd[1]: sshd@285-120-172.31.16.165:22-144.225.8.54:36632.service: Deactivated successfully. Jul 21 12:40:32.500000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@285-120-172.31.16.165:22-144.225.8.54:36632 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:32.576000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@286-121-172.31.16.165:22-144.225.8.54:36642 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:32.576553 systemd[1]: Started sshd@286-121-172.31.16.165:22-144.225.8.54:36642.service - OpenSSH per-connection server daemon (144.225.8.54:36642). Jul 21 12:40:32.823963 sshd[8797]: Invalid user debian from 144.225.8.54 port 36642 Jul 21 12:40:32.884731 sshd[8797]: Connection closed by invalid user debian 144.225.8.54 port 36642 [preauth] Jul 21 12:40:32.885000 audit[8797]: AUDIT1109 pid=8797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:32.889078 systemd[1]: sshd@286-121-172.31.16.165:22-144.225.8.54:36642.service: Deactivated successfully. Jul 21 12:40:32.889000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@286-121-172.31.16.165:22-144.225.8.54:36642 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:32.958000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@287-4263-172.31.16.165:22-144.225.8.54:36656 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:32.958796 systemd[1]: Started sshd@287-4263-172.31.16.165:22-144.225.8.54:36656.service - OpenSSH per-connection server daemon (144.225.8.54:36656). Jul 21 12:40:33.216551 sshd[8823]: Invalid user debian from 144.225.8.54 port 36656 Jul 21 12:40:33.276932 sshd[8823]: Connection closed by invalid user debian 144.225.8.54 port 36656 [preauth] Jul 21 12:40:33.277000 audit[8823]: AUDIT1109 pid=8823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:33.281460 systemd[1]: sshd@287-4263-172.31.16.165:22-144.225.8.54:36656.service: Deactivated successfully. Jul 21 12:40:33.282000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@287-4263-172.31.16.165:22-144.225.8.54:36656 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:33.359000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@288-122-172.31.16.165:22-144.225.8.54:36662 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:33.358268 systemd[1]: Started sshd@288-122-172.31.16.165:22-144.225.8.54:36662.service - OpenSSH per-connection server daemon (144.225.8.54:36662). Jul 21 12:40:33.618488 sshd[8836]: Invalid user debian from 144.225.8.54 port 36662 Jul 21 12:40:33.679289 sshd[8836]: Connection closed by invalid user debian 144.225.8.54 port 36662 [preauth] Jul 21 12:40:33.680000 audit[8836]: AUDIT1109 pid=8836 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:33.683853 systemd[1]: sshd@288-122-172.31.16.165:22-144.225.8.54:36662.service: Deactivated successfully. Jul 21 12:40:33.686000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@288-122-172.31.16.165:22-144.225.8.54:36662 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:33.757000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@289-4264-172.31.16.165:22-144.225.8.54:36668 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:33.757466 systemd[1]: Started sshd@289-4264-172.31.16.165:22-144.225.8.54:36668.service - OpenSSH per-connection server daemon (144.225.8.54:36668). Jul 21 12:40:34.017583 sshd[8842]: Invalid user debian from 144.225.8.54 port 36668 Jul 21 12:40:34.077376 sshd[8842]: Connection closed by invalid user debian 144.225.8.54 port 36668 [preauth] Jul 21 12:40:34.077000 audit[8842]: AUDIT1109 pid=8842 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:34.086818 systemd[1]: sshd@289-4264-172.31.16.165:22-144.225.8.54:36668.service: Deactivated successfully. Jul 21 12:40:34.088000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@289-4264-172.31.16.165:22-144.225.8.54:36668 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:34.158000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@290-4265-172.31.16.165:22-144.225.8.54:36674 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:34.158805 systemd[1]: Started sshd@290-4265-172.31.16.165:22-144.225.8.54:36674.service - OpenSSH per-connection server daemon (144.225.8.54:36674). Jul 21 12:40:34.433165 sshd[8848]: Invalid user debian from 144.225.8.54 port 36674 Jul 21 12:40:34.494900 sshd[8848]: Connection closed by invalid user debian 144.225.8.54 port 36674 [preauth] Jul 21 12:40:34.494000 audit[8848]: AUDIT1109 pid=8848 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:34.498593 systemd[1]: sshd@290-4265-172.31.16.165:22-144.225.8.54:36674.service: Deactivated successfully. Jul 21 12:40:34.501411 kernel: kauditd_printk_skb: 40 callbacks suppressed Jul 21 12:40:34.501493 kernel: audit: type=1109 audit(1784637634.494:1722): pid=8848 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:34.496000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@290-4265-172.31.16.165:22-144.225.8.54:36674 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:34.510252 kernel: audit: type=1131 audit(1784637634.496:1723): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@290-4265-172.31.16.165:22-144.225.8.54:36674 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:34.573598 systemd[1]: Started sshd@291-4266-172.31.16.165:22-144.225.8.54:36684.service - OpenSSH per-connection server daemon (144.225.8.54:36684). Jul 21 12:40:34.573000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@291-4266-172.31.16.165:22-144.225.8.54:36684 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:34.583249 kernel: audit: type=1130 audit(1784637634.573:1724): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@291-4266-172.31.16.165:22-144.225.8.54:36684 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:34.845527 sshd[8854]: Invalid user debian from 144.225.8.54 port 36684 Jul 21 12:40:34.906478 sshd[8854]: Connection closed by invalid user debian 144.225.8.54 port 36684 [preauth] Jul 21 12:40:34.907000 audit[8854]: AUDIT1109 pid=8854 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:34.912091 systemd[1]: sshd@291-4266-172.31.16.165:22-144.225.8.54:36684.service: Deactivated successfully. Jul 21 12:40:34.912000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@291-4266-172.31.16.165:22-144.225.8.54:36684 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:34.919839 kernel: audit: type=1109 audit(1784637634.907:1725): pid=8854 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:34.919956 kernel: audit: type=1131 audit(1784637634.912:1726): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@291-4266-172.31.16.165:22-144.225.8.54:36684 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:34.985007 systemd[1]: Started sshd@292-4267-172.31.16.165:22-144.225.8.54:36698.service - OpenSSH per-connection server daemon (144.225.8.54:36698). Jul 21 12:40:34.985000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@292-4267-172.31.16.165:22-144.225.8.54:36698 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:34.997361 kernel: audit: type=1130 audit(1784637634.985:1727): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@292-4267-172.31.16.165:22-144.225.8.54:36698 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:35.254895 sshd[8860]: Invalid user debian from 144.225.8.54 port 36698 Jul 21 12:40:35.315823 sshd[8860]: Connection closed by invalid user debian 144.225.8.54 port 36698 [preauth] Jul 21 12:40:35.316000 audit[8860]: AUDIT1109 pid=8860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:35.324242 kernel: audit: type=1109 audit(1784637635.316:1728): pid=8860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:35.325051 systemd[1]: sshd@292-4267-172.31.16.165:22-144.225.8.54:36698.service: Deactivated successfully. Jul 21 12:40:35.327000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@292-4267-172.31.16.165:22-144.225.8.54:36698 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:35.334253 kernel: audit: type=1131 audit(1784637635.327:1729): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@292-4267-172.31.16.165:22-144.225.8.54:36698 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:35.394000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@293-4268-172.31.16.165:22-144.225.8.54:36702 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:35.394791 systemd[1]: Started sshd@293-4268-172.31.16.165:22-144.225.8.54:36702.service - OpenSSH per-connection server daemon (144.225.8.54:36702). Jul 21 12:40:35.406349 kernel: audit: type=1130 audit(1784637635.394:1730): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@293-4268-172.31.16.165:22-144.225.8.54:36702 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:35.678736 sshd[8866]: Invalid user debian from 144.225.8.54 port 36702 Jul 21 12:40:35.741188 sshd[8866]: Connection closed by invalid user debian 144.225.8.54 port 36702 [preauth] Jul 21 12:40:35.741000 audit[8866]: AUDIT1109 pid=8866 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:35.747514 systemd[1]: sshd@293-4268-172.31.16.165:22-144.225.8.54:36702.service: Deactivated successfully. Jul 21 12:40:35.748288 kernel: audit: type=1109 audit(1784637635.741:1731): pid=8866 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:35.748000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@293-4268-172.31.16.165:22-144.225.8.54:36702 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:35.820000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@294-4269-172.31.16.165:22-144.225.8.54:36716 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:35.820813 systemd[1]: Started sshd@294-4269-172.31.16.165:22-144.225.8.54:36716.service - OpenSSH per-connection server daemon (144.225.8.54:36716). Jul 21 12:40:35.926963 systemd[1]: Started sshd@295-4270-172.31.16.165:22-20.76.1.115:55564.service - OpenSSH per-connection server daemon (20.76.1.115:55564). Jul 21 12:40:35.927000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@295-4270-172.31.16.165:22-20.76.1.115:55564 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:36.096612 sshd[8877]: Invalid user debian from 144.225.8.54 port 36716 Jul 21 12:40:36.159238 sshd[8877]: Connection closed by invalid user debian 144.225.8.54 port 36716 [preauth] Jul 21 12:40:36.159000 audit[8877]: AUDIT1109 pid=8877 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:36.164337 systemd[1]: sshd@294-4269-172.31.16.165:22-144.225.8.54:36716.service: Deactivated successfully. Jul 21 12:40:36.164000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@294-4269-172.31.16.165:22-144.225.8.54:36716 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:36.238582 systemd[1]: Started sshd@296-4271-172.31.16.165:22-144.225.8.54:36732.service - OpenSSH per-connection server daemon (144.225.8.54:36732). Jul 21 12:40:36.238000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@296-4271-172.31.16.165:22-144.225.8.54:36732 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:36.540487 sshd[8887]: Invalid user debian from 144.225.8.54 port 36732 Jul 21 12:40:36.599358 sshd[8887]: Connection closed by invalid user debian 144.225.8.54 port 36732 [preauth] Jul 21 12:40:36.600000 audit[8887]: AUDIT1109 pid=8887 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:36.606716 systemd[1]: sshd@296-4271-172.31.16.165:22-144.225.8.54:36732.service: Deactivated successfully. Jul 21 12:40:36.608000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@296-4271-172.31.16.165:22-144.225.8.54:36732 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:36.675000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@297-123-172.31.16.165:22-144.225.8.54:36738 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:36.675812 systemd[1]: Started sshd@297-123-172.31.16.165:22-144.225.8.54:36738.service - OpenSSH per-connection server daemon (144.225.8.54:36738). Jul 21 12:40:36.827000 audit[8881]: AUDIT1101 pid=8881 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:36.830608 sshd[8881]: Accepted publickey for core from 20.76.1.115 port 55564 ssh2: RSA SHA256:2VgdT30/jpPxwhgjxWOwUkLQrTI4n2eoyKJ+G4yHru8 Jul 21 12:40:36.833000 audit[8881]: AUDIT1103 pid=8881 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:36.834000 audit[8881]: SYSCALL arch=c00000b7 syscall=64 success=yes exit=3 a0=8 a1=ffffc1b392e0 a2=3 a3=0 items=0 ppid=1 pid=8881 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=24 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:36.834000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Jul 21 12:40:36.837726 sshd-session[8881]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Jul 21 12:40:36.855311 systemd-logind[2347]: New session '24' of user 'core' with class 'user' and type 'tty'. Jul 21 12:40:36.861542 systemd[1]: Started session-24.scope - Session 24 of User core. Jul 21 12:40:36.883000 audit[8881]: AUDIT1105 pid=8881 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:36.887000 audit[8897]: AUDIT1103 pid=8897 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:36.924617 sshd[8893]: Invalid user debian from 144.225.8.54 port 36738 Jul 21 12:40:36.984910 sshd[8893]: Connection closed by invalid user debian 144.225.8.54 port 36738 [preauth] Jul 21 12:40:36.986000 audit[8893]: AUDIT1109 pid=8893 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:36.991489 systemd[1]: sshd@297-123-172.31.16.165:22-144.225.8.54:36738.service: Deactivated successfully. Jul 21 12:40:36.993000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@297-123-172.31.16.165:22-144.225.8.54:36738 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:37.064000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@298-4272-172.31.16.165:22-144.225.8.54:36754 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:37.064608 systemd[1]: Started sshd@298-4272-172.31.16.165:22-144.225.8.54:36754.service - OpenSSH per-connection server daemon (144.225.8.54:36754). Jul 21 12:40:37.337747 sshd[8917]: Invalid user debian from 144.225.8.54 port 36754 Jul 21 12:40:37.399136 sshd[8917]: Connection closed by invalid user debian 144.225.8.54 port 36754 [preauth] Jul 21 12:40:37.399000 audit[8917]: AUDIT1109 pid=8917 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:37.403793 systemd[1]: sshd@298-4272-172.31.16.165:22-144.225.8.54:36754.service: Deactivated successfully. Jul 21 12:40:37.404000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@298-4272-172.31.16.165:22-144.225.8.54:36754 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:37.442428 sshd[8897]: Connection closed by 20.76.1.115 port 55564 Jul 21 12:40:37.447528 sshd-session[8881]: pam_unix(sshd:session): session closed for user core Jul 21 12:40:37.448000 audit[8881]: AUDIT1106 pid=8881 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:37.448000 audit[8881]: AUDIT1104 pid=8881 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.76.1.115 addr=20.76.1.115 terminal=ssh res=success' Jul 21 12:40:37.457759 systemd[1]: sshd@295-4270-172.31.16.165:22-20.76.1.115:55564.service: Deactivated successfully. Jul 21 12:40:37.458000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@295-4270-172.31.16.165:22-20.76.1.115:55564 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:37.468823 systemd[1]: session-24.scope: Deactivated successfully. Jul 21 12:40:37.481361 systemd-logind[2347]: Session 24 logged out. Waiting for processes to exit. Jul 21 12:40:37.505000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@299-124-172.31.16.165:22-144.225.8.54:36764 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:37.505756 systemd[1]: Started sshd@299-124-172.31.16.165:22-144.225.8.54:36764.service - OpenSSH per-connection server daemon (144.225.8.54:36764). Jul 21 12:40:37.526320 systemd-logind[2347]: Removed session 24. Jul 21 12:40:37.782141 sshd[8935]: Invalid user debian from 144.225.8.54 port 36764 Jul 21 12:40:37.842534 sshd[8935]: Connection closed by invalid user debian 144.225.8.54 port 36764 [preauth] Jul 21 12:40:37.843000 audit[8935]: AUDIT1109 pid=8935 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:37.847842 systemd[1]: sshd@299-124-172.31.16.165:22-144.225.8.54:36764.service: Deactivated successfully. Jul 21 12:40:37.850000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@299-124-172.31.16.165:22-144.225.8.54:36764 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:37.934677 systemd[1]: Started sshd@300-125-172.31.16.165:22-144.225.8.54:44102.service - OpenSSH per-connection server daemon (144.225.8.54:44102). Jul 21 12:40:37.936000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@300-125-172.31.16.165:22-144.225.8.54:44102 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:38.208582 sshd[8941]: Invalid user debian from 144.225.8.54 port 44102 Jul 21 12:40:38.268635 sshd[8941]: Connection closed by invalid user debian 144.225.8.54 port 44102 [preauth] Jul 21 12:40:38.269000 audit[8941]: AUDIT1109 pid=8941 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:38.272503 systemd[1]: sshd@300-125-172.31.16.165:22-144.225.8.54:44102.service: Deactivated successfully. Jul 21 12:40:38.273000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@300-125-172.31.16.165:22-144.225.8.54:44102 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:38.344000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@301-4273-172.31.16.165:22-144.225.8.54:44104 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:38.344385 systemd[1]: Started sshd@301-4273-172.31.16.165:22-144.225.8.54:44104.service - OpenSSH per-connection server daemon (144.225.8.54:44104). Jul 21 12:40:38.596117 sshd[8947]: Invalid user debian from 144.225.8.54 port 44104 Jul 21 12:40:38.656451 sshd[8947]: Connection closed by invalid user debian 144.225.8.54 port 44104 [preauth] Jul 21 12:40:38.656000 audit[8947]: AUDIT1109 pid=8947 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:38.658851 systemd[1]: sshd@301-4273-172.31.16.165:22-144.225.8.54:44104.service: Deactivated successfully. Jul 21 12:40:38.659000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@301-4273-172.31.16.165:22-144.225.8.54:44104 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:38.739005 systemd[1]: Started sshd@302-126-172.31.16.165:22-144.225.8.54:44110.service - OpenSSH per-connection server daemon (144.225.8.54:44110). Jul 21 12:40:38.740000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@302-126-172.31.16.165:22-144.225.8.54:44110 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:39.000463 sshd[8955]: Invalid user debian from 144.225.8.54 port 44110 Jul 21 12:40:39.060488 sshd[8955]: Connection closed by invalid user debian 144.225.8.54 port 44110 [preauth] Jul 21 12:40:39.061000 audit[8955]: AUDIT1109 pid=8955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:39.064477 systemd[1]: sshd@302-126-172.31.16.165:22-144.225.8.54:44110.service: Deactivated successfully. Jul 21 12:40:39.065000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@302-126-172.31.16.165:22-144.225.8.54:44110 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:39.135000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@303-127-172.31.16.165:22-144.225.8.54:44112 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:39.135756 systemd[1]: Started sshd@303-127-172.31.16.165:22-144.225.8.54:44112.service - OpenSSH per-connection server daemon (144.225.8.54:44112). Jul 21 12:40:39.378061 sshd[8961]: Invalid user debian from 144.225.8.54 port 44112 Jul 21 12:40:39.438234 sshd[8961]: Connection closed by invalid user debian 144.225.8.54 port 44112 [preauth] Jul 21 12:40:39.438000 audit[8961]: AUDIT1109 pid=8961 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:39.441613 systemd[1]: sshd@303-127-172.31.16.165:22-144.225.8.54:44112.service: Deactivated successfully. Jul 21 12:40:39.442000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@303-127-172.31.16.165:22-144.225.8.54:44112 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:39.514000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@304-128-172.31.16.165:22-144.225.8.54:44114 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:39.513114 systemd[1]: Started sshd@304-128-172.31.16.165:22-144.225.8.54:44114.service - OpenSSH per-connection server daemon (144.225.8.54:44114). Jul 21 12:40:39.516294 kernel: kauditd_printk_skb: 39 callbacks suppressed Jul 21 12:40:39.516389 kernel: audit: type=1130 audit(1784637639.514:1769): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@304-128-172.31.16.165:22-144.225.8.54:44114 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:39.762662 sshd[8967]: Invalid user debian from 144.225.8.54 port 44114 Jul 21 12:40:39.822768 sshd[8967]: Connection closed by invalid user debian 144.225.8.54 port 44114 [preauth] Jul 21 12:40:39.823000 audit[8967]: AUDIT1109 pid=8967 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:39.828224 systemd[1]: sshd@304-128-172.31.16.165:22-144.225.8.54:44114.service: Deactivated successfully. Jul 21 12:40:39.828000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@304-128-172.31.16.165:22-144.225.8.54:44114 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:39.839091 kernel: audit: type=1109 audit(1784637639.823:1770): pid=8967 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:39.839261 kernel: audit: type=1131 audit(1784637639.828:1771): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@304-128-172.31.16.165:22-144.225.8.54:44114 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:39.897757 systemd[1]: Started sshd@305-129-172.31.16.165:22-144.225.8.54:44120.service - OpenSSH per-connection server daemon (144.225.8.54:44120). Jul 21 12:40:39.897000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@305-129-172.31.16.165:22-144.225.8.54:44120 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:39.907301 kernel: audit: type=1130 audit(1784637639.897:1772): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@305-129-172.31.16.165:22-144.225.8.54:44120 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:40.151100 sshd[8973]: Invalid user debian from 144.225.8.54 port 44120 Jul 21 12:40:40.211322 sshd[8973]: Connection closed by invalid user debian 144.225.8.54 port 44120 [preauth] Jul 21 12:40:40.211000 audit[8973]: AUDIT1109 pid=8973 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:40.218246 kernel: audit: type=1109 audit(1784637640.211:1773): pid=8973 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:40.221819 systemd[1]: sshd@305-129-172.31.16.165:22-144.225.8.54:44120.service: Deactivated successfully. Jul 21 12:40:40.223000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@305-129-172.31.16.165:22-144.225.8.54:44120 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:40.232412 kernel: audit: type=1131 audit(1784637640.223:1774): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@305-129-172.31.16.165:22-144.225.8.54:44120 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:40.287889 systemd[1]: Started sshd@306-130-172.31.16.165:22-144.225.8.54:44122.service - OpenSSH per-connection server daemon (144.225.8.54:44122). Jul 21 12:40:40.287000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@306-130-172.31.16.165:22-144.225.8.54:44122 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:40.300255 kernel: audit: type=1130 audit(1784637640.287:1775): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@306-130-172.31.16.165:22-144.225.8.54:44122 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:40.543890 sshd[8979]: Invalid user debian from 144.225.8.54 port 44122 Jul 21 12:40:40.603666 sshd[8979]: Connection closed by invalid user debian 144.225.8.54 port 44122 [preauth] Jul 21 12:40:40.604000 audit[8979]: AUDIT1109 pid=8979 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:40.609886 systemd[1]: sshd@306-130-172.31.16.165:22-144.225.8.54:44122.service: Deactivated successfully. Jul 21 12:40:40.610000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@306-130-172.31.16.165:22-144.225.8.54:44122 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:40.616001 kernel: audit: type=1109 audit(1784637640.604:1776): pid=8979 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:40.616062 kernel: audit: type=1131 audit(1784637640.610:1777): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@306-130-172.31.16.165:22-144.225.8.54:44122 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:40.679000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@307-131-172.31.16.165:22-144.225.8.54:44134 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:40.679724 systemd[1]: Started sshd@307-131-172.31.16.165:22-144.225.8.54:44134.service - OpenSSH per-connection server daemon (144.225.8.54:44134). Jul 21 12:40:40.690831 kernel: audit: type=1130 audit(1784637640.679:1778): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@307-131-172.31.16.165:22-144.225.8.54:44134 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:40.939356 sshd[8985]: Invalid user debian from 144.225.8.54 port 44134 Jul 21 12:40:40.999007 sshd[8985]: Connection closed by invalid user debian 144.225.8.54 port 44134 [preauth] Jul 21 12:40:40.999000 audit[8985]: AUDIT1109 pid=8985 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:41.002961 systemd[1]: sshd@307-131-172.31.16.165:22-144.225.8.54:44134.service: Deactivated successfully. Jul 21 12:40:41.003000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@307-131-172.31.16.165:22-144.225.8.54:44134 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:41.082000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@308-4274-172.31.16.165:22-144.225.8.54:44136 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:41.082903 systemd[1]: Started sshd@308-4274-172.31.16.165:22-144.225.8.54:44136.service - OpenSSH per-connection server daemon (144.225.8.54:44136). Jul 21 12:40:41.336159 sshd[8991]: Invalid user debian from 144.225.8.54 port 44136 Jul 21 12:40:41.397552 sshd[8991]: Connection closed by invalid user debian 144.225.8.54 port 44136 [preauth] Jul 21 12:40:41.398000 audit[8991]: AUDIT1109 pid=8991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:41.402401 systemd[1]: sshd@308-4274-172.31.16.165:22-144.225.8.54:44136.service: Deactivated successfully. Jul 21 12:40:41.403000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@308-4274-172.31.16.165:22-144.225.8.54:44136 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:41.472000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@309-132-172.31.16.165:22-144.225.8.54:44144 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:41.472781 systemd[1]: Started sshd@309-132-172.31.16.165:22-144.225.8.54:44144.service - OpenSSH per-connection server daemon (144.225.8.54:44144). Jul 21 12:40:41.717081 sshd[8997]: Invalid user debian from 144.225.8.54 port 44144 Jul 21 12:40:41.776861 sshd[8997]: Connection closed by invalid user debian 144.225.8.54 port 44144 [preauth] Jul 21 12:40:41.777000 audit[8997]: AUDIT1109 pid=8997 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:41.782597 systemd[1]: sshd@309-132-172.31.16.165:22-144.225.8.54:44144.service: Deactivated successfully. Jul 21 12:40:41.783000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@309-132-172.31.16.165:22-144.225.8.54:44144 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:41.857952 systemd[1]: Started sshd@310-4275-172.31.16.165:22-144.225.8.54:44156.service - OpenSSH per-connection server daemon (144.225.8.54:44156). Jul 21 12:40:41.858000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@310-4275-172.31.16.165:22-144.225.8.54:44156 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:42.102820 sshd[9003]: Invalid user debian from 144.225.8.54 port 44156 Jul 21 12:40:42.162872 sshd[9003]: Connection closed by invalid user debian 144.225.8.54 port 44156 [preauth] Jul 21 12:40:42.163000 audit[9003]: AUDIT1109 pid=9003 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:42.166839 systemd[1]: sshd@310-4275-172.31.16.165:22-144.225.8.54:44156.service: Deactivated successfully. Jul 21 12:40:42.167000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@310-4275-172.31.16.165:22-144.225.8.54:44156 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:42.235764 systemd[1]: Started sshd@311-133-172.31.16.165:22-144.225.8.54:44172.service - OpenSSH per-connection server daemon (144.225.8.54:44172). Jul 21 12:40:42.235000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@311-133-172.31.16.165:22-144.225.8.54:44172 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:42.481029 sshd[9009]: Invalid user debian from 144.225.8.54 port 44172 Jul 21 12:40:42.540268 sshd[9009]: Connection closed by invalid user debian 144.225.8.54 port 44172 [preauth] Jul 21 12:40:42.540000 audit[9009]: AUDIT1109 pid=9009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:42.543617 systemd[1]: sshd@311-133-172.31.16.165:22-144.225.8.54:44172.service: Deactivated successfully. Jul 21 12:40:42.543000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@311-133-172.31.16.165:22-144.225.8.54:44172 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:42.616755 systemd[1]: Started sshd@312-134-172.31.16.165:22-144.225.8.54:44182.service - OpenSSH per-connection server daemon (144.225.8.54:44182). Jul 21 12:40:42.616000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@312-134-172.31.16.165:22-144.225.8.54:44182 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:42.861791 sshd[9015]: Invalid user debian from 144.225.8.54 port 44182 Jul 21 12:40:42.921182 sshd[9015]: Connection closed by invalid user debian 144.225.8.54 port 44182 [preauth] Jul 21 12:40:42.921000 audit[9015]: AUDIT1109 pid=9015 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:42.924851 systemd[1]: sshd@312-134-172.31.16.165:22-144.225.8.54:44182.service: Deactivated successfully. Jul 21 12:40:42.926000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@312-134-172.31.16.165:22-144.225.8.54:44182 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:42.995742 systemd[1]: Started sshd@313-4276-172.31.16.165:22-144.225.8.54:44184.service - OpenSSH per-connection server daemon (144.225.8.54:44184). Jul 21 12:40:42.995000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@313-4276-172.31.16.165:22-144.225.8.54:44184 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:43.238706 sshd[9021]: Invalid user debian from 144.225.8.54 port 44184 Jul 21 12:40:43.299562 sshd[9021]: Connection closed by invalid user debian 144.225.8.54 port 44184 [preauth] Jul 21 12:40:43.299000 audit[9021]: AUDIT1109 pid=9021 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:43.302753 systemd[1]: sshd@313-4276-172.31.16.165:22-144.225.8.54:44184.service: Deactivated successfully. Jul 21 12:40:43.304000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@313-4276-172.31.16.165:22-144.225.8.54:44184 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:43.374000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@314-135-172.31.16.165:22-144.225.8.54:44188 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:43.374800 systemd[1]: Started sshd@314-135-172.31.16.165:22-144.225.8.54:44188.service - OpenSSH per-connection server daemon (144.225.8.54:44188). Jul 21 12:40:43.620650 sshd[9027]: Invalid user debian from 144.225.8.54 port 44188 Jul 21 12:40:43.682446 sshd[9027]: Connection closed by invalid user debian 144.225.8.54 port 44188 [preauth] Jul 21 12:40:43.683000 audit[9027]: AUDIT1109 pid=9027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:43.686455 systemd[1]: sshd@314-135-172.31.16.165:22-144.225.8.54:44188.service: Deactivated successfully. Jul 21 12:40:43.687000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@314-135-172.31.16.165:22-144.225.8.54:44188 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:43.759797 systemd[1]: Started sshd@315-4277-172.31.16.165:22-144.225.8.54:44202.service - OpenSSH per-connection server daemon (144.225.8.54:44202). Jul 21 12:40:43.759000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@315-4277-172.31.16.165:22-144.225.8.54:44202 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:44.014243 sshd[9033]: Invalid user debian from 144.225.8.54 port 44202 Jul 21 12:40:44.074678 sshd[9033]: Connection closed by invalid user debian 144.225.8.54 port 44202 [preauth] Jul 21 12:40:44.075000 audit[9033]: AUDIT1109 pid=9033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:44.080024 systemd[1]: sshd@315-4277-172.31.16.165:22-144.225.8.54:44202.service: Deactivated successfully. Jul 21 12:40:44.082000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@315-4277-172.31.16.165:22-144.225.8.54:44202 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:44.150768 systemd[1]: Started sshd@316-4278-172.31.16.165:22-144.225.8.54:44214.service - OpenSSH per-connection server daemon (144.225.8.54:44214). Jul 21 12:40:44.151000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@316-4278-172.31.16.165:22-144.225.8.54:44214 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:44.403244 sshd[9039]: Invalid user debian from 144.225.8.54 port 44214 Jul 21 12:40:44.463142 sshd[9039]: Connection closed by invalid user debian 144.225.8.54 port 44214 [preauth] Jul 21 12:40:44.463000 audit[9039]: AUDIT1109 pid=9039 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:44.467313 systemd[1]: sshd@316-4278-172.31.16.165:22-144.225.8.54:44214.service: Deactivated successfully. Jul 21 12:40:44.467000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@316-4278-172.31.16.165:22-144.225.8.54:44214 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:44.537000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@317-4279-172.31.16.165:22-144.225.8.54:44220 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:44.545435 kernel: kauditd_printk_skb: 29 callbacks suppressed Jul 21 12:40:44.537789 systemd[1]: Started sshd@317-4279-172.31.16.165:22-144.225.8.54:44220.service - OpenSSH per-connection server daemon (144.225.8.54:44220). Jul 21 12:40:44.545641 kernel: audit: type=1130 audit(1784637644.537:1808): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@317-4279-172.31.16.165:22-144.225.8.54:44220 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:44.790060 sshd[9045]: Invalid user debian from 144.225.8.54 port 44220 Jul 21 12:40:44.850313 sshd[9045]: Connection closed by invalid user debian 144.225.8.54 port 44220 [preauth] Jul 21 12:40:44.849000 audit[9045]: AUDIT1109 pid=9045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:44.854774 systemd[1]: sshd@317-4279-172.31.16.165:22-144.225.8.54:44220.service: Deactivated successfully. Jul 21 12:40:44.854000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@317-4279-172.31.16.165:22-144.225.8.54:44220 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:44.860915 kernel: audit: type=1109 audit(1784637644.849:1809): pid=9045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:44.861158 kernel: audit: type=1131 audit(1784637644.854:1810): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@317-4279-172.31.16.165:22-144.225.8.54:44220 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:44.926000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@318-4280-172.31.16.165:22-144.225.8.54:44224 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:44.925904 systemd[1]: Started sshd@318-4280-172.31.16.165:22-144.225.8.54:44224.service - OpenSSH per-connection server daemon (144.225.8.54:44224). Jul 21 12:40:44.937250 kernel: audit: type=1130 audit(1784637644.926:1811): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@318-4280-172.31.16.165:22-144.225.8.54:44224 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:45.177749 sshd[9051]: Invalid user debian from 144.225.8.54 port 44224 Jul 21 12:40:45.237978 sshd[9051]: Connection closed by invalid user debian 144.225.8.54 port 44224 [preauth] Jul 21 12:40:45.238000 audit[9051]: AUDIT1109 pid=9051 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:45.247283 kernel: audit: type=1109 audit(1784637645.238:1812): pid=9051 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:45.250380 systemd[1]: sshd@318-4280-172.31.16.165:22-144.225.8.54:44224.service: Deactivated successfully. Jul 21 12:40:45.252000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@318-4280-172.31.16.165:22-144.225.8.54:44224 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:45.262238 kernel: audit: type=1131 audit(1784637645.252:1813): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@318-4280-172.31.16.165:22-144.225.8.54:44224 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:45.314821 systemd[1]: Started sshd@319-4281-172.31.16.165:22-144.225.8.54:44240.service - OpenSSH per-connection server daemon (144.225.8.54:44240). Jul 21 12:40:45.313000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@319-4281-172.31.16.165:22-144.225.8.54:44240 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:45.325245 kernel: audit: type=1130 audit(1784637645.313:1814): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@319-4281-172.31.16.165:22-144.225.8.54:44240 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:45.563138 sshd[9057]: Invalid user debian from 144.225.8.54 port 44240 Jul 21 12:40:45.623426 sshd[9057]: Connection closed by invalid user debian 144.225.8.54 port 44240 [preauth] Jul 21 12:40:45.623000 audit[9057]: AUDIT1109 pid=9057 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:45.628141 systemd[1]: sshd@319-4281-172.31.16.165:22-144.225.8.54:44240.service: Deactivated successfully. Jul 21 12:40:45.627000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@319-4281-172.31.16.165:22-144.225.8.54:44240 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:45.634409 kernel: audit: type=1109 audit(1784637645.623:1815): pid=9057 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:45.634524 kernel: audit: type=1131 audit(1784637645.627:1816): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@319-4281-172.31.16.165:22-144.225.8.54:44240 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:45.698000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@320-136-172.31.16.165:22-144.225.8.54:44242 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:45.699780 systemd[1]: Started sshd@320-136-172.31.16.165:22-144.225.8.54:44242.service - OpenSSH per-connection server daemon (144.225.8.54:44242). Jul 21 12:40:45.710365 kernel: audit: type=1130 audit(1784637645.698:1817): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@320-136-172.31.16.165:22-144.225.8.54:44242 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:45.950675 sshd[9063]: Invalid user debian from 144.225.8.54 port 44242 Jul 21 12:40:46.010073 sshd[9063]: Connection closed by invalid user debian 144.225.8.54 port 44242 [preauth] Jul 21 12:40:46.010000 audit[9063]: AUDIT1109 pid=9063 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:46.015031 systemd[1]: sshd@320-136-172.31.16.165:22-144.225.8.54:44242.service: Deactivated successfully. Jul 21 12:40:46.016000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@320-136-172.31.16.165:22-144.225.8.54:44242 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:46.088044 systemd[1]: Started sshd@321-4282-172.31.16.165:22-144.225.8.54:44252.service - OpenSSH per-connection server daemon (144.225.8.54:44252). Jul 21 12:40:46.089000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@321-4282-172.31.16.165:22-144.225.8.54:44252 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:46.342226 sshd[9069]: Invalid user debian from 144.225.8.54 port 44252 Jul 21 12:40:46.402865 sshd[9069]: Connection closed by invalid user debian 144.225.8.54 port 44252 [preauth] Jul 21 12:40:46.402000 audit[9069]: AUDIT1109 pid=9069 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:46.407269 systemd[1]: sshd@321-4282-172.31.16.165:22-144.225.8.54:44252.service: Deactivated successfully. Jul 21 12:40:46.406000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@321-4282-172.31.16.165:22-144.225.8.54:44252 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:46.475000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@322-4283-172.31.16.165:22-144.225.8.54:44264 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:46.476710 systemd[1]: Started sshd@322-4283-172.31.16.165:22-144.225.8.54:44264.service - OpenSSH per-connection server daemon (144.225.8.54:44264). Jul 21 12:40:46.721381 sshd[9075]: Invalid user debian from 144.225.8.54 port 44264 Jul 21 12:40:46.781270 sshd[9075]: Connection closed by invalid user debian 144.225.8.54 port 44264 [preauth] Jul 21 12:40:46.780000 audit[9075]: AUDIT1109 pid=9075 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:46.786301 systemd[1]: sshd@322-4283-172.31.16.165:22-144.225.8.54:44264.service: Deactivated successfully. Jul 21 12:40:46.786000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@322-4283-172.31.16.165:22-144.225.8.54:44264 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:46.856841 systemd[1]: Started sshd@323-137-172.31.16.165:22-144.225.8.54:44278.service - OpenSSH per-connection server daemon (144.225.8.54:44278). Jul 21 12:40:46.857000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@323-137-172.31.16.165:22-144.225.8.54:44278 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:47.102454 sshd[9081]: Invalid user debian from 144.225.8.54 port 44278 Jul 21 12:40:47.163281 sshd[9081]: Connection closed by invalid user debian 144.225.8.54 port 44278 [preauth] Jul 21 12:40:47.162000 audit[9081]: AUDIT1109 pid=9081 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:47.166662 systemd[1]: sshd@323-137-172.31.16.165:22-144.225.8.54:44278.service: Deactivated successfully. Jul 21 12:40:47.166000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@323-137-172.31.16.165:22-144.225.8.54:44278 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:47.238000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@324-138-172.31.16.165:22-144.225.8.54:44288 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:47.239316 systemd[1]: Started sshd@324-138-172.31.16.165:22-144.225.8.54:44288.service - OpenSSH per-connection server daemon (144.225.8.54:44288). Jul 21 12:40:47.489696 sshd[9087]: Invalid user debian from 144.225.8.54 port 44288 Jul 21 12:40:47.549077 sshd[9087]: Connection closed by invalid user debian 144.225.8.54 port 44288 [preauth] Jul 21 12:40:47.548000 audit[9087]: AUDIT1109 pid=9087 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:47.553165 systemd[1]: sshd@324-138-172.31.16.165:22-144.225.8.54:44288.service: Deactivated successfully. Jul 21 12:40:47.554000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@324-138-172.31.16.165:22-144.225.8.54:44288 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:47.623781 systemd[1]: Started sshd@325-139-172.31.16.165:22-144.225.8.54:44302.service - OpenSSH per-connection server daemon (144.225.8.54:44302). Jul 21 12:40:47.622000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@325-139-172.31.16.165:22-144.225.8.54:44302 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:47.865424 sshd[9093]: Invalid user debian from 144.225.8.54 port 44302 Jul 21 12:40:47.926252 sshd[9093]: Connection closed by invalid user debian 144.225.8.54 port 44302 [preauth] Jul 21 12:40:47.925000 audit[9093]: AUDIT1109 pid=9093 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:47.930038 systemd[1]: sshd@325-139-172.31.16.165:22-144.225.8.54:44302.service: Deactivated successfully. Jul 21 12:40:47.931000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@325-139-172.31.16.165:22-144.225.8.54:44302 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:48.001000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@326-140-172.31.16.165:22-144.225.8.54:46144 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:48.001787 systemd[1]: Started sshd@326-140-172.31.16.165:22-144.225.8.54:46144.service - OpenSSH per-connection server daemon (144.225.8.54:46144). Jul 21 12:40:48.243696 sshd[9099]: Invalid user debian from 144.225.8.54 port 46144 Jul 21 12:40:48.305317 sshd[9099]: Connection closed by invalid user debian 144.225.8.54 port 46144 [preauth] Jul 21 12:40:48.304000 audit[9099]: AUDIT1109 pid=9099 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:48.309172 systemd[1]: sshd@326-140-172.31.16.165:22-144.225.8.54:46144.service: Deactivated successfully. Jul 21 12:40:48.310000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@326-140-172.31.16.165:22-144.225.8.54:46144 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:48.380000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@327-4284-172.31.16.165:22-144.225.8.54:46150 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:48.381446 systemd[1]: Started sshd@327-4284-172.31.16.165:22-144.225.8.54:46150.service - OpenSSH per-connection server daemon (144.225.8.54:46150). Jul 21 12:40:48.630148 sshd[9105]: Invalid user debian from 144.225.8.54 port 46150 Jul 21 12:40:48.692268 sshd[9105]: Connection closed by invalid user debian 144.225.8.54 port 46150 [preauth] Jul 21 12:40:48.691000 audit[9105]: AUDIT1109 pid=9105 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:48.695950 systemd[1]: sshd@327-4284-172.31.16.165:22-144.225.8.54:46150.service: Deactivated successfully. Jul 21 12:40:48.695000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@327-4284-172.31.16.165:22-144.225.8.54:46150 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:48.770000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@328-4285-172.31.16.165:22-144.225.8.54:46152 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:48.771575 systemd[1]: Started sshd@328-4285-172.31.16.165:22-144.225.8.54:46152.service - OpenSSH per-connection server daemon (144.225.8.54:46152). Jul 21 12:40:49.020738 sshd[9111]: Invalid user debian from 144.225.8.54 port 46152 Jul 21 12:40:49.082617 sshd[9111]: Connection closed by invalid user debian 144.225.8.54 port 46152 [preauth] Jul 21 12:40:49.081000 audit[9111]: AUDIT1109 pid=9111 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:49.088091 systemd[1]: sshd@328-4285-172.31.16.165:22-144.225.8.54:46152.service: Deactivated successfully. Jul 21 12:40:49.089000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@328-4285-172.31.16.165:22-144.225.8.54:46152 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:49.157000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@329-141-172.31.16.165:22-144.225.8.54:46160 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:49.158785 systemd[1]: Started sshd@329-141-172.31.16.165:22-144.225.8.54:46160.service - OpenSSH per-connection server daemon (144.225.8.54:46160). Jul 21 12:40:49.407988 sshd[9117]: Invalid user debian from 144.225.8.54 port 46160 Jul 21 12:40:49.469397 sshd[9117]: Connection closed by invalid user debian 144.225.8.54 port 46160 [preauth] Jul 21 12:40:49.469000 audit[9117]: AUDIT1109 pid=9117 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:49.473364 systemd[1]: sshd@329-141-172.31.16.165:22-144.225.8.54:46160.service: Deactivated successfully. Jul 21 12:40:49.474000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@329-141-172.31.16.165:22-144.225.8.54:46160 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:49.543000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@330-142-172.31.16.165:22-144.225.8.54:46168 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:49.552471 kernel: kauditd_printk_skb: 29 callbacks suppressed Jul 21 12:40:49.544418 systemd[1]: Started sshd@330-142-172.31.16.165:22-144.225.8.54:46168.service - OpenSSH per-connection server daemon (144.225.8.54:46168). Jul 21 12:40:49.552657 kernel: audit: type=1130 audit(1784637649.543:1847): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@330-142-172.31.16.165:22-144.225.8.54:46168 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:49.797600 sshd[9123]: Invalid user debian from 144.225.8.54 port 46168 Jul 21 12:40:49.858797 sshd[9123]: Connection closed by invalid user debian 144.225.8.54 port 46168 [preauth] Jul 21 12:40:49.858000 audit[9123]: AUDIT1109 pid=9123 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:49.866166 systemd[1]: sshd@330-142-172.31.16.165:22-144.225.8.54:46168.service: Deactivated successfully. Jul 21 12:40:49.866492 kernel: audit: type=1109 audit(1784637649.858:1848): pid=9123 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:49.866000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@330-142-172.31.16.165:22-144.225.8.54:46168 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:49.873428 kernel: audit: type=1131 audit(1784637649.866:1849): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@330-142-172.31.16.165:22-144.225.8.54:46168 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:49.933822 systemd[1]: Started sshd@331-143-172.31.16.165:22-144.225.8.54:46172.service - OpenSSH per-connection server daemon (144.225.8.54:46172). Jul 21 12:40:49.932000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@331-143-172.31.16.165:22-144.225.8.54:46172 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:49.945459 kernel: audit: type=1130 audit(1784637649.932:1850): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@331-143-172.31.16.165:22-144.225.8.54:46172 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:50.186193 sshd[9129]: Invalid user debian from 144.225.8.54 port 46172 Jul 21 12:40:50.246877 sshd[9129]: Connection closed by invalid user debian 144.225.8.54 port 46172 [preauth] Jul 21 12:40:50.246000 audit[9129]: AUDIT1109 pid=9129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:50.253251 kernel: audit: type=1109 audit(1784637650.246:1851): pid=9129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:50.255527 systemd[1]: sshd@331-143-172.31.16.165:22-144.225.8.54:46172.service: Deactivated successfully. Jul 21 12:40:50.254000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@331-143-172.31.16.165:22-144.225.8.54:46172 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:50.261561 kernel: audit: type=1131 audit(1784637650.254:1852): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@331-143-172.31.16.165:22-144.225.8.54:46172 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:50.323000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@332-144-172.31.16.165:22-144.225.8.54:46174 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:50.324785 systemd[1]: Started sshd@332-144-172.31.16.165:22-144.225.8.54:46174.service - OpenSSH per-connection server daemon (144.225.8.54:46174). Jul 21 12:40:50.333323 kernel: audit: type=1130 audit(1784637650.323:1853): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@332-144-172.31.16.165:22-144.225.8.54:46174 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:50.576822 sshd[9135]: Invalid user debian from 144.225.8.54 port 46174 Jul 21 12:40:50.638398 sshd[9135]: Connection closed by invalid user debian 144.225.8.54 port 46174 [preauth] Jul 21 12:40:50.637000 audit[9135]: AUDIT1109 pid=9135 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:50.644536 systemd[1]: sshd@332-144-172.31.16.165:22-144.225.8.54:46174.service: Deactivated successfully. Jul 21 12:40:50.643000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@332-144-172.31.16.165:22-144.225.8.54:46174 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:50.650183 kernel: audit: type=1109 audit(1784637650.637:1854): pid=9135 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:50.650789 kernel: audit: type=1131 audit(1784637650.643:1855): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@332-144-172.31.16.165:22-144.225.8.54:46174 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:50.715808 systemd[1]: Started sshd@333-145-172.31.16.165:22-144.225.8.54:46180.service - OpenSSH per-connection server daemon (144.225.8.54:46180). Jul 21 12:40:50.714000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@333-145-172.31.16.165:22-144.225.8.54:46180 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:50.726290 kernel: audit: type=1130 audit(1784637650.714:1856): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@333-145-172.31.16.165:22-144.225.8.54:46180 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:50.967503 sshd[9141]: Invalid user debian from 144.225.8.54 port 46180 Jul 21 12:40:51.027249 sshd[9141]: Connection closed by invalid user debian 144.225.8.54 port 46180 [preauth] Jul 21 12:40:51.026000 audit[9141]: AUDIT1109 pid=9141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:51.031583 systemd[1]: sshd@333-145-172.31.16.165:22-144.225.8.54:46180.service: Deactivated successfully. Jul 21 12:40:51.032000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@333-145-172.31.16.165:22-144.225.8.54:46180 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:51.104185 systemd[1]: Started sshd@334-146-172.31.16.165:22-144.225.8.54:46188.service - OpenSSH per-connection server daemon (144.225.8.54:46188). Jul 21 12:40:51.103000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@334-146-172.31.16.165:22-144.225.8.54:46188 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:51.351285 sshd[9147]: Invalid user debian from 144.225.8.54 port 46188 Jul 21 12:40:51.412651 sshd[9147]: Connection closed by invalid user debian 144.225.8.54 port 46188 [preauth] Jul 21 12:40:51.412000 audit[9147]: AUDIT1109 pid=9147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:51.416962 systemd[1]: sshd@334-146-172.31.16.165:22-144.225.8.54:46188.service: Deactivated successfully. Jul 21 12:40:51.418000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@334-146-172.31.16.165:22-144.225.8.54:46188 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:51.487000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@335-4286-172.31.16.165:22-144.225.8.54:46200 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:51.488237 systemd[1]: Started sshd@335-4286-172.31.16.165:22-144.225.8.54:46200.service - OpenSSH per-connection server daemon (144.225.8.54:46200). Jul 21 12:40:51.743962 sshd[9153]: Invalid user debian from 144.225.8.54 port 46200 Jul 21 12:40:51.804436 sshd[9153]: Connection closed by invalid user debian 144.225.8.54 port 46200 [preauth] Jul 21 12:40:51.804000 audit[9153]: AUDIT1109 pid=9153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:51.808422 systemd[1]: sshd@335-4286-172.31.16.165:22-144.225.8.54:46200.service: Deactivated successfully. Jul 21 12:40:51.808000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@335-4286-172.31.16.165:22-144.225.8.54:46200 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:51.882000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@336-4287-172.31.16.165:22-144.225.8.54:46206 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:51.881594 systemd[1]: Started sshd@336-4287-172.31.16.165:22-144.225.8.54:46206.service - OpenSSH per-connection server daemon (144.225.8.54:46206). Jul 21 12:40:52.127518 sshd[9159]: Invalid user debian from 144.225.8.54 port 46206 Jul 21 12:40:52.187890 sshd[9159]: Connection closed by invalid user debian 144.225.8.54 port 46206 [preauth] Jul 21 12:40:52.188000 audit[9159]: AUDIT1109 pid=9159 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:52.193267 systemd[1]: sshd@336-4287-172.31.16.165:22-144.225.8.54:46206.service: Deactivated successfully. Jul 21 12:40:52.192000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@336-4287-172.31.16.165:22-144.225.8.54:46206 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:52.225508 systemd[1]: cri-containerd-a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2.scope: Deactivated successfully. Jul 21 12:40:52.226251 systemd[1]: cri-containerd-a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2.scope: Consumed 5.877s CPU time over 2min 57.693s wall clock time, 66.9M memory peak. Jul 21 12:40:52.229000 audit: BPF prog-id=88 op=UNLOAD Jul 21 12:40:52.229000 audit: BPF prog-id=90 op=UNLOAD Jul 21 12:40:52.239073 containerd[2389]: time="2026-07-21T12:40:52.239005905Z" level=info msg="received container exit event container_id:\"a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2\" id:\"a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2\" pid:3573 exit_status:1 exited_at:{seconds:1784637652 nanos:233371353}" Jul 21 12:40:52.272000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@337-4288-172.31.16.165:22-144.225.8.54:46216 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:52.273700 systemd[1]: Started sshd@337-4288-172.31.16.165:22-144.225.8.54:46216.service - OpenSSH per-connection server daemon (144.225.8.54:46216). Jul 21 12:40:52.338251 systemd[1]: run-containerd-io.containerd.runtime.v2.task-k8s.io-a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2-rootfs.mount: Deactivated successfully. Jul 21 12:40:52.373581 systemd[1]: cri-containerd-524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe.scope: Deactivated successfully. Jul 21 12:40:52.375463 systemd[1]: cri-containerd-524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe.scope: Consumed 42.057s CPU time over 2min 40.663s wall clock time, 154.8M memory peak. Jul 21 12:40:52.376000 audit: BPF prog-id=128 op=UNLOAD Jul 21 12:40:52.376000 audit: BPF prog-id=132 op=UNLOAD Jul 21 12:40:52.386587 containerd[2389]: time="2026-07-21T12:40:52.386445106Z" level=info msg="received container exit event container_id:\"524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe\" id:\"524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe\" pid:4328 exit_status:1 exited_at:{seconds:1784637652 nanos:382471210}" Jul 21 12:40:52.454953 systemd[1]: run-containerd-io.containerd.runtime.v2.task-k8s.io-524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe-rootfs.mount: Deactivated successfully. Jul 21 12:40:52.601914 sshd[9190]: Invalid user debian from 144.225.8.54 port 46216 Jul 21 12:40:52.663345 sshd[9190]: Connection closed by invalid user debian 144.225.8.54 port 46216 [preauth] Jul 21 12:40:52.662000 audit[9190]: AUDIT1109 pid=9190 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:52.666934 systemd[1]: sshd@337-4288-172.31.16.165:22-144.225.8.54:46216.service: Deactivated successfully. Jul 21 12:40:52.666000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@337-4288-172.31.16.165:22-144.225.8.54:46216 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:52.738781 systemd[1]: Started sshd@338-147-172.31.16.165:22-144.225.8.54:46218.service - OpenSSH per-connection server daemon (144.225.8.54:46218). Jul 21 12:40:52.737000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@338-147-172.31.16.165:22-144.225.8.54:46218 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:52.763341 kubelet[4002]: I0721 12:40:52.763303 4002 scope.go:117] "RemoveContainer" containerID="a18242420716cd26e2ab64414137066a07e8bc1700933b1849b4c50e142811e2" Jul 21 12:40:52.774662 kubelet[4002]: I0721 12:40:52.774057 4002 scope.go:117] "RemoveContainer" containerID="524f6a3fca781fe9b9a766e1f908fec9ced5281711c05c0c3122dab5b9dcefbe" Jul 21 12:40:52.774982 containerd[2389]: time="2026-07-21T12:40:52.774527256Z" level=info msg="CreateContainer within sandbox \"c47a2792930df7d58fff0c1a69e873eae6b010cebad9550a9ef1d17464530fdb\" for container name:\"kube-controller-manager\" attempt:1" Jul 21 12:40:52.783256 containerd[2389]: time="2026-07-21T12:40:52.782432088Z" level=info msg="CreateContainer within sandbox \"b208cb9d0711e1f2a03ff644c8d838eaeccf8baba3b4289fbf7b49452b21150a\" for container name:\"tigera-operator\" attempt:1" Jul 21 12:40:52.816791 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount972955029.mount: Deactivated successfully. Jul 21 12:40:52.852250 containerd[2389]: time="2026-07-21T12:40:52.851519808Z" level=info msg="CreateContainer within sandbox \"c47a2792930df7d58fff0c1a69e873eae6b010cebad9550a9ef1d17464530fdb\" for name:\"kube-controller-manager\" attempt:1 returns container id \"f4b1ef7bff2d9fc021ca6bd304de65149b23127409a4d60213d93d3ce9714e6e\"" Jul 21 12:40:52.852599 containerd[2389]: time="2026-07-21T12:40:52.852366924Z" level=info msg="StartContainer for \"f4b1ef7bff2d9fc021ca6bd304de65149b23127409a4d60213d93d3ce9714e6e\"" Jul 21 12:40:52.857907 containerd[2389]: time="2026-07-21T12:40:52.856837884Z" level=info msg="connecting to shim f4b1ef7bff2d9fc021ca6bd304de65149b23127409a4d60213d93d3ce9714e6e" address="unix:///run/containerd/s/b98a369f226ce3c41f6b280c8ef4a54361202d0dcef2a06492b2237f109c598b" protocol=ttrpc version=3 Jul 21 12:40:52.865679 containerd[2389]: time="2026-07-21T12:40:52.865560576Z" level=info msg="CreateContainer within sandbox \"b208cb9d0711e1f2a03ff644c8d838eaeccf8baba3b4289fbf7b49452b21150a\" for name:\"tigera-operator\" attempt:1 returns container id \"1ee91173bab18c3afa3b1c998921ebaa32cac0a42223f858155b09246ff7e129\"" Jul 21 12:40:52.866805 containerd[2389]: time="2026-07-21T12:40:52.866739732Z" level=info msg="StartContainer for \"1ee91173bab18c3afa3b1c998921ebaa32cac0a42223f858155b09246ff7e129\"" Jul 21 12:40:52.870731 containerd[2389]: time="2026-07-21T12:40:52.870675204Z" level=info msg="connecting to shim 1ee91173bab18c3afa3b1c998921ebaa32cac0a42223f858155b09246ff7e129" address="unix:///run/containerd/s/f6f8fbb44c7afa9f7bcbdf432bdcf5ef88e817f0958122465f64be11ade24d21" protocol=ttrpc version=3 Jul 21 12:40:52.905724 systemd[1]: Started cri-containerd-f4b1ef7bff2d9fc021ca6bd304de65149b23127409a4d60213d93d3ce9714e6e.scope - libcontainer container f4b1ef7bff2d9fc021ca6bd304de65149b23127409a4d60213d93d3ce9714e6e. Jul 21 12:40:52.940403 systemd[1]: Started cri-containerd-1ee91173bab18c3afa3b1c998921ebaa32cac0a42223f858155b09246ff7e129.scope - libcontainer container 1ee91173bab18c3afa3b1c998921ebaa32cac0a42223f858155b09246ff7e129. Jul 21 12:40:52.962000 audit: BPF prog-id=284 op=LOAD Jul 21 12:40:52.965000 audit: BPF prog-id=285 op=LOAD Jul 21 12:40:52.965000 audit[9221]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=53cba639bf90 a2=98 a3=0 items=0 ppid=3439 pid=9221 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.965000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6634623165663762666632643966633032316361366264333034646536 Jul 21 12:40:52.965000 audit: BPF prog-id=285 op=UNLOAD Jul 21 12:40:52.965000 audit[9221]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=3439 pid=9221 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.965000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6634623165663762666632643966633032316361366264333034646536 Jul 21 12:40:52.966000 audit: BPF prog-id=286 op=LOAD Jul 21 12:40:52.966000 audit[9221]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=53cba639c268 a2=98 a3=0 items=0 ppid=3439 pid=9221 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.966000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6634623165663762666632643966633032316361366264333034646536 Jul 21 12:40:52.967000 audit: BPF prog-id=287 op=LOAD Jul 21 12:40:52.967000 audit[9221]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=53cba639bfa8 a2=98 a3=0 items=0 ppid=3439 pid=9221 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.967000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6634623165663762666632643966633032316361366264333034646536 Jul 21 12:40:52.968000 audit: BPF prog-id=287 op=UNLOAD Jul 21 12:40:52.968000 audit[9221]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=3439 pid=9221 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.968000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6634623165663762666632643966633032316361366264333034646536 Jul 21 12:40:52.968000 audit: BPF prog-id=286 op=UNLOAD Jul 21 12:40:52.968000 audit[9221]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=3439 pid=9221 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.968000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6634623165663762666632643966633032316361366264333034646536 Jul 21 12:40:52.969000 audit: BPF prog-id=288 op=LOAD Jul 21 12:40:52.969000 audit[9221]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=53cba639c4b8 a2=98 a3=0 items=0 ppid=3439 pid=9221 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.969000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6634623165663762666632643966633032316361366264333034646536 Jul 21 12:40:52.989000 audit: BPF prog-id=289 op=LOAD Jul 21 12:40:52.991000 audit: BPF prog-id=290 op=LOAD Jul 21 12:40:52.991000 audit[9232]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=649a0b79ff90 a2=98 a3=0 items=0 ppid=4106 pid=9232 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.991000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3165653931313733626162313863336166613362316339393839323165 Jul 21 12:40:52.991000 audit: BPF prog-id=290 op=UNLOAD Jul 21 12:40:52.991000 audit[9232]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=4106 pid=9232 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.991000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3165653931313733626162313863336166613362316339393839323165 Jul 21 12:40:52.991000 audit: BPF prog-id=291 op=LOAD Jul 21 12:40:52.991000 audit[9232]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=649a0b7a0268 a2=98 a3=0 items=0 ppid=4106 pid=9232 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.991000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3165653931313733626162313863336166613362316339393839323165 Jul 21 12:40:52.992000 audit: BPF prog-id=292 op=LOAD Jul 21 12:40:52.992000 audit[9232]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=649a0b79ffa8 a2=98 a3=0 items=0 ppid=4106 pid=9232 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.992000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3165653931313733626162313863336166613362316339393839323165 Jul 21 12:40:52.993000 audit: BPF prog-id=292 op=UNLOAD Jul 21 12:40:52.993000 audit[9232]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=4106 pid=9232 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.993000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3165653931313733626162313863336166613362316339393839323165 Jul 21 12:40:52.993000 audit: BPF prog-id=291 op=UNLOAD Jul 21 12:40:52.993000 audit[9232]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=4106 pid=9232 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.993000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3165653931313733626162313863336166613362316339393839323165 Jul 21 12:40:52.993000 audit: BPF prog-id=293 op=LOAD Jul 21 12:40:52.993000 audit[9232]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=649a0b7a04b8 a2=98 a3=0 items=0 ppid=4106 pid=9232 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:52.993000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F3165653931313733626162313863336166613362316339393839323165 Jul 21 12:40:53.016930 sshd[9218]: Invalid user debian from 144.225.8.54 port 46218 Jul 21 12:40:53.061511 containerd[2389]: time="2026-07-21T12:40:53.061445649Z" level=info msg="StartContainer for \"f4b1ef7bff2d9fc021ca6bd304de65149b23127409a4d60213d93d3ce9714e6e\" returns successfully" Jul 21 12:40:53.070757 containerd[2389]: time="2026-07-21T12:40:53.070694865Z" level=info msg="StartContainer for \"1ee91173bab18c3afa3b1c998921ebaa32cac0a42223f858155b09246ff7e129\" returns successfully" Jul 21 12:40:53.079331 sshd[9218]: Connection closed by invalid user debian 144.225.8.54 port 46218 [preauth] Jul 21 12:40:53.078000 audit[9218]: AUDIT1109 pid=9218 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:53.084658 systemd[1]: sshd@338-147-172.31.16.165:22-144.225.8.54:46218.service: Deactivated successfully. Jul 21 12:40:53.085000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@338-147-172.31.16.165:22-144.225.8.54:46218 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:53.161000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@339-148-172.31.16.165:22-144.225.8.54:46222 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:53.162452 systemd[1]: Started sshd@339-148-172.31.16.165:22-144.225.8.54:46222.service - OpenSSH per-connection server daemon (144.225.8.54:46222). Jul 21 12:40:53.334905 systemd[1]: var-lib-containerd-tmpmounts-containerd\x2dmount2663468567.mount: Deactivated successfully. Jul 21 12:40:53.434041 sshd[9281]: Invalid user debian from 144.225.8.54 port 46222 Jul 21 12:40:53.495049 sshd[9281]: Connection closed by invalid user debian 144.225.8.54 port 46222 [preauth] Jul 21 12:40:53.494000 audit[9281]: AUDIT1109 pid=9281 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:53.499047 systemd[1]: sshd@339-148-172.31.16.165:22-144.225.8.54:46222.service: Deactivated successfully. Jul 21 12:40:53.499000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@339-148-172.31.16.165:22-144.225.8.54:46222 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:53.571000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@340-149-172.31.16.165:22-144.225.8.54:46236 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:53.572059 systemd[1]: Started sshd@340-149-172.31.16.165:22-144.225.8.54:46236.service - OpenSSH per-connection server daemon (144.225.8.54:46236). Jul 21 12:40:53.851533 sshd[9299]: Invalid user debian from 144.225.8.54 port 46236 Jul 21 12:40:53.915011 sshd[9299]: Connection closed by invalid user debian 144.225.8.54 port 46236 [preauth] Jul 21 12:40:53.914000 audit[9299]: AUDIT1109 pid=9299 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:53.920283 systemd[1]: sshd@340-149-172.31.16.165:22-144.225.8.54:46236.service: Deactivated successfully. Jul 21 12:40:53.920000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@340-149-172.31.16.165:22-144.225.8.54:46236 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:53.991730 systemd[1]: Started sshd@341-4289-172.31.16.165:22-144.225.8.54:46244.service - OpenSSH per-connection server daemon (144.225.8.54:46244). Jul 21 12:40:53.990000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@341-4289-172.31.16.165:22-144.225.8.54:46244 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:54.253306 sshd[9305]: Invalid user debian from 144.225.8.54 port 46244 Jul 21 12:40:54.311486 sshd[9305]: Connection closed by invalid user debian 144.225.8.54 port 46244 [preauth] Jul 21 12:40:54.310000 audit[9305]: AUDIT1109 pid=9305 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:54.314690 systemd[1]: sshd@341-4289-172.31.16.165:22-144.225.8.54:46244.service: Deactivated successfully. Jul 21 12:40:54.315000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@341-4289-172.31.16.165:22-144.225.8.54:46244 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:54.388000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@342-150-172.31.16.165:22-144.225.8.54:46250 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:54.389730 systemd[1]: Started sshd@342-150-172.31.16.165:22-144.225.8.54:46250.service - OpenSSH per-connection server daemon (144.225.8.54:46250). Jul 21 12:40:54.652613 sshd[9311]: Invalid user debian from 144.225.8.54 port 46250 Jul 21 12:40:54.714286 sshd[9311]: Connection closed by invalid user debian 144.225.8.54 port 46250 [preauth] Jul 21 12:40:54.713000 audit[9311]: AUDIT1109 pid=9311 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:54.716252 kernel: kauditd_printk_skb: 75 callbacks suppressed Jul 21 12:40:54.716365 kernel: audit: type=1109 audit(1784637654.713:1904): pid=9311 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:54.721674 systemd[1]: sshd@342-150-172.31.16.165:22-144.225.8.54:46250.service: Deactivated successfully. Jul 21 12:40:54.720000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@342-150-172.31.16.165:22-144.225.8.54:46250 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:54.727979 kernel: audit: type=1131 audit(1784637654.720:1905): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@342-150-172.31.16.165:22-144.225.8.54:46250 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:54.787727 systemd[1]: Started sshd@343-151-172.31.16.165:22-144.225.8.54:46262.service - OpenSSH per-connection server daemon (144.225.8.54:46262). Jul 21 12:40:54.786000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@343-151-172.31.16.165:22-144.225.8.54:46262 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:54.797336 kernel: audit: type=1130 audit(1784637654.786:1906): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@343-151-172.31.16.165:22-144.225.8.54:46262 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.038145 sshd[9318]: Invalid user debian from 144.225.8.54 port 46262 Jul 21 12:40:55.099096 sshd[9318]: Connection closed by invalid user debian 144.225.8.54 port 46262 [preauth] Jul 21 12:40:55.098000 audit[9318]: AUDIT1109 pid=9318 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:55.102741 systemd[1]: sshd@343-151-172.31.16.165:22-144.225.8.54:46262.service: Deactivated successfully. Jul 21 12:40:55.103000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@343-151-172.31.16.165:22-144.225.8.54:46262 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.110596 kernel: audit: type=1109 audit(1784637655.098:1907): pid=9318 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:55.110648 kernel: audit: type=1131 audit(1784637655.103:1908): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@343-151-172.31.16.165:22-144.225.8.54:46262 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.173748 systemd[1]: Started sshd@344-152-172.31.16.165:22-144.225.8.54:46264.service - OpenSSH per-connection server daemon (144.225.8.54:46264). Jul 21 12:40:55.172000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@344-152-172.31.16.165:22-144.225.8.54:46264 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.185266 kernel: audit: type=1130 audit(1784637655.172:1909): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@344-152-172.31.16.165:22-144.225.8.54:46264 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.444509 sshd[9324]: Invalid user debian from 144.225.8.54 port 46264 Jul 21 12:40:55.504000 audit[9324]: AUDIT1109 pid=9324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:55.506233 sshd[9324]: Connection closed by invalid user debian 144.225.8.54 port 46264 [preauth] Jul 21 12:40:55.510923 systemd[1]: sshd@344-152-172.31.16.165:22-144.225.8.54:46264.service: Deactivated successfully. Jul 21 12:40:55.511250 kernel: audit: type=1109 audit(1784637655.504:1910): pid=9324 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:55.510000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@344-152-172.31.16.165:22-144.225.8.54:46264 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.520399 kernel: audit: type=1131 audit(1784637655.510:1911): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@344-152-172.31.16.165:22-144.225.8.54:46264 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.578784 systemd[1]: Started sshd@345-153-172.31.16.165:22-144.225.8.54:46268.service - OpenSSH per-connection server daemon (144.225.8.54:46268). Jul 21 12:40:55.577000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@345-153-172.31.16.165:22-144.225.8.54:46268 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.589254 kernel: audit: type=1130 audit(1784637655.577:1912): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@345-153-172.31.16.165:22-144.225.8.54:46268 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.828757 sshd[9330]: Invalid user debian from 144.225.8.54 port 46268 Jul 21 12:40:55.889571 sshd[9330]: Connection closed by invalid user debian 144.225.8.54 port 46268 [preauth] Jul 21 12:40:55.891000 audit[9330]: AUDIT1109 pid=9330 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:55.899586 systemd[1]: sshd@345-153-172.31.16.165:22-144.225.8.54:46268.service: Deactivated successfully. Jul 21 12:40:55.899000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@345-153-172.31.16.165:22-144.225.8.54:46268 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.908298 kernel: audit: type=1109 audit(1784637655.891:1913): pid=9330 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:55.965000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@346-154-172.31.16.165:22-144.225.8.54:46272 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:55.966767 systemd[1]: Started sshd@346-154-172.31.16.165:22-144.225.8.54:46272.service - OpenSSH per-connection server daemon (144.225.8.54:46272). Jul 21 12:40:56.215914 sshd[9361]: Invalid user debian from 144.225.8.54 port 46272 Jul 21 12:40:56.276290 sshd[9361]: Connection closed by invalid user debian 144.225.8.54 port 46272 [preauth] Jul 21 12:40:56.277000 audit[9361]: AUDIT1109 pid=9361 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:56.281889 systemd[1]: sshd@346-154-172.31.16.165:22-144.225.8.54:46272.service: Deactivated successfully. Jul 21 12:40:56.281000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@346-154-172.31.16.165:22-144.225.8.54:46272 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:56.351848 systemd[1]: Started sshd@347-155-172.31.16.165:22-144.225.8.54:46276.service - OpenSSH per-connection server daemon (144.225.8.54:46276). Jul 21 12:40:56.350000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@347-155-172.31.16.165:22-144.225.8.54:46276 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:56.594582 sshd[9388]: Invalid user debian from 144.225.8.54 port 46276 Jul 21 12:40:56.655065 sshd[9388]: Connection closed by invalid user debian 144.225.8.54 port 46276 [preauth] Jul 21 12:40:56.654000 audit[9388]: AUDIT1109 pid=9388 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:56.659039 systemd[1]: sshd@347-155-172.31.16.165:22-144.225.8.54:46276.service: Deactivated successfully. Jul 21 12:40:56.658000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@347-155-172.31.16.165:22-144.225.8.54:46276 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:56.730000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@348-156-172.31.16.165:22-144.225.8.54:46286 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:56.731736 systemd[1]: Started sshd@348-156-172.31.16.165:22-144.225.8.54:46286.service - OpenSSH per-connection server daemon (144.225.8.54:46286). Jul 21 12:40:56.977097 sshd[9394]: Invalid user debian from 144.225.8.54 port 46286 Jul 21 12:40:57.037005 sshd[9394]: Connection closed by invalid user debian 144.225.8.54 port 46286 [preauth] Jul 21 12:40:57.036000 audit[9394]: AUDIT1109 pid=9394 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:57.040730 systemd[1]: sshd@348-156-172.31.16.165:22-144.225.8.54:46286.service: Deactivated successfully. Jul 21 12:40:57.042000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@348-156-172.31.16.165:22-144.225.8.54:46286 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:57.065096 systemd[1]: cri-containerd-262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584.scope: Deactivated successfully. Jul 21 12:40:57.067769 systemd[1]: cri-containerd-262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584.scope: Consumed 3.459s CPU time over 3min 2.668s wall clock time, 23.2M memory peak, 64K read from disk. Jul 21 12:40:57.068000 audit: BPF prog-id=78 op=UNLOAD Jul 21 12:40:57.068000 audit: BPF prog-id=92 op=UNLOAD Jul 21 12:40:57.075009 containerd[2389]: time="2026-07-21T12:40:57.074634637Z" level=info msg="received container exit event container_id:\"262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584\" id:\"262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584\" pid:3537 exit_status:1 exited_at:{seconds:1784637657 nanos:74273653}" Jul 21 12:40:57.112000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@349-157-172.31.16.165:22-144.225.8.54:46288 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:57.113636 systemd[1]: Started sshd@349-157-172.31.16.165:22-144.225.8.54:46288.service - OpenSSH per-connection server daemon (144.225.8.54:46288). Jul 21 12:40:57.170897 systemd[1]: run-containerd-io.containerd.runtime.v2.task-k8s.io-262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584-rootfs.mount: Deactivated successfully. Jul 21 12:40:57.208949 kubelet[4002]: E0721 12:40:57.208796 4002 controller.go:195] "Failed to update lease" err="the server was unable to return a response in the time allotted, but may still be processing the request (put leases.coordination.k8s.io ip-172-31-16-165)" Jul 21 12:40:57.377018 sshd[9412]: Invalid user debian from 144.225.8.54 port 46288 Jul 21 12:40:57.438985 sshd[9412]: Connection closed by invalid user debian 144.225.8.54 port 46288 [preauth] Jul 21 12:40:57.438000 audit[9412]: AUDIT1109 pid=9412 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:57.442842 systemd[1]: sshd@349-157-172.31.16.165:22-144.225.8.54:46288.service: Deactivated successfully. Jul 21 12:40:57.442000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@349-157-172.31.16.165:22-144.225.8.54:46288 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:57.515000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@350-158-172.31.16.165:22-144.225.8.54:46298 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:57.516053 systemd[1]: Started sshd@350-158-172.31.16.165:22-144.225.8.54:46298.service - OpenSSH per-connection server daemon (144.225.8.54:46298). Jul 21 12:40:57.760915 sshd[9418]: Invalid user debian from 144.225.8.54 port 46298 Jul 21 12:40:57.821000 audit[9418]: AUDIT1109 pid=9418 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:57.824554 sshd[9418]: Connection closed by invalid user debian 144.225.8.54 port 46298 [preauth] Jul 21 12:40:57.827193 systemd[1]: sshd@350-158-172.31.16.165:22-144.225.8.54:46298.service: Deactivated successfully. Jul 21 12:40:57.828000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@350-158-172.31.16.165:22-144.225.8.54:46298 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:57.838465 kubelet[4002]: I0721 12:40:57.838429 4002 scope.go:117] "RemoveContainer" containerID="262fd1e6aafe897ce69f37b38d131eb7ef20567d7178b8d400fc21623930d584" Jul 21 12:40:57.845223 containerd[2389]: time="2026-07-21T12:40:57.845152973Z" level=info msg="CreateContainer within sandbox \"115c6d35035a0944d448195978ed9700305cc0123ed5f3143cfada96d1fc2e58\" for container name:\"kube-scheduler\" attempt:1" Jul 21 12:40:57.889044 containerd[2389]: time="2026-07-21T12:40:57.888908585Z" level=info msg="CreateContainer within sandbox \"115c6d35035a0944d448195978ed9700305cc0123ed5f3143cfada96d1fc2e58\" for name:\"kube-scheduler\" attempt:1 returns container id \"cd4e60b52210a36adbe72a8369732614d28d223033c3e88669111f598ef51524\"" Jul 21 12:40:57.890611 containerd[2389]: time="2026-07-21T12:40:57.890541689Z" level=info msg="StartContainer for \"cd4e60b52210a36adbe72a8369732614d28d223033c3e88669111f598ef51524\"" Jul 21 12:40:57.897010 systemd[1]: Started sshd@351-159-172.31.16.165:22-144.225.8.54:43364.service - OpenSSH per-connection server daemon (144.225.8.54:43364). Jul 21 12:40:57.897000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@351-159-172.31.16.165:22-144.225.8.54:43364 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:57.900391 containerd[2389]: time="2026-07-21T12:40:57.899085893Z" level=info msg="connecting to shim cd4e60b52210a36adbe72a8369732614d28d223033c3e88669111f598ef51524" address="unix:///run/containerd/s/308e33583940f89b30cb6d8e3bd8ad44aca8ab5fdd14fda8a088bc7151055c7b" protocol=ttrpc version=3 Jul 21 12:40:57.965685 systemd[1]: Started cri-containerd-cd4e60b52210a36adbe72a8369732614d28d223033c3e88669111f598ef51524.scope - libcontainer container cd4e60b52210a36adbe72a8369732614d28d223033c3e88669111f598ef51524. Jul 21 12:40:58.007000 audit: BPF prog-id=294 op=LOAD Jul 21 12:40:58.009000 audit: BPF prog-id=295 op=LOAD Jul 21 12:40:58.009000 audit[9425]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=8f7cdd31f90 a2=98 a3=0 items=0 ppid=3393 pid=9425 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:58.009000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6364346536306235323231306133366164626537326138333639373332 Jul 21 12:40:58.009000 audit: BPF prog-id=295 op=UNLOAD Jul 21 12:40:58.009000 audit[9425]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=3393 pid=9425 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:58.009000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6364346536306235323231306133366164626537326138333639373332 Jul 21 12:40:58.010000 audit: BPF prog-id=296 op=LOAD Jul 21 12:40:58.010000 audit[9425]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=8f7cdd32268 a2=98 a3=0 items=0 ppid=3393 pid=9425 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:58.010000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6364346536306235323231306133366164626537326138333639373332 Jul 21 12:40:58.010000 audit: BPF prog-id=297 op=LOAD Jul 21 12:40:58.010000 audit[9425]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=22 a0=5 a1=8f7cdd31fa8 a2=98 a3=0 items=0 ppid=3393 pid=9425 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:58.010000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6364346536306235323231306133366164626537326138333639373332 Jul 21 12:40:58.010000 audit: BPF prog-id=297 op=UNLOAD Jul 21 12:40:58.010000 audit[9425]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=16 a1=0 a2=0 a3=0 items=0 ppid=3393 pid=9425 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:58.010000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6364346536306235323231306133366164626537326138333639373332 Jul 21 12:40:58.010000 audit: BPF prog-id=296 op=UNLOAD Jul 21 12:40:58.010000 audit[9425]: SYSCALL arch=c00000b7 syscall=57 success=yes exit=0 a0=14 a1=0 a2=0 a3=0 items=0 ppid=3393 pid=9425 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:58.010000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6364346536306235323231306133366164626537326138333639373332 Jul 21 12:40:58.010000 audit: BPF prog-id=298 op=LOAD Jul 21 12:40:58.010000 audit[9425]: SYSCALL arch=c00000b7 syscall=280 success=yes exit=20 a0=5 a1=8f7cdd324b8 a2=98 a3=0 items=0 ppid=3393 pid=9425 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Jul 21 12:40:58.010000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F72756E2F636F6E7461696E6572642F72756E632F6B38732E696F002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6B38732E696F2F6364346536306235323231306133366164626537326138333639373332 Jul 21 12:40:58.083510 containerd[2389]: time="2026-07-21T12:40:58.083444582Z" level=info msg="StartContainer for \"cd4e60b52210a36adbe72a8369732614d28d223033c3e88669111f598ef51524\" returns successfully" Jul 21 12:40:58.183101 sshd[9424]: Invalid user debian from 144.225.8.54 port 43364 Jul 21 12:40:58.252625 sshd[9424]: Connection closed by invalid user debian 144.225.8.54 port 43364 [preauth] Jul 21 12:40:58.251000 audit[9424]: AUDIT1109 pid=9424 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:58.257363 systemd[1]: sshd@351-159-172.31.16.165:22-144.225.8.54:43364.service: Deactivated successfully. Jul 21 12:40:58.258000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@351-159-172.31.16.165:22-144.225.8.54:43364 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:58.329000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@352-4290-172.31.16.165:22-144.225.8.54:43366 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:58.330087 systemd[1]: Started sshd@352-4290-172.31.16.165:22-144.225.8.54:43366.service - OpenSSH per-connection server daemon (144.225.8.54:43366). Jul 21 12:40:58.577705 sshd[9461]: Invalid user debian from 144.225.8.54 port 43366 Jul 21 12:40:58.638408 sshd[9461]: Connection closed by invalid user debian 144.225.8.54 port 43366 [preauth] Jul 21 12:40:58.638000 audit[9461]: AUDIT1109 pid=9461 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:58.642950 systemd[1]: sshd@352-4290-172.31.16.165:22-144.225.8.54:43366.service: Deactivated successfully. Jul 21 12:40:58.643000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@352-4290-172.31.16.165:22-144.225.8.54:43366 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:58.714000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@353-4291-172.31.16.165:22-144.225.8.54:43372 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:58.714768 systemd[1]: Started sshd@353-4291-172.31.16.165:22-144.225.8.54:43372.service - OpenSSH per-connection server daemon (144.225.8.54:43372). Jul 21 12:40:58.980465 sshd[9467]: Invalid user debian from 144.225.8.54 port 43372 Jul 21 12:40:59.040885 sshd[9467]: Connection closed by invalid user debian 144.225.8.54 port 43372 [preauth] Jul 21 12:40:59.041000 audit[9467]: AUDIT1109 pid=9467 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:59.046823 systemd[1]: sshd@353-4291-172.31.16.165:22-144.225.8.54:43372.service: Deactivated successfully. Jul 21 12:40:59.046000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@353-4291-172.31.16.165:22-144.225.8.54:43372 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:59.121000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@354-4292-172.31.16.165:22-144.225.8.54:43376 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:59.120938 systemd[1]: Started sshd@354-4292-172.31.16.165:22-144.225.8.54:43376.service - OpenSSH per-connection server daemon (144.225.8.54:43376). Jul 21 12:40:59.381558 sshd[9475]: Invalid user debian from 144.225.8.54 port 43376 Jul 21 12:40:59.442929 sshd[9475]: Connection closed by invalid user debian 144.225.8.54 port 43376 [preauth] Jul 21 12:40:59.443000 audit[9475]: AUDIT1109 pid=9475 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:59.451040 systemd[1]: sshd@354-4292-172.31.16.165:22-144.225.8.54:43376.service: Deactivated successfully. Jul 21 12:40:59.450000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@354-4292-172.31.16.165:22-144.225.8.54:43376 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:59.521476 systemd[1]: Started sshd@355-4293-172.31.16.165:22-144.225.8.54:43378.service - OpenSSH per-connection server daemon (144.225.8.54:43378). Jul 21 12:40:59.521000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@355-4293-172.31.16.165:22-144.225.8.54:43378 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:59.786770 sshd[9481]: Invalid user debian from 144.225.8.54 port 43378 Jul 21 12:40:59.848276 sshd[9481]: Connection closed by invalid user debian 144.225.8.54 port 43378 [preauth] Jul 21 12:40:59.847000 audit[9481]: AUDIT1109 pid=9481 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:59.850191 kernel: kauditd_printk_skb: 53 callbacks suppressed Jul 21 12:40:59.850292 kernel: audit: type=1109 audit(1784637659.847:1953): pid=9481 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:40:59.860505 systemd[1]: sshd@355-4293-172.31.16.165:22-144.225.8.54:43378.service: Deactivated successfully. Jul 21 12:40:59.862000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@355-4293-172.31.16.165:22-144.225.8.54:43378 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:59.865410 kernel: audit: type=1131 audit(1784637659.862:1954): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@355-4293-172.31.16.165:22-144.225.8.54:43378 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:59.924000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@356-160-172.31.16.165:22-144.225.8.54:43388 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:40:59.925356 systemd[1]: Started sshd@356-160-172.31.16.165:22-144.225.8.54:43388.service - OpenSSH per-connection server daemon (144.225.8.54:43388). Jul 21 12:40:59.936317 kernel: audit: type=1130 audit(1784637659.924:1955): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@356-160-172.31.16.165:22-144.225.8.54:43388 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:00.204586 sshd[9487]: Invalid user debian from 144.225.8.54 port 43388 Jul 21 12:41:00.264771 sshd[9487]: Connection closed by invalid user debian 144.225.8.54 port 43388 [preauth] Jul 21 12:41:00.264000 audit[9487]: AUDIT1109 pid=9487 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:00.271362 kernel: audit: type=1109 audit(1784637660.264:1956): pid=9487 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:00.273480 systemd[1]: sshd@356-160-172.31.16.165:22-144.225.8.54:43388.service: Deactivated successfully. Jul 21 12:41:00.272000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@356-160-172.31.16.165:22-144.225.8.54:43388 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:00.280356 kernel: audit: type=1131 audit(1784637660.272:1957): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@356-160-172.31.16.165:22-144.225.8.54:43388 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:00.340000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@357-161-172.31.16.165:22-144.225.8.54:43398 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:00.341855 systemd[1]: Started sshd@357-161-172.31.16.165:22-144.225.8.54:43398.service - OpenSSH per-connection server daemon (144.225.8.54:43398). Jul 21 12:41:00.351335 kernel: audit: type=1130 audit(1784637660.340:1958): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@357-161-172.31.16.165:22-144.225.8.54:43398 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:00.593627 sshd[9493]: Invalid user debian from 144.225.8.54 port 43398 Jul 21 12:41:00.653898 sshd[9493]: Connection closed by invalid user debian 144.225.8.54 port 43398 [preauth] Jul 21 12:41:00.653000 audit[9493]: AUDIT1109 pid=9493 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:00.658758 systemd[1]: sshd@357-161-172.31.16.165:22-144.225.8.54:43398.service: Deactivated successfully. Jul 21 12:41:00.660273 kernel: audit: type=1109 audit(1784637660.653:1959): pid=9493 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:00.659000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@357-161-172.31.16.165:22-144.225.8.54:43398 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:00.668285 kernel: audit: type=1131 audit(1784637660.659:1960): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@357-161-172.31.16.165:22-144.225.8.54:43398 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:00.732000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@358-4294-172.31.16.165:22-144.225.8.54:43404 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:00.732806 systemd[1]: Started sshd@358-4294-172.31.16.165:22-144.225.8.54:43404.service - OpenSSH per-connection server daemon (144.225.8.54:43404). Jul 21 12:41:00.742267 kernel: audit: type=1130 audit(1784637660.732:1961): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@358-4294-172.31.16.165:22-144.225.8.54:43404 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:00.981276 sshd[9499]: Invalid user debian from 144.225.8.54 port 43404 Jul 21 12:41:01.043046 sshd[9499]: Connection closed by invalid user debian 144.225.8.54 port 43404 [preauth] Jul 21 12:41:01.042000 audit[9499]: AUDIT1109 pid=9499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:01.049406 systemd[1]: sshd@358-4294-172.31.16.165:22-144.225.8.54:43404.service: Deactivated successfully. Jul 21 12:41:01.049000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@358-4294-172.31.16.165:22-144.225.8.54:43404 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:01.050544 kernel: audit: type=1109 audit(1784637661.042:1962): pid=9499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:01.117000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@359-4295-172.31.16.165:22-144.225.8.54:43406 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:01.116714 systemd[1]: Started sshd@359-4295-172.31.16.165:22-144.225.8.54:43406.service - OpenSSH per-connection server daemon (144.225.8.54:43406). Jul 21 12:41:01.361980 sshd[9505]: Invalid user debian from 144.225.8.54 port 43406 Jul 21 12:41:01.422210 sshd[9505]: Connection closed by invalid user debian 144.225.8.54 port 43406 [preauth] Jul 21 12:41:01.421000 audit[9505]: AUDIT1109 pid=9505 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:01.426106 systemd[1]: sshd@359-4295-172.31.16.165:22-144.225.8.54:43406.service: Deactivated successfully. Jul 21 12:41:01.425000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@359-4295-172.31.16.165:22-144.225.8.54:43406 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:01.493000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@360-4296-172.31.16.165:22-144.225.8.54:43412 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:01.494773 systemd[1]: Started sshd@360-4296-172.31.16.165:22-144.225.8.54:43412.service - OpenSSH per-connection server daemon (144.225.8.54:43412). Jul 21 12:41:01.737886 sshd[9511]: Invalid user debian from 144.225.8.54 port 43412 Jul 21 12:41:01.798691 sshd[9511]: Connection closed by invalid user debian 144.225.8.54 port 43412 [preauth] Jul 21 12:41:01.797000 audit[9511]: AUDIT1109 pid=9511 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:01.801838 systemd[1]: sshd@360-4296-172.31.16.165:22-144.225.8.54:43412.service: Deactivated successfully. Jul 21 12:41:01.801000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@360-4296-172.31.16.165:22-144.225.8.54:43412 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:01.875000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@361-4297-172.31.16.165:22-144.225.8.54:43416 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:01.876782 systemd[1]: Started sshd@361-4297-172.31.16.165:22-144.225.8.54:43416.service - OpenSSH per-connection server daemon (144.225.8.54:43416). Jul 21 12:41:02.123641 sshd[9517]: Invalid user debian from 144.225.8.54 port 43416 Jul 21 12:41:02.184364 sshd[9517]: Connection closed by invalid user debian 144.225.8.54 port 43416 [preauth] Jul 21 12:41:02.183000 audit[9517]: AUDIT1109 pid=9517 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:02.187965 systemd[1]: sshd@361-4297-172.31.16.165:22-144.225.8.54:43416.service: Deactivated successfully. Jul 21 12:41:02.187000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@361-4297-172.31.16.165:22-144.225.8.54:43416 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:02.261828 systemd[1]: Started sshd@362-4298-172.31.16.165:22-144.225.8.54:43432.service - OpenSSH per-connection server daemon (144.225.8.54:43432). Jul 21 12:41:02.260000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@362-4298-172.31.16.165:22-144.225.8.54:43432 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:02.512097 sshd[9524]: Invalid user debian from 144.225.8.54 port 43432 Jul 21 12:41:02.574257 sshd[9524]: Connection closed by invalid user debian 144.225.8.54 port 43432 [preauth] Jul 21 12:41:02.573000 audit[9524]: AUDIT1109 pid=9524 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:02.577813 systemd[1]: sshd@362-4298-172.31.16.165:22-144.225.8.54:43432.service: Deactivated successfully. Jul 21 12:41:02.578000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@362-4298-172.31.16.165:22-144.225.8.54:43432 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:02.648764 systemd[1]: Started sshd@363-4299-172.31.16.165:22-144.225.8.54:43436.service - OpenSSH per-connection server daemon (144.225.8.54:43436). Jul 21 12:41:02.647000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@363-4299-172.31.16.165:22-144.225.8.54:43436 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:02.896045 sshd[9530]: Invalid user debian from 144.225.8.54 port 43436 Jul 21 12:41:02.956994 sshd[9530]: Connection closed by invalid user debian 144.225.8.54 port 43436 [preauth] Jul 21 12:41:02.956000 audit[9530]: AUDIT1109 pid=9530 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:02.960363 systemd[1]: sshd@363-4299-172.31.16.165:22-144.225.8.54:43436.service: Deactivated successfully. Jul 21 12:41:02.959000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@363-4299-172.31.16.165:22-144.225.8.54:43436 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:03.031000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@364-4300-172.31.16.165:22-144.225.8.54:43444 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:03.032774 systemd[1]: Started sshd@364-4300-172.31.16.165:22-144.225.8.54:43444.service - OpenSSH per-connection server daemon (144.225.8.54:43444). Jul 21 12:41:03.278340 sshd[9536]: Invalid user debian from 144.225.8.54 port 43444 Jul 21 12:41:03.340342 sshd[9536]: Connection closed by invalid user debian 144.225.8.54 port 43444 [preauth] Jul 21 12:41:03.339000 audit[9536]: AUDIT1109 pid=9536 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:03.344032 systemd[1]: sshd@364-4300-172.31.16.165:22-144.225.8.54:43444.service: Deactivated successfully. Jul 21 12:41:03.344000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@364-4300-172.31.16.165:22-144.225.8.54:43444 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:03.416000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@365-162-172.31.16.165:22-144.225.8.54:43452 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:03.417255 systemd[1]: Started sshd@365-162-172.31.16.165:22-144.225.8.54:43452.service - OpenSSH per-connection server daemon (144.225.8.54:43452). Jul 21 12:41:03.670715 sshd[9544]: Invalid user debian from 144.225.8.54 port 43452 Jul 21 12:41:03.731401 sshd[9544]: Connection closed by invalid user debian 144.225.8.54 port 43452 [preauth] Jul 21 12:41:03.730000 audit[9544]: AUDIT1109 pid=9544 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:03.735291 systemd[1]: sshd@365-162-172.31.16.165:22-144.225.8.54:43452.service: Deactivated successfully. Jul 21 12:41:03.735000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@365-162-172.31.16.165:22-144.225.8.54:43452 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:03.809982 systemd[1]: Started sshd@366-4301-172.31.16.165:22-144.225.8.54:43468.service - OpenSSH per-connection server daemon (144.225.8.54:43468). Jul 21 12:41:03.810000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@366-4301-172.31.16.165:22-144.225.8.54:43468 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:04.054332 sshd[9551]: Invalid user debian from 144.225.8.54 port 43468 Jul 21 12:41:04.114724 sshd[9551]: Connection closed by invalid user debian 144.225.8.54 port 43468 [preauth] Jul 21 12:41:04.114000 audit[9551]: AUDIT1109 pid=9551 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:04.118804 systemd[1]: sshd@366-4301-172.31.16.165:22-144.225.8.54:43468.service: Deactivated successfully. Jul 21 12:41:04.120000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@366-4301-172.31.16.165:22-144.225.8.54:43468 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:04.195397 systemd[1]: Started sshd@367-4302-172.31.16.165:22-144.225.8.54:43480.service - OpenSSH per-connection server daemon (144.225.8.54:43480). Jul 21 12:41:04.194000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@367-4302-172.31.16.165:22-144.225.8.54:43480 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:04.446971 sshd[9557]: Invalid user debian from 144.225.8.54 port 43480 Jul 21 12:41:04.508411 sshd[9557]: Connection closed by invalid user debian 144.225.8.54 port 43480 [preauth] Jul 21 12:41:04.508000 audit[9557]: AUDIT1109 pid=9557 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:04.512307 systemd[1]: sshd@367-4302-172.31.16.165:22-144.225.8.54:43480.service: Deactivated successfully. Jul 21 12:41:04.513000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@367-4302-172.31.16.165:22-144.225.8.54:43480 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:04.584785 systemd[1]: Started sshd@368-4303-172.31.16.165:22-144.225.8.54:43488.service - OpenSSH per-connection server daemon (144.225.8.54:43488). Jul 21 12:41:04.583000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@368-4303-172.31.16.165:22-144.225.8.54:43488 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:04.828568 sshd[9564]: Invalid user debian from 144.225.8.54 port 43488 Jul 21 12:41:04.888373 sshd[9564]: Connection closed by invalid user debian 144.225.8.54 port 43488 [preauth] Jul 21 12:41:04.888000 audit[9564]: AUDIT1109 pid=9564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:04.893653 systemd[1]: sshd@368-4303-172.31.16.165:22-144.225.8.54:43488.service: Deactivated successfully. Jul 21 12:41:04.895360 kernel: kauditd_printk_skb: 29 callbacks suppressed Jul 21 12:41:04.895418 kernel: audit: type=1109 audit(1784637664.888:1992): pid=9564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/lib64/misc/sshd-session" hostname=144.225.8.54 addr=144.225.8.54 terminal=ssh res=failed' Jul 21 12:41:04.889000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@368-4303-172.31.16.165:22-144.225.8.54:43488 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:04.900934 kernel: audit: type=1131 audit(1784637664.889:1993): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@368-4303-172.31.16.165:22-144.225.8.54:43488 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:04.978018 systemd[1]: Started sshd@369-4304-172.31.16.165:22-144.225.8.54:43494.service - OpenSSH per-connection server daemon (144.225.8.54:43494). Jul 21 12:41:04.977000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@369-4304-172.31.16.165:22-144.225.8.54:43494 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jul 21 12:41:04.987235 kernel: audit: type=1130 audit(1784637664.977:1994): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@369-4304-172.31.16.165:22-144.225.8.54:43494 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'