DELTA-SIERRA · SPACE ACADEMYBack to the Mars Bible
MODULE 12 · Progressive training: understand, calculate, verify.

Survival & ECLSS: close loops without hiding failures

A life-support loop must survive its own failures
A life-support loop must survive its own failures — teaching summary diagram for this module.

ECLSS is a system of life-support functions, not one machine. It must maintain air, water, temperature, and quality while remaining controllable after faults.

The module separates ISS-demonstrated performance, long-duration goals, and Mars teaching scenarios.

1. Start from life-support functions

ECLSS is not one box but a set of functions: breathable atmosphere, potable water, thermal control, hygiene, waste processing, and monitoring. Equipment may change while the required function remains.

For each function, track inventory, flow, quality, and time to consequence. CO₂ sensor failure and pressure-shell rupture evolve on different timescales and demand different responses.

System intuition

A vital system should be described as a measurable function before hardware is chosen. For each function, define the controlled variable, acceptable domain, sensor, action, backup path, and recovery criterion. This prevents a hardware item from being confused with the survival function it performs.

fonction = variable + limite + mesure + action + secours + récupération

One hardware item can support several functions; that interconnection must remain visible in common-cause analysis.

Design case — function and backup

Take the function “remove CO₂.” Write the sensor that detects drift, nominal removal capacity, saturation signal, backup path, and criterion for returning to normal mode. If the backup uses the same fan or power bus, it is not independent. This simple sheet turns a hardware list into a verifiable survival architecture.

Decision check. A useful design review asks whether the function can be demonstrated end to end: can the sensor detect the state, can the controller decide, can an actuator restore the variable, and can the crew verify recovery? Writing that chain for every vital function exposes hidden dependencies before hardware names dominate the discussion.

2. Atmosphere means pressure plus composition

A habitable atmosphere has total pressure and partial pressures. O₂, CO₂, water vapor, and contaminants must be monitored; correct total pressure can coexist with dangerous composition.

Pressure is also structural load. A 70 kPa difference over 1 m² produces 70 kN ideal resultant force. The atmosphere is both a life resource and a mechanical load.

Quantified balance

Total pressure and composition are insufficient when considered separately. An atmosphere can have correct total pressure but inadequate oxygen partial pressure, or the reverse. Sensors must therefore distinguish pressure, gas fractions, temperature, humidity, and contaminants rather than reducing “air” to one reading.

p_i = y_i p_total

A pressure change shifts every partial pressure even if mole fractions remain temporarily unchanged.

Calculation case — atmosphere

Assume 70 kPa with 30% O₂ and 0.6% CO₂ in a teaching case. Partial pressures are 21 kPa O₂ and 0.42 kPa CO₂. If total pressure falls to 60 kPa with fractions temporarily unchanged, they become 18 kPa and 0.36 kPa. The same percentage therefore does not represent the same physiological state when total pressure changes.

Decision check. For atmosphere control, the practical test is to calculate at least one off-nominal state. Change total pressure, oxygen fraction, and CO₂ independently and observe which sensor would first show unacceptable conditions. That exercise prevents one “green” indicator from being mistaken for proof that the whole atmosphere is safe.

3. CO₂, humidity, and contaminants accumulate

Crew continuously produces CO₂ and water vapor. Removal systems need capacity for nominal operation, activity peaks, restarts, and some partial failures. Treatment flow must be compared with production flow.

Measurement is a barrier. A good scrubber with a bad sensor can allow silent drift. Calibration, redundancy, and cross-checks therefore belong to life support.

Water loop and losses
Water loop: collection, treatment, quality control, recovery and residual makeup.

Degraded mode

CO₂, water vapor, and contaminants are continuous source terms. Sizing must compare plausible maximum production with available removal and include regeneration, sorbent changeout, and maintenance intervals. Nominal capacity exactly equal to production leaves no margin for drift or an extra crew member.

dM/dt = génération − retrait

A large cabin or buffer can slow concentration rise without correcting the flow imbalance.

Drift case — contaminant

A loop generates 0.25 kg/h of an equivalent contaminant and removes 0.24 kg/h. The difference looks tiny: 0.01 kg/h. Yet it accumulates 0.24 kg in 24 h and 7.2 kg in 30 days. The exercise shows why flow balance must close at adequate precision and why a small persistent drift can become a slow emergency.

4. Oxygen, electrolysis, and Sabatier

Water electrolysis produces O₂ and H₂. Removed CO₂ can react with H₂ through Sabatier chemistry to produce CH₄ and H₂O; recovered water can return toward electrolysis.

CO₂ + 4 H₂ → CH₄ + 2 H₂O

Integration increases recovery but also creates interfaces. Safe design needs isolation so catalyst, compressor, or separator faults do not simultaneously compromise potable water and oxygen generation.

Safety reading

Oxygen can come from stored inventory, electrolysis, or a chain coupled to CO₂ processing. Each path has different dependencies on water, power, compression, and consumables. A safe architecture must isolate a failed subsystem without contaminating or stopping the entire loop.

2H₂O → 2H₂ + O₂ ; CO₂ + 4H₂ → CH₄ + 2H₂O

Stoichiometry gives ideal masses; it does not give electrical efficiency, purity, or catalyst life.

Material case — oxygen

In an ideal balance, electrolyzing 72 kg water yields 8 kg H₂ and 64 kg O₂. If the 8 kg H₂ feeds Sabatier with 44 kg CO₂, the reaction makes 36 kg water and 16 kg CH₄; only half the original hydrogen returns after re-electrolysis of that water. The loop therefore still has an open boundary that must be identified.

5. Water: understand the 98% milestone

NASA reported ISS ECLSS demonstrated about 98% total water recovery with the Brine Processor Assembly, compared with roughly 93–94% beforehand. The aggregate result does not mean every stream recovers 98%.

Teaching case: q = 20 kg/person/day gross processed flow. For 100 people, 2,000 kg/day passes through the model. At R = 0.98, makeup = 40 kg/day; at 0.94, 120 kg/day. Difference = 80 kg/day or 29.2 t/year.

M_makeup = q × N × (1 − R)

Exercise 5

For 1,000 people, q = 20 kg/day and R = 0.98: yearly makeup?

Solution : 400 kg/day × 365 = 146,000 kg = 146 t/year. q is a teaching assumption.

The 146 t/year result shows why 98% recovery is not autonomy. At 1,000 people the remaining two percent becomes a major logistics flow, and q must stay explicitly labeled as a teaching assumption.

Integrated case — 98% recovery does not eliminate losses

NASA demonstrated roughly 98% total water recovery on the ISS, compared with about 93–94% before the brine processor milestone. Use a teaching gross flow of 20 kg/person/day. For 20 people, gross flow is 400 kg/day. At 98% recovery, ideal makeup from unrecovered fraction alone is 8 kg/day or about 2.92 t/year. At 94%, it is 24 kg/day or 8.76 t/year. Four percentage points therefore change annual makeup by 5.84 t in this example.

Do not turn the teaching flow into a NASA requirement for a Mars colonist: 20 kg/person/day is only a loop-throughput assumption. Leaks, maintenance losses, rejected water, water embodied in processes or food, and contingency inventory sit outside that simple calculation. A headline recovery percentage never replaces a stream-by-stream balance.

20×20×(1−0.98)=8 kg/day; at 94%: 24 kg/day; annual difference = 5.84 t

System intuition

The ISS 98% milestone is demonstrated overall recovery in a specific architecture, not a promise that every Mars loop will lose exactly 2%. For engineering, convert the percentage into makeup mass, then add storage, quality control, maintenance losses, and outage scenarios.

M_appoint = q N (1−R)

The flow q must be defined: drinking water alone, total processed water, or loop throughput produce very different answers.

Logistics case — water

For 100 people, use a teaching processed flow of 20 kg/person/day. At 98% recovery, ideal makeup is 40 kg/day; at 94%, 120 kg/day. Over a year the difference is 29.2 tonnes. This does not define a real settlement flow; it shows the logistics sensitivity to a few recovery points at larger population.

6. Recovered water still needs qualification

NASA describes ISS processing with filtration, catalytic treatment, quality sensors, and reprocessing of unacceptable water. A recovery loop is therefore also a continuous quality-control system.

A false “good” sensor indication can be more dangerous than a filter that fails visibly. Sampling, calibration, acceptance criteria, and buffer storage limit propagation of one bad measurement.

Safe haven and degraded modes
Safe haven and degraded mode: sequence isolation, reserves, repair and return to service.

Quantified balance

Water quality is separate from mass recovery. A highly efficient loop that passes a critical contaminant is unusable. Define quality parameters, sampling frequency, sensors, confirmatory analyses, reprocessing capacity, and quarantine volume for suspect batches.

eau acceptée = eau produite ∩ critères de qualité

A compliant measurement does not prove every possible contaminant was measured; the control plan must connect risk with analytical method.

Qualification case — water

Imagine a processor producing 500 L/day while 2% of batches are temporarily off specification. Even with excellent mass recovery, operations need buffer volume to isolate, reprocess, or analyze those batches. If laboratory confirmation takes 12 h, the buffer cannot be sized only from average consumption.

7. Food and waste: partial closure

Food combines calories, protein, micronutrients, water, shelf life, and acceptability. Crops can supply fresh food and contribute to gas exchange without instantly removing food logistics.

Waste retains water, carbon, nitrogen, phosphorus, and materials. Recovery requires energy, reactors, sanitation controls, and maintenance. Optimum closure can remain below 100% when marginal recovery costs exceed its value.

Degraded mode

Food creates a trade among shipped mass, water content, nutritional stability, crew time, fresh crops, and waste. Plants can provide variety and micronutrients without making the habitat automatically calorie-self-sufficient. The balance must count lighting energy, water, nutrients, volume, maintenance, and crop losses.

m_aliment = m_sec /(1−f_eau)

Reducing food mass can shift demand into water or energy; the optimum must be judged at system level.

System case — food

A 2.0 kg/day prepackaged ration at 46% water contains 1.08 kg dry matter. At 30% water, the same dry matter would weigh 1.54 kg/day. Shipped mass falls by about 0.46 kg/day, but the water loop must supply more at use. The system boundary must move rather than counting the saving twice.

Decision check. Food also couples to waste handling. Packaging, uneaten material, plant residues, nutrient solution, and sanitation loads become flows that consume storage and processing capacity. A crop system that reduces imported food mass can still increase electrical load and crew time, so the trade must remain multi-resource.

8. Fire, depressurization, safe haven

Fire combines heat, smoke, and toxic gases; depressurization combines atmosphere loss with structural danger. Both can require leaving nominal operation locally through compartmentation, hatches, masks, extinguishers, reserves, and safe haven.

A safe haven needs independent air, water, power, and communications for a defined duration covering detection, isolation, diagnosis, and repair. Emergency consumables should not share the same failure path they protect against.

Safe-haven scenario — 72 hours without external resources

Imagine an isolated refuge for six people over 72 hours. Start with functions rather than an arbitrary mass: pressure, oxygen, CO₂ removal, drinking water, temperature, control power, minimum lighting, communication, medical care, and sanitation. Give each function a stock or capacity, margin, and exit criterion. A refuge is not merely a stronger room; it is an isolatable miniature life-support system.

For direct drinking water, if a teaching scenario assumes 4 kg/person/day, arithmetic baseline is 6×4×3=72 kg before margin. Adding 25% gives 90 kg. That mass does not include fire suppression or medical uses. A critical electrical load averaging 1.5 kW for 72 h requires 108 kWh useful; with an 85% storage chain, upstream stored energy is about 127 kWh. Two functions, two budgets, and two explicitly separate assumptions.

water = 6×4×3×1.25 = 90 kg; storage = 1.5×72 /0.85 ≈ 127 kWh

Safety reading

Fire and depressurization demand different responses in some respects: fire can require confinement, ventilation isolation, or suppression, while a leak requires volume isolation and pressure-loss management. A safe haven must remain habitable during repair without depending on the failure that triggered the emergency.

autonomie_refuge = stocks / consommation_mode_secours

NASA’s 30-day safe-haven concept is a studied architecture, not a universal duration; each mission must demonstrate its own recovery time.

Emergency case — safe haven

For eight people over 30 days, a 3 kW average vital load requires 2,160 kWh if no generation is available. With 80% usable stored energy and 90% conversion efficiency, nominal storage becomes 2,160/(0.8×0.9)≈3,000 kWh. The exercise separates useful demand, usable depth, and conversion loss.

9. Martian dust: measurable contamination

In July 2026 NASA established a preliminary requirement of 0.1 mg/m³ as a 24-hour average for Martian particles below 10 µm in specified exposure scenarios up to 30 days. Uncertainty remains because authentic airborne Mars dust has not been returned for full human toxicology.

At that concentration, 100 m³ contains 10 mg suspended on average. Small mass can still matter for fine-particle inhalation, so airlocks, suit handling, cleaning, filtration, and monitoring form layered control.

EVA scenario — dust, airlock, cross-contamination

NASA published in July 2026 a preliminary requirement for Martian particles below 10 µm: 24-hour time-weighted average below 0.1 mg/m³ for certain exposure scenarios up to 30 days. In a 150 m³ habitat that concentration corresponds to 15 mg of airborne mass at that average. A very small total mass can therefore matter when dispersed as respirable fine particles.

Contamination architecture aims to prevent dust from reaching habitable air: dirty and clean zones, suit cleaning, cleanable surfaces, filtration, measurement, and post-EVA procedures. Because authentic airborne Martian dust has not been returned to Earth, NASA explicitly describes uncertainty in the initial limit. Design should therefore preserve the ability to measure and revise rather than treating 0.1 mg/m³ as an immutable biological constant.

0.1 mg/m³ × 150 m³ = 15 mg
Redundancy and common cause
Redundancy and common cause: identify what can defeat two supposedly independent paths at once.

System intuition

Martian dust should be treated as a contamination flow: EVA ingress, deposition, resuspension, filtration, and removal. NASA’s new 2026 requirement provides a 24-hour average limit for particles <10 µm, while design must also address local peaks and toxicology uncertainty.

C_TWA = (Σ C_i Δt_i)/(ΣΔt_i)

An acceptable average can hide a large airlock peak; sensor location and sampling strategy matter.

Exposure case — dust

A 24-hour time-weighted average can combine 0.20 mg/m³ for 2 h near the airlock and 0.05 mg/m³ for 22 h. The average is 0.0625 mg/m³. It is below 0.1 mg/m³ in this example, but the 0.20 peak can still matter operationally and for sampling strategy.

10. Radiation, EVA, and return time

Background radiation and solar events create shielding and exposure-time problems. EVA adds vacuum, dust, fatigue, thermal control, and suit dependence. These risks belong in schedules and return plans.

A better-shielded zone and decision rules can support radiation events. EVA needs consumables margin and a return path after credible faults. Survival is partly management of available time.

Quantified balance

Radiation and EVA become a time-to-shielding problem. A distant sortie adds return delay, mobility dependence, and possible simultaneous failure. Procedures must connect forecast, alarm, distance, degraded speed, accumulated dose, and shelter capability.

t_retour = d / v_dégradée

Travel-time calculation does not directly convert a radiation event into dose; it defines the operational response window.

Return case — EVA

A crew works 24 km from shelter. At 12 km/h nominal, return takes 2 h. If a failure cuts speed to 6 km/h, return takes 4 h. An excursion rule based on nominal speed can therefore double exposure time precisely when degraded operation is required. Distance limits must use credible degraded modes.

Decision check. A return-time rule should be written for nominal and degraded mobility. If a rover loses half its usable energy or a wheel failure halves speed, the allowed excursion radius may need to shrink before the EVA begins. The rule is therefore an operational control derived from physics, not a fixed distance painted on a map.

11. Medicine and human factors

Earth-Mars delay prevents instant telemedicine. Crew must recognize, stabilize, and treat conditions locally. Medical capability depends on water, power, sterilization, pharmacy, cold storage, and waste.

Fatigue, sleep, conflict, and maintenance workload affect risk. Technical redundancy can still fail operationally if each fault consumes too many hours of scarce expert labor.

Degraded mode

Mission medicine must classify what can be diagnosed locally, what can wait for Earth expertise, and what requires immediate action. Medical inventory is therefore a portfolio of capabilities: drugs, consumables, sterilization, imaging, blood or substitutes, procedures, and human skill.

temps_clinique disponible < délai de communication ⇒ autonomie locale

Communication delay varies with geometry; the architecture must tolerate the range of delays and outages rather than one fixed value.

Clinical case — autonomy

A medical decision procedure requires four exchanges with an Earth specialist. At 18 min one way, a minimum question-answer cycle takes 36 min; four cycles can exceed 2 h 20 before human decision time. Any emergency with a shorter treatment window therefore requires local procedures, skill, and equipment.

Decision check. Medical autonomy can be decomposed into prevention, diagnosis, stabilization, definitive treatment, and recovery. Each layer has a different demand for training, consumables, sterile equipment, imaging, and communication. Mapping conditions to those layers is more useful than a single statement that the base “has a clinic.”

12. Redundancy and common cause

Two identical units sharing power or software are not independent barriers. Common power, contamination, configuration, or procedural errors can defeat both.

A degraded mode is deliberately less capable but stable: zones isolated, experiments postponed, consumption reduced. Defining these states early makes reserves and procedures concrete.

Safety reading

Useful redundancy separates causes. Two units on the same power bus, in the same dusty compartment, and running the same software can fail together. Diversity, isolation, independent monitoring, and repairability can matter more than unit count.

risque_système ≠ produit des risques individuels si causes communes

Independent probabilistic calculations are conditional models, never proof that common causes have vanished.

Common-cause case

Two backup pumps occupy the same compartment and share one controller. A liquid contamination event or software error can disable both. Adding a third identical pump in the same place increases component count without creating real diversity. The useful exercise is to identify physical or functional separation that breaks the common cause.

Decision check. A strong redundancy review also asks whether maintenance can create common cause. Two channels may be independent in normal operation yet become coupled when the same technician, calibration standard, software update, or spare batch services both. Configuration control is therefore part of resilience.

13. Scale: 4, 20, 100, 1,000 people

At four people, one unit and reserve may cover a function. At twenty, spares and maintenance shape organization. At one hundred, medical, workshop, water quality, and multi-zone redundancy become infrastructure. At one thousand, 2% of a large stream becomes hundreds of kilograms per day.

Larger population adds skills while also increasing networks, interfaces, and common-contamination consequences. A settlement is not a mission multiplied by one factor.

14. Integrated exercise: 72 h without water recovery

Scenario: 100 people, emergency net demand 4 kg/person/day, zero recovery, separate 1,500 kg reserve. Demand = 400 kg/day. Three days consume 1,200 kg, leaving 300 kg or 18 hours at the same rate.

The number opens the real questions: can demand be reduced, is reserve quality verified, can repair finish before the deadline, is reserve physically independent, and what nonessential loads shut down automatically?

Scaling — when a loop becomes infrastructure

With four people, a single device may be watched directly by the whole crew. At twenty, the system becomes a service with scheduled maintenance and dedicated spares. At one hundred, a loop failure can affect people who do not operate it; distribution, isolation, compartmentation, and documentation become central. At one thousand, multiple trains, strategic inventories, workshops, and specialist teams become plausible, while new common causes appear: shared software, shared power, shared filters, or shared metrology errors.

Scaling is therefore not simply multiplying power by population. Take a teaching pump MTTR of eight hours. One pump makes the function unavailable for those eight hours after a fault. Two genuinely isolatable trains can preserve partial service, but not if both are disabled by contaminated common water or the same electrical failure. Useful redundancy requires independence of failure causes as well as duplicated machines.

End-of-module project — seven days in controlled degraded mode

A 20-person base loses one water-processing unit and must operate for seven days on inventory and reduced capacity. The teaching scenario assumes 5 kg/person/day of direct non-deferrable need and 3 kg/person/day of deferrable use. Minimum vital requirement is 20×5×7 = 700 kg. Deferrable uses would add 420 kg. That separation immediately creates degraded-mode logic: 700 kg belongs to a vital function while 420 kg can be reduced or postponed according to the scenario.

Available inventory is 1,050 kg, of which 150 kg is reserved for medical and unforeseen events. That leaves 900 kg for routine operations. The 700 kg vital need leaves 200 kg, insufficient for all 420 kg deferrable uses. About 220 kg must therefore be rationed across seven days, or 31.4 kg/day. This does not mean people simply drink less; the scenario first reduces uses explicitly classified as non-vital. A safety rule emerges from the material balance before it becomes an organizational rule.

At the same time, the main CO₂-removal train is unavailable for ten hours while a backup provides 70% of nominal capacity. Without a detailed metabolic model, we do not invent a concentration. Instead, list the required information: CO₂ generation per person, habitable volume, ventilation, sorbent capacity, thresholds, and sensor dynamics. Knowing when the data are insufficient for a numerical answer is a safety skill. Inventing a metabolic rate merely to fill an equation would be less rigorous than declaring the missing input.

An unscheduled EVA then introduces a dust load. The base must isolate the airlock, clean the suit, monitor air, and replace a filter without shutting down the entire life-support system. Look for a common cause: if the same electrical bus feeds both main filtration and airlock filtration, one electrical fault can defeat functional separation. Redundancy on a diagram matters only when power, sensors, software, and consumables do not recreate a single failure point.

The final worksheet therefore has five columns: function, normal capacity, degraded capacity, buffer resource, and return-to-normal criterion. Water returns after repair and loop qualification; atmosphere after main train recovery and sensor confirmation; dust after cleaning, measurement, and consumable replacement. The project succeeds when the team can explain why the base remains inside a safe envelope for seven days, which activities are suspended, and which additional event would force refuge or evacuation.

FunctionNominalDegradedBuffer / decision
Water8 kg/p/d in this scenario5 kg/p/d vital900 kg routine +150 kg reserved
CO₂main train70% backupwatch trend, limit activity if needed
Dustairlock + filtrationlocal isolationfilter, cleaning, air check
Powerfull networkcritical loadsshed deferrable functions
vital need = 20×5×7 = 700 kg; routine stock = 1,050−150 = 900 kg

Corrected drill set — independent check

1. 20 people, 10 kg/day/person gross flow, 98% recovery: makeup?

Gross flow is 200 kg/day; 2% loss is 4 kg/day. Across 365 days that is 1,460 kg, for this teaching flow assumption and this loss mechanism alone.

2. Why may two identical filters fail to provide useful redundancy?

Shared power, software, consumable batch, or common contamination can disable both. Physical duplication must be paired with functional independence.

3. A 300 kg reserve is consumed at 25 kg/day. Endurance?

Twelve days if flow stays constant and all reserve is usable. Medical reserves or minimum tank thresholds would reduce available inventory.

4. What must be checked after a water-loop repair?

More than whether the pump runs: flow, pressure, leakage, sensors, water quality, and stable return to nominal operation. A life-critical function is qualified by useful output.

5. Why does dust connect health with maintenance?

It can affect human exposure, seals, filters, surfaces, sensors, and EVA procedures. Contamination barriers therefore span several systems.

Deep practice workshop

For each survival scenario, identify the life-critical function and its time margin first: how long before pressure, CO₂, water, temperature, or medical capability leaves the acceptable range? Then build the resource balance and recovery path. The solutions emphasize operational decisions: detect, isolate, enter a degraded mode, repair, and requalify.

1. Water at 98%

20 people, 20 kg/person/day, 98% recovery. Makeup?

Reasoned solution : 20×20×0.02=8 kg/day; 2,920 kg/year.

2. CO₂-equivalent drift

Production 4.0 kg/day, removal 3.95 kg/day for 60 days.

Reasoned solution : Accumulation=0.05×60=3 kg.

A daily mismatch of only 0.05 kg appears tiny, yet integration over sixty days creates 3 kg of unremoved CO₂. Habitats therefore track cumulative imbalance as well as instantaneous flow.

3. Partial pressure

70 kPa at 30% O₂.

Reasoned solution : 21 kPa.

4. Dust

0.1 mg/m³ in 120 m³ perfectly mixed volume.

Reasoned solution : 12 mg airborne at the stated average.

The 12 mg is airborne mass in 120 m³ at the selected average concentration. It does not specify distribution near an airlock, inhaled fraction, or an individual crew member’s exposure duration.

5. Safe haven

20 people, 30 days, 2 kg/person/day water makeup.

Reasoned solution : 1,200 kg makeup in this degraded-mode scenario.

The 1,200 kg comes from a degraded requirement of 2 kg per person per day for thirty days. A real safe-haven reserve also needs losses, medical uses, fire response, restart needs, and duration uncertainty.

6. Sensor vote

p=0.01 independent, 2-of-3 vote.

Reasoned solution : 3p²(1-p)+p³=0.000298=0.0298%.

Two-out-of-three voting greatly reduces independent one-percent errors, but the formula depends on that independence. Shared power, software, or calibration can fail all three sensors together and erase the theoretical benefit.

7. Delay

22 min one way: minimum question-answer loop.

Reasoned solution : 44 min before added decision or transmission delays.

Forty-four minutes is only the light-time round trip when each leg takes 22 minutes. A medical or engineering decision adds observation, human analysis, message preparation, and possibly another question cycle.

8. Combined-failure capstone

A 20-person base loses its main water processor for 72 h. Emergency mode recovers 90% of a 15 kg/person/day flow. What ideal minimum makeup stock is needed, and why is it insufficient for a procedure?

Reasoned solution : Deficit=20×15×0.10=30 kg/day, or 90 kg over 3 days. A real procedure must add margin, non-potable needs, fire and medical demand, startup, repair uncertainty, and the possibility that power or sensing fails too. Ninety kilograms is a calculation baseline, not a final safety reserve.

The 90 kg three-day deficit is the first line of a contingency budget, not the final reserve. The scenario also has to protect non-potable functional water and retain restart margin.

Additional advanced problems

1. Water buffer

Deficit 25 kg/day, repair estimate 5 days, 2-day margin.

Reasoned solution : Scenario minimum=25×7=175 kg.

2. Atmosphere

60 kPa, O₂ 32%. pO₂?

Reasoned solution : 19.2 kPa.

3. Dust TWA

0.2 mg/m³ for 2 h then 0.05 for 22 h. 24 h average?

Reasoned solution : (0.2×2+0.05×22)/24=0.0625 mg/m³.

The 24-hour weighted average is below the two-hour peak because the other twenty-two hours carry more weight. A compliant mean still does not describe a local peak or particle-size distribution by itself.

4. Safe-haven mini-project

8 people, 30 days, total vital load 3 kW average. Energy with no generation?

Reasoned solution : Crew count does not enter if 3 kW is already total load: 3×24×30=2,160 kWh. Efficiency, reserve, and peak power must then be added.

The 2,160 kWh assumes 3 kW is already the total safe-haven load. Population affects other consumables but not this multiplication; defining the boundary avoids counting the number of people twice.

Sources and references

The references document operational ECLSS, the water-recovery milestone, and the preliminary dust limit. Safe-haven budgets are sizing exercises rather than NASA operational prescriptions.