I had three schedulers, and none of them knew the other two existed.

A cron table on nix1, launchd jobs on the Mac Mini, and a handful of GitHub Actions workflows. Each got added on its own and each one worked. Together they had a dangerous property. A healthy fleet and a dead fleet produced the same output, which was nothing. The daily digest stayed quiet unless something changed, and the pulse went missing whenever the box that sent it was down. Silence could mean fine or it could mean broken, and I read it as fine every time.

Timezone was being decided by line number. A CRON_TZ line sat at line 42 of the crontab, so jobs above it ran UTC and jobs below it ran Eastern. One watcher's own header documented times four hours off from when it fired.

Today I built a schedule registry that every job has to be listed in, a drift check against it, and a dead-man's switch. Jobs write a heartbeat when they finish, the Mini pushes those to nix1 over the SSH path it already had, and nix1 flags anything stale. No new credentials anywhere. Each heartbeat carries its own max age, so adding a job never means touching the checker, and a heartbeat it can't read counts as stale instead of getting skipped. I ran it against six controls before trusting it: fresh, stale, corrupt, missing store, empty store, and a path traversal attempt.

Work now goes to whichever machine can reach what the job touches. The cloud side has no route to my LAN, so the Mac Mini stays load-bearing.