Four satellites, one part shortage, and a redesign in nine weeks

Claire Dubois Programme Lead, Ottawa

The notification arrived on a Tuesday. Last-time-buy in ninety days, end of production in twelve months, and we had two of four spacecraft built.

Constellation programmes are built on sameness. The customer had contracted for four identical spacecraft precisely so that operations, spares and ground software would be identical too. Spacecraft one and two were integrated and through environmental test. Three and four existed as a bill of materials and a schedule.

The radiation-hardened FPGA at the centre of the Meridian processing core was going out of production.

The three bad options

We put three options in front of the customer within a week, with honest numbers attached.

Last-time buy. Purchase enough devices for spacecraft three and four plus spares. Fastest, and it solves nothing — it converts a design problem into an inventory problem and hands it to whoever needs a replacement board in year six. We priced it, and recommended against it.

Fly a mixed fleet. Redesign for three and four, leave one and two as built. Cheapest in engineering hours and most expensive everywhere else: two ground software variants, two spares pools, two anomaly-investigation baselines for seven years.

Redesign all four. Most engineering, most schedule risk, one fleet at the end of it. This is what we recommended and what the customer chose.

The customer's programme manager asked one question before deciding: how much of the existing qualification survives? That number decided it.

Why nine weeks was possible

The answer was: most of it. And that is entirely down to a decision made three years earlier, when the Meridian architecture was first laid out.

The processing core sits behind a specified interface. The power system, attitude control, radio and payload interface do not know what is inside it. They know the electrical interface, the timing contract and the fault semantics. Nothing else in the bus reaches through that boundary.

That boundary is not free. It cost real performance in a couple of places — there is a data path that would be measurably faster without it, and an engineer argued hard for the shortcut in 2022. The boundary held because the architecture lead insisted the core would outlive at least one silicon generation.

He was right, and he was right for a reason he could not have known at the time. That is what a good architectural decision looks like from the outside.Claire Dubois · Programme Lead

What actually had to change

Because the boundary held, the redesign was contained to the core module:

  • The FPGA and its support circuitry — new device, new configuration memory, revised power sequencing.
  • The logic implementation — re-synthesised and re-verified against unchanged requirements, which is a very different job from re-writing them.
  • Radiation qualification for the new device — the long pole, and the reason nine weeks was tight rather than comfortable.

What did not change: the bus software, the ground segment, the interface control documents, the power system, the attitude control electronics, the radio, the mechanical envelope, the thermal design, or the launch vehicle interface. The qualification evidence for all of it carried across unchanged, and we could show exactly why.

The nine weeks

Weeks one to two: device selection and a survey of existing radiation data. We shortlisted three candidates and picked the one with published heavy-ion data close enough to our environment to be usable, rather than the highest-performing part.

Weeks two to five: logic re-implementation and board respin, run in parallel. The independent verification team in Ottawa started against the unchanged requirements before the boards existed, using the simulator.

Weeks four to eight: radiation campaign. Beam time was the hard constraint and we were fortunate — a slot came free at short notice. Without it we would have been looking at fourteen weeks, not nine, and we told the customer that in writing at the time rather than claiming the schedule was robust.

Weeks seven to nine: integration and environmental test of the new core in a spacecraft-representative stack, then re-run of the affected acceptance tests on spacecraft one and two.

What it cost, and what we took from it

Nine weeks of schedule and a little under a fifth of the original avionics development cost, for a fleet that stayed identical. Both spacecraft already built were retrofitted with the new core before delivery.

Two things changed in how we work afterwards. We now run an obsolescence review at every design gate rather than annually, with lifecycle status treated as a design input and not a procurement footnote. And we write down, at architecture time, which boundaries exist to enable replacement — so that when somebody proposes the shortcut in three years, there is a recorded reason to say no.

The second one matters more. The boundary that saved this programme survived an argument it could easily have lost, and it survived because one person happened to hold the line. That is not a process.

Related

Read next

The twenty-year fleet and the seven-year part

Read

Eleven days in Wichita: what a DAL-A dry run really costs

Read

Talk to us

Bring us the awkward one.

The problems worth writing up are rarely the ones that arrive well specified. If yours is not, that is a reason to call rather than a reason to wait.

Start a conversation