warden / Vigil / problem

Vigil: the site answers is failing

fixedopened 26 days agodown 67s

what the check said

the site answers — expected 200, got 502

Warden’s diagnosis · 70% sure of the cause

vigil is stopped, not crashed. `pm2_list`: status "stopped", lastStartedAt 11:06:25 (one minute before this incident). Error stream is empty — no stack trace. Out stream only shows Next.js startup banners ("✓ Ready in ~900ms") repeating. `grep_repo` for `process.on` returned nothing in the repo, so the app has no SIGTERM/SIGINT handler of its own. Failures began 07:20 UTC, intermittent (26/108 looks failed), 17 cumulative restarts. The 502 is the reverse proxy saying "no upstream" because nothing is listening on :3100. Per owner's standing rule ("Restart it if it is just stopped"), pm2_restart vigil is the natural next step. If it stops again immediately after restart, the cause is external (cron, vigilante-sweep, warden-sweep) and warrants a second look.

suspect · vigil process — lastStartedAt 2026-09-14T11:06:25.567Z, exits cleanly with no error output

Done

This one was worked before you opened the page, so there is nothing to watch live. Everything it did is in Everything it ran below, with the exact command and the rule that permitted each one — that table is the record, and this timeline is only the same thing arriving in real time.

    vigil is stopped, not crashed. Fixed, and the check that failed passes again.

    Everything it ran11 calls · 1 changed something

    Warden has no shell. Each row below is one named action from a fixed list, spawned without a shell, with the rule of yours that permitted it. Copy any command and run it yourself.

    whathow safeyour rulecommandms
    list the processes pm2_listlooks onlydid ityou allowed itpm2 jlist206
    read the log pm2_logslooks onlydid ityou allowed itpm2 logs vigil --lines 100 (errors only)253
    read the log pm2_logslooks onlydid ityou allowed itpm2 logs vigil --lines 150239
    read recent commits git_loglooks onlydid ityou allowed itgit log -n 1510
    load the page http_probelooks onlydid ityou allowed itGET https://vigil.80.225.209.190.sslip.io16
    read a file read_filelooks onlydid ityou allowed itread /home/ubuntu/vigil/package.json12
    search the code grep_repolooks onlydid ityou allowed itgrep -rn "vigil|process.on\\(|SIGTERM|SIGINT|stop\\(\\)" /home/ubuntu/vigil15
    search the code grep_repolooks onlydid ityou allowed itgrep -rn "vigil" /home/ubuntu/vigil32
    search the code grep_repolooks onlydid ityou allowed itgrep -rn "process\\.on" /home/ubuntu/vigil27
    search the code grep_repolooks onlydid ityou allowed itgrep -rn "owed" /home/ubuntu/vigil129
    restart the process pm2_restartundoes itselfdid ityou allowed itrestart vigil251

    This incident is marked resolved because the site answers — the same check that failed — was run again and passed. Nothing Warden believed about its own fix could have closed it.

    Warden — an autonomous operator for software that is already running