Every seasoned PKI administrator has the moment, and most only admit it over drinks: three commands into a change, a cold jolt — wait, is this UAT? — and it wasn't. The consoles were pixel-identical; only a hostname differed, and hostnames don't shout. Wrong-instance actions are a top-tier operator hazard for a CA, and the protection goca ships costs you one minute, right now.
You are signed in, so you can see it: a fresh instance shows a muted, dash-bordered "Set environment…" badge in the top bar. Click it. Type a label — this machine is a lab, so say so, loudly: LAB, green — and save. From that moment the console opens every page with the heatline: a full-width colored bar carrying your label in white uppercase, the first element on every screen, sticky so it never scrolls away — and layered above the login overlay, because the identity of the system must read before any session exists. A matching top-bar badge and an optional page tint come with it. Presets cover the common convention — red PROD, blue ROOT CA, amber STAGING, green TEST — and any #rrggbb works.
Two honest details. The heatline is identity, not status: it never changes color by itself and never carries alerts. And it does not set itself — a fresh instance shows no banner until an operator types one; the console never invents an environment name (only root-CA-mode instances arrive pre-branded blue ROOT CA). Underneath, it is an ordinary versioned config resource, UiBranding/console, so every change is audited — while reading it needs no login at all, deliberately: its entire purpose is telling an operator which system this is before they sign in. Set it on day one, for every environment you ever stand up: it is the cheapest wrong-instance protection you will ever deploy.
Now every console I run announces what it is on every screen, login included — and the prod-instead-of-UAT jolt is a story I tell, not one I repeat.