warden / Vigil / problem

Vigil: the site answers is failing

fixedopened 26 days agodown 10m

what the check said

the site answers — expected 200, got 502

Warden’s diagnosis · 75% sure of the cause

502 because vigil is not running. `pm2 jlist` shows vigil with status "stopped" (not "errored"), lastStartedAt 2026-09-14T09:12:06.078Z, cwd /home/ubuntu/vigil. So the reverse proxy has nothing on port 3100. The output log shows Next.js reaching "Ready in ~1s" each time, and the error stream is empty — it isn't crashing on startup, it has been stopped. lastPassedAt 09:12:09 is ~3s after lastStartedAt, lining up with a brief window where the site answered 200 before the process exited, after which the proxy returned 502. "stopped" (not "errored") is the key clue: either pm2 was told not to auto-restart, or someone ran `pm2 stop vigil`. Standing rules show this happened twice before on this incident — the pattern is vigil being stopped and the owner approving a start. Restarting vigil (pm2_start, allowed without asking) should clear the 502.

suspect · vigil process (pm2 status: stopped)

Done

This one was worked before you opened the page, so there is nothing to watch live. Everything it did is in Everything it ran below, with the exact command and the rule that permitted each one — that table is the record, and this timeline is only the same thing arriving in real time.

    502 because vigil is not running. `pm2 jlist` shows vigil with status "stopped" (not "errored"), lastStartedAt 2026-09-14T09:12:06.078Z, cwd /home/ubuntu/vigil. So the reverse proxy has nothing on por — fixed and verified.

    What you decided

    Everything it ran13 calls · 1 changed something

    Warden has no shell. Each row below is one named action from a fixed list, spawned without a shell, with the rule of yours that permitted it. Copy any command and run it yourself.

    whathow safeyour rulecommandms
    list the processes pm2_listlooks onlydid ityou allowed itpm2 jlist185
    read the log pm2_logslooks onlydid ityou allowed itpm2 logs vigil --lines 100 (errors only)261
    read the log pm2_logslooks onlydid ityou allowed itpm2 logs vigil --lines 200200
    search the code grep_repolooks onlydid ityou allowed itgrep -rn "crash|exit|SIGTERM|fatal|killed|EADDR|throw|ENOENT|TypeError" /home/ubuntu/vigil24
    read recent commits git_loglooks onlydid ityou allowed itgit log -n 109
    read recent commits git_loglooks onlydid ityou allowed itgit log -n 2511
    read one commit git_showlooks onlydid ityou allowed itgit show 6fad86615
    read one commit git_showlooks onlydid ityou allowed itgit show 503accd37
    read recent commits git_loglooks onlydid ityou allowed itgit log -n 3010
    read a file read_filelooks onlydid ityou allowed itread /home/ubuntu/vigil/ecosystem.config.cjs23
    start the process pm2_startundoes itselfasked youstill cooling down from the last actWarden acted on this service 8 minutes ago and your cooldown is 10. Restarting in a loop is not a fix.—
    start the process pm2_startundoes itselfdid ityou allowed itstart vigil319
    run the tests run_testsundoes itselfasked youstill cooling down from the last actWarden acted on this service 0 minutes ago and your cooldown is 10. Restarting in a loop is not a fix.—

    This incident is marked resolved because the site answers — the same check that failed — was run again and passed. Nothing Warden believed about its own fix could have closed it.

    Warden — an autonomous operator for software that is already running