warden / service
SAGE
Someone else's production, and it is submitted to two competitions. Warden watches it and touches nothing.
observe only
What it checks600 looks kept
- passingthe site answers100% of 120
GET https://sagepays.xyz/ · every 120s · opens a problem after 2 failures in a row
200 in 147ms
- passingthe process is up100% of 120
pm2 · sage · every 120s · opens a problem after 1 failure in a row
online, 16 restarts since deploy
- passingthe certificate is not about to expire100% of 120
pm2 · · every 21600s · opens a problem after 1 failure in a row
56 days left, until 2026-12-06 (Let's Encrypt)
What it may do here
This is the whole list — there is nothing else Warden is able to do.
“Watch and diagnose. Touch nothing — this service is not ours to operate.” At most 0 actions on one problem, and no acting twice within 0 minutes.
| what | what it does | your rule |
|---|---|---|
| load the page | Asks a URL and reports the status and how long it took. Reads nothing else. | may |
| check the certificate | Reads the TLS certificate a URL is served with and reports how many days are left on it. | asks first |
| look up the name | Asks DNS what a URL's host name points at, so a name that stopped resolving is caught by name. | asks first |
| ask what answers | Fetches a URL without following it off-site and reports what answered: the status, the server, whether it is a proxy's error page. | asks first |
| list the processes | Lists the processes on the machine with their status, uptime and restart count. | may |
| read the log | Reads the last lines of a process's output and error logs. | may |
| read recent commits | Reads the recent commits in the checkout — what landed, when, and by whom. | may |
| read one commit | Reads one commit's diff, to see what a change actually did. | may |
| read a file | Reads one file from inside the service's checkout. It cannot read outside it. | may |
| search the code | Searches the checkout for a string, to find where something is configured. | may |
| check disk space | Reads how much disk is left, because a full disk looks like everything else. | may |
| restart the process | Restarts the process. Undoes itself: the same code comes back up. | never |
| start the process | Starts the process when it is stopped. Undoes itself. | never |
| run the tests | Runs the test suite in the checkout and reads the result. Changes nothing. | never |
| call the deploy hook | POSTs the deploy or restart hook the owner gave this service, which redeploys or restarts it. Undoes itself: the same code comes back. | asks first |
| roll back to the last deploy | Checks out the previous commit and restarts. This changes which code is running. | never |
| run a migration | Would run database migrations. Refused by name — a migration is not undone by a restart. | never, whatever your rules say |
| delete data | Would delete data. Refused by name. There is no incident this is the answer to. | never, whatever your rules say |
| rotate a secret | Would rotate a credential. Refused by name — it breaks everything still holding the old one. | never, whatever your rules say |
| destroy infrastructure | Would destroy infrastructure. Refused by name, and listed here so you can see it is. | never, whatever your rules say |