warden / Vigil / problem

Vigil: the site answers is failing

fixedopened 26 days agodown 5m

what the check said

the site answers — expected 200, got 502

Warden’s diagnosis · 55% sure of the cause

The vigil process is stopped (pm2 status: "stopped", restartsSinceAdded: 8, lastStartedAt: 2026-09-14T07:48:57Z — i.e. it exited about 4 minutes ago, which matches minutesDown: 4). The upstream 502 is the consequence, not the cause: the gateway is proxying to a dead listener. The stdout shows the app reaches "✓ Ready in ~1000ms" on every boot, then dies with no error logged and the error stream is empty. That pattern — clean startup, no exception, sudden death — is what an OOM kill (pm2 max_memory_restart, or the host OOM killer) leaves behind, because SIGKILL produces no log line. Repository is on the correct disk (/home/ubuntu/vigil), 20G free, so disk is not the cause. The check started failing at 07:20:01Z; pm2's restart count climbing in that window is consistent with the process being repeatedly killed shortly after start. I did not find a stack trace pointing at a specific code path, and I deliberately did not read the application source — the process is not running, so no code path is the answer right now.

suspect · pm2 process vigil (post-startup kill, most likely OOM)

Done

This one was worked before you opened the page, so there is nothing to watch live. Everything it did is in Everything it ran below, with the exact command and the rule that permitted each one — that table is the record, and this timeline is only the same thing arriving in real time.

    The vigil process is stopped (pm2 status: "stopped", restartsSinceAdded: 8, lastStartedAt: 2026-09-14T07:48:57Z — i.e. it exited about 4 minutes ago, which matches minutesDown: 4). The upstream 502 is — fixed and verified.

    Everything it ran10 calls · 1 changed something

    Warden has no shell. Each row below is one named action from a fixed list, spawned without a shell, with the rule of yours that permitted it. Copy any command and run it yourself.

    whathow safeyour rulecommandms
    read the log pm2_logslooks onlydid ityou allowed itpm2 logs vigil --lines 80189
    load the page http_probelooks onlydid ityou allowed itGET https://vigil.80.225.209.190.sslip.io/561
    list the processes pm2_listlooks onlydid ityou allowed itpm2 jlist270
    read the log pm2_logslooks onlydid ityou allowed itpm2 logs vigil --lines 80 (errors only)193
    read recent commits git_loglooks onlydid ityou allowed itgit log -n 109
    read one commit git_showlooks onlydid ityou allowed itgit show 6fad86615
    read a file read_filelooks onlydid ityou allowed itread /home/ubuntu/vigil/package.json9
    check disk space disk_freelooks onlydid ityou allowed itdf -h /9
    read the log pm2_logslooks onlydid ityou allowed itpm2 logs vigil --lines 200192
    start the process pm2_startundoes itselfdid ityou allowed itstart vigil353

    This incident is marked resolved because the site answers — the same check that failed — was run again and passed. Nothing Warden believed about its own fix could have closed it.

    Warden — an autonomous operator for software that is already running