
Situation
There was one final task before leaving for dinner: shut down the local desktop workstation and walk away. The workstation and the production server were both open side-by-side in terminal windows on the same 3440×1440 ultrawide monitor.
The desktop workstation on the left and the remote production server on the right intentionally shared the same Sway desktop and terminal appearance. Both terminals were visible at the same time.
What Happened
The shutdown command was entered without noticing that the active terminal was not the intended one. The command completed, and the session appeared to be finished.
Only after standing up to leave for dinner did something feel unusual: the desktop computer was still running.
That short moment of confusion identified the mistake. The active terminal had been connected to the remote production server, Worldnode, rather than the local workstation, Cthulhu. The production server had shut down exactly as instructed.
Solution
The provider console was used to reconnect and start the server again. The website and every World Observer service were then checked and confirmed to be back online.
Update · 12.09.2026
THE WRONG TERMINAL II — WORLDNODE STRIKES BACK
It happened again.
That day had been spent turning a Cisco CP-9951 into a delightfully unnecessary homelab terminal. Monitor 2 was still covered in the leftovers of the experiment: SIP sessions, Cisco configuration, DOOM, FFmpeg, Baresip and capture terminals. In other words, there were enough nearly identical shells open to make one wrong focus entirely plausible.
At the end of the evening the intention was simple: shut down the local workstation, Cthulhu. sudo shutdown now was entered, the remaining windows disappeared and the day appeared to be finished.
A little later, Katharina wanted to look at the story from that day on the website. Her report was short: “It doesn't load.”
That sentence triggered immediate recognition. The machine that had obediently received the shutdown command was, once again, Worldnode.
The workstation had survived. The production server had not.
Worldnode was brought back online, the site was checked, and two broken German World Observer routes discovered during the recovery were repaired as well.
Preventing Part III
The real fix is not “pay more attention.” The two systems deliberately look similar, and humans eventually click the wrong terminal.
So Worldnode now has a shutdown guard. The usual shutdown, reboot, poweroff and halt commands resolve through guarded wrappers in /usr/local/sbin. Before anything destructive happens, the terminal now makes the target painfully obvious:
“REALLY STOP THE WEBSITE, JUNGE?!”
It then requires the exact phrase STOP WORLDNODE. A normal Enter, a distracted yes, or muscle memory is not enough.
The guard was installed and tested on 12.09.2026. Both sudo shutdown --guard-test and sudo reboot --guard-test confirmed the protection without stopping the machine, and the four guarded commands were verified to resolve to /usr/local/sbin.
Lesson
The command wasn't wrong.
The terminal was.
Twice.
Part III now has to get past the guard first.