The mirror of the heartbeat:
one switch that stops every loop.
Heartbeats tell you when a job died. A gate tells the
job whether it should run at all. Prepend one line to any cron entry,
systemd timer or agent loop — it checks its gate before every run. Halt the
gate and every box on every machine stops at its next boundary. No account,
no agent to install, nothing runs on your side but curl.
- Arm a gate. One form or one
curl. You get a gate URL that answers200 RUNor503 HALTwith a JSON reason. The key is shown once — it is both the gate's address and its remote control. - Make your loops check it. One line before the work:
[ "$(curl -s -o /dev/null -w '%{http_code}' --max-time 5 \ https://golemreach.com/heartbeat/gate/<key>)" = 200 ] || exit 0Cron, systemdExecStartPre=, CI step, agent-loop tick — same line everywhere. - Halt everything from anywhere. One curl (or the button below)
flips the gate with a reason. Loops stop at their next boundary and see WHY:
{ "state": "halt", "reason": "deploying v2, back by 14:00Z" } - Run it back. Flip to RUN when you land. Recovery is just another flip — and if you armed Nostr delivery, every flip lands as an encrypted DM in your client.
Halt at the boundary, not mid-flight
A gate is honest about what it is: jobs stop at their
next check, never mid-execution. That is the safe primitive — no sidecars,
no kernel modules, works on any box that can curl.
You choose the failure mode
The line above is fail-closed: unreachable control plane
means skip this round (safe for destructive jobs). Want fail-open instead?
[ "$(curl -s -o /dev/null -w '%{http_code}' URL)" = 503 ] &&
exit 0 — only an explicit HALT stops you.Flips reach you
Arm a notify npub and every HALT/RUN arrives as an
encrypted NIP-17 DM from our alert key — plus a line in the public event
feed. Nobody else in the dead-man cohort ships control-pull at all.
Agent-native
Create, check and flip gates over plain HTTP/JSON —
exactly how an autonomous fleet does it. This site's own babysitter refuses
to resurrect the server while its gate says HALT.
Create one from a terminal right now
curl -s https://golemreach.com/heartbeat/api/gates/self-serve -H 'Content-Type: application/json' \
-d '{"name":"nightly-fleet"}'
Response carries the gate URL, the exact shell prepend, and the flip command. Free while in beta; $5 Pro passes lift limits.
Arm a free gate
No account. The gate key is shown once, right after you submit — it is the check URL AND the flip credential.
Recipes
Cron entry (skip the run entirely):
[ "$(curl -s -o /dev/null -w '%{http_code}' --max-time 5 GATE_URL)" = 200 ] || exit 0
0 3 * * * /usr/local/bin/nightly-backup
systemd service (block the start):
[Service]
ExecStartPre=/bin/sh -c '[ "$(curl -s -o /dev/null -w '%{http_code}' --max-time 5 GATE_URL)" = 200 ] || exit 1'
ExecStart=/usr/local/bin/agent-loop
Agent loop (check every tick, Python):
import os, urllib.request
if urllib.request.urlopen(GATE_URL, timeout=5).status != 200:
raise SystemExit("gate says halt")
Flip remotely:
curl -s https://golemreach.com/heartbeat/api/gates/flip -H 'Content-Type: application/json' \
-d '{"key":"<key>","action":"halt","reason":"deploying"}'