Vigil: the site answers is failing
fixedopened 26 days agodown 87s
what the check said
the site answers — expected 200, got 502
Warden’s diagnosis · 90% sure of the cause
vigil's own pm2 process is "stopped", which is why every request to https://vigil.80.225.209.190.sslip.io/ is being answered by a 502 from whatever sits in front of it: the origin on this machine is not running. The out-log shows clean restarts ("Ready in 979ms", "Ready in 928ms", …) and no error/exception output, so the process is not crashing in a loop — it is being shut down or killed from outside. pm2's restart count is 27 since it was added, but what matters is lastStartedAt=2026-09-14T22:16:59.605Z, which is two minutes before the check started failing again. This pattern (process stopped, clean restarts in the log, no exception, fleet-wide sweeps running on the same cron schedule) matches the standing rules: "vigil is the service the console lets visitors break on purpose, and it is put back more often than anything else here." Per the owner's standing instruction and policy, restarting a stopped process is in-bounds without asking.
suspect · pm2 process "vigil" — status stopped; no error log.
This one was worked before you opened the page, so there is nothing to watch live. Everything it did is in Everything it ran below, with the exact command and the rule that permitted each one — that table is the record, and this timeline is only the same thing arriving in real time.
vigil's own pm2 process is "stopped", which is why every request to https://vigil.80.225.209.190.sslip.io/ is being answered by a 502 from whatever sits in front of it: the origin on this machine is not running. Fixed, and the check that failed passes again.
Everything it ran6 calls · 1 changed something
Warden has no shell. Each row below is one named action from a fixed list, spawned without a shell, with the rule of yours that permitted it. Copy any command and run it yourself.
| what | how safe | your rule | command | ms |
|---|---|---|---|---|
ask what answers http_headers | looks only | asked youyou never granted it | Your policy does not grant http_headers on this service, so Warden will not do it without you. | — |
load the page http_probe | looks only | did ityou allowed it | GET https://vigil.80.225.209.190.sslip.io/ | 561 |
list the processes pm2_list | looks only | did ityou allowed it | pm2 jlist | 174 |
read the log pm2_logs | looks only | did ityou allowed it | pm2 logs vigil --lines 120 (errors only) | 183 |
read the log pm2_logs | looks only | did ityou allowed it | pm2 logs vigil --lines 200 | 184 |
start the process pm2_start | undoes itself | did ityou allowed it | start vigil | 498 |
This incident is marked resolved because the site answers — the same check that failed — was run again and passed. Nothing Warden believed about its own fix could have closed it.