Autonomy begins with knowing what must be stocked before failure occurs
A long Mars mission cannot order a critical component for next-day delivery. Transfer windows, transit time and the lack of rapid evacuation fundamentally change logistics. The settlement must trade redundancy, spare parts, raw materials, repair capability, local manufacturing and consumable reserves while avoiding enormous mass tied up in poorly targeted inventory.
Deep monograph
Deciding what deserves storage before counting kilograms
Deciding what deserves storage before counting kilograms.
Spares, logistics and strategic reserves — functional architecture showing the flows, interfaces and dependencies developed in the chapter.Conceptual internal logistics: stocks, spares and consumables must remain identifiable, accessible and quickly movable when a failure turns a theoretical reserve into an immediate operational need.
Martian logistics starts years before the crew arrives.
Prepositioning: sending survival options before people.
Inventory: knowing what exists, where, in what condition and for which version.
Criticality: not every part deserves the same kilogram of cargo.
Criticality: not every part deserves the same kilogram of cargo.
Criticality: not every part deserves the same kilogram of cargo. Who may modify spares?
Forecasting: failure rates, uncertainty and rare events.
Forecasting: failure rates, uncertainty and rare events.
Forecasting: failure rates, uncertainty and rare events. The observation chain for traceability must remain credible after stockout.
Commonality: one common part can replace several specialized inventories. The function “tools” interacts with traceability and prepositioning, while hazards inventory error and underestimated volume can cross disciplinary boundaries. Architecture comparison should test at least two responses: strengthen packaging or improve recovery through prepositioning.
Choosing repair level: box, board, component or raw material
Standardization: connectors, fasteners, voltages and interfaces
Standardization: connectors, fasteners, voltages and interfaces.
Consumables: filters, seals, lubricants, reagents and sorbent media.
Shelf life: long storage can degrade the backup before it is needed. Inventory traceability must survive periods when stored volume has been underestimated.
Packaging: the container is part of the survival system.
Distributed storage: do not lose every spare in the same fire.
Raw stock: bar, sheet, powder, polymer, cable and semi-finished seals.
Reproducible calculations specific to this subject
Expected failures in a fleet
μ = n × T / MTBF = 10 × 17 520 h / 4 000 h = 43,8
For ten identical units operated for two years, an MTBF of 4,000 hours gives about 43.8 expected failures under a simplified exponential assumption. Stock planning must then account for dispersion, criticality and repair options.
Whole module or repair parts
10 × 20 kg = 200 kg; 30 × 0,8 kg = 24 kg; écart brut = 176 kg
The example compares ten 20 kg modules with thirty 0.8 kg repair parts. The 176 kg saving is gross: tools, test equipment, skills, labor time and diagnostic risk must be added.
Consumable until the next window
M = 0,4 kg/j × 780 j × 1,30 = 405,6 kg
For a critical consumable used at 0.4 kg/day, 780 days of coverage and a 30% margin require about 406 kg. The number becomes most useful when compared with a repairable or locally manufactured alternative.
Cannibalization: useful in crisis, dangerous as a permanent model
Tools and documentation: reserve what makes the part usable.
Four people: high mass per person and little specialization.
Twenty people: central stores and first family-level inventories.
One hundred people: ABC policy, repair and local manufacturing.
One thousand people: warehouse network, local production and economic management.
Lost cargo: recalculating the mission around what is actually available.
Spares, logistics and strategic reserves — visual synthesis of the system-specific choices and constraints.Strategic reserve mass — scaling scenario: the quantity and unit are illustrative and are not a NASA requirement.
Four architecture scenarios that materially change the decision
The part exists but nobody can find it
The part exists but nobody can find it. The physical spare exists, but the digital inventory lost its location or compatibility after configuration changes. Martian logistics must guarantee identity, location, condition and applicability or stored mass is not real capability.
An entire batch becomes suspect
An entire batch becomes suspect. A failure reveals a potential defect affecting every item from the same batch. Counting ten copies as ten independent protections was illusory. The scenario requires batch traceability, quarantine and supply diversity.
The resupply window slips
The resupply window slips. A cargo mission is delayed and inventory coverage must last several extra months. Simple consumables, medicines, filters and wear parts do not share the same risk profile. The scenario tests strategic reserve and demand-reduction options.
Print it or carry it?
Print it or carry it?. A rarely failing part is heavy to carry but relatively simple to manufacture. The right choice depends on material, machine, metrology, manufacturing time and criticality. The scenario compares physical inventory with industrial capability rather than only two masses.
From mission manifest to a city strategic reserve
Single critical part: one kilogram can be worth more than a tonne of generic material.
Crisis reserves: separating normal operations from survival stock.
Data: every issue from stores improves the next forecast.
Data: every issue from stores improves the next forecast.
From mission to economy: when spares become a supply chain.
From mission to economy: when spares become a supply chain.
Martian logistics is a time problem: pipeline, uncertainty and launch windows
On Earth a shortage can sometimes be corrected in hours or days. On Mars the delay includes terrestrial production, integration, launch, transfer, landing and local delivery. Missing a launch opportunity can push arrival back by many months. Logistics should therefore be modeled as a pipeline with items already in transit, items waiting for launch and reserves already on Mars.
This timing changes safety stock. Thirty days of coverage means little when the next reliable replenishment is hundreds of days away. Levels should be linked to actual recovery time and loss-of-cargo scenarios. Low-mass survival parts can justify years of coverage.
Mission duration increases uncertainty. As mission duration grows, cumulative failure probability rises and it becomes harder to predict which part will be needed. NASA supportability studies identify spares logistics as a major challenge beyond low Earth orbit. Mars inventory planning therefore needs probabilistic analysis, updated reliability data and direct connection to real maintenance history.
Earth-Mars logistics is a pipeline, not a delivery service. On Earth, a stockout may sometimes be corrected in hours or days. For a Mars settlement, a needed part does not become available merely because it exists on Earth.
The chain includes detecting the need, deciding to buy or make, preparing and integrating cargo, launch, transit, landing, receiving and local warehousing. Each stage has its own delays and failure modes.
The key consequence is that stocks must be planned before the failure. Mars logistics is closer to managing an isolated industrial system than a continuously replenished warehouse.
Spares must bridge long resupply opportunities while absorbing uncertain failures. Reference for “Martian logistics is a time problem: pipeline, uncertainty and launch windows”: the image helps track components or stages without treating the illustration itself as evidence of maturity.
Classify inventory by function and criticality, not only by mass
A useful classification separates regular consumables, wear items, repairable components, line-replaceable modules, complete equipment and catastrophe reserves. Each follows a different model. A weekly filter is forecast from consumption; a rare controller from risk; emergency fire equipment from loss scenarios rather than average use.
Criticality should dominate price. A twenty-dollar part may stop life support while an expensive machine can wait months. A matrix of criticality × replenishment delay × failure likelihood gives a more useful stocking priority than financial value.
Several logistics families. ISS experience separates logistics into categories such as consumables, maintenance items, spares, outfitting, utilization/science and packaging. A Mars settlement adds industrial feedstocks, medical supplies, seeds, filters, catalysts and emergency reserves. Quantity is only part of the problem: each item has storage conditions, service life and sometimes expiration limits.
Strategic reserve versus working stock. Working stock supports normal operations. A strategic reserve should be consumed only under defined contingencies such as loss of a resupply campaign, failure of a local production plant, tank contamination, fire or prolonged isolation. The two should be physically and digitally distinguished so gradual consumption does not silently erase crisis margin.
Store reserves without creating one loss point. Distributing some vital stock across multiple compartments reduces the chance that fire, depressurization or contamination destroys equipment and its backup at the same time. Water, breathing resources, filters, medicines and critical electrical parts should be positioned against the physical hazard map.
Do not place the entire reserve in one location. A single strategic store can become a single point of loss. Fire, contamination, depressurization, inventory error or blocked access can make parts unavailable even though the database says they exist.
The most critical items may therefore be distributed across protected volumes. Dispersion costs space and inventory effort, but prevents one event from destroying both the primary system and its repair capability.
Classify parts by criticality, not only by price or mass. A tiny fastener can matter more than a tonne of bulk material if it blocks a life-critical function and has no substitute. Logistics priority should ask:
does failure threaten life immediately or mainly comfort?
is redundancy available?
can the part be repaired or made locally?
how many systems use the same item?
how long can it be stored?
what is the consequence of underestimating demand?
Repair, cannibalize or manufacture: three responses to one risk
When equipment fails, the team may repair a component, harvest a module from a less critical system or manufacture a replacement. These consume different resources: skill and time, loss of secondary capability, or feedstock and machine time. Good procedures prepare all three choices instead of treating cannibalization as an improvised failure.
The decision should remain reversible where possible. Stripping a rover to save a habitat pump may be rational, but the inventory must record the harvested parts and the capability lost. Otherwise the settlement accumulates invisible debt in partly dismantled equipment that can never return to service.
Repair, cannibalize, manufacture. A robust system supports several levels: module replacement, board or mechanism repair, controlled cannibalization of non-critical equipment, then local additive manufacturing or machining when material and drawings allow. Local fabrication does not eliminate all imported spares; advanced electronics, specialized sensors, medicines and certified materials may remain Earth-dependent for a long time.
Connect stock, repair and manufacturing: three answers to the same risk. For each critical item, three strategies can complement each other: stock a ready spare, repair a failed item, or manufacture a local replacement.
Lightweight parts that cannot be made locally may deserve large stocks. Heavy repairable parts may justify repair kits. Simple common components may be good candidates for local manufacturing.
The objective is to reduce the chance that one material reference turns a local failure into a settlement-wide crisis.
Cannibalization is not failure: it is a last-resort option to prepare. Cannibalization means removing a working part from a lower-priority or unavailable asset to restore a more important one. It reduces the number of complete systems, but can preserve a critical function.
To keep it controlled, compatibility and every removal should be documented, with a clear priority order for which equipment may become a donor.
MARS BIBLE — DEEP DIVE
Spare parts: autonomy begins by knowing what will fail before trying to manufacture everything. Evidence status: Documented facts + explicitly identified engineering extrapolation. Method and evidence levels →
A settlement does not become autonomous the day it owns a 3D printer. Autonomy grows by understanding failure modes, stocking what cannot yet be produced locally and expanding repair capability over time.
Classify spares by criticality. A light unique part may be more valuable than a tonne of common feedstock. Inventory planning therefore combines failure probability, consequence, Earth resupply time, repairability and available workaround. Specialized electronics, seals, sensors or bearings can be strategic despite occupying very little volume.
Repair, remake or cannibalize. After failure, a crew can restore the original part, manufacture a replacement or recover a component from lower-priority equipment. Cannibalization must be tracked carefully so that solving one fault does not silently create another unavailable system.
Additive manufacturing does not remove qualification. NASA studies polymer and metal printing to reduce spare-parts logistics. But reproducing geometry does not guarantee strength, leak-tightness or fatigue life. Critical parts require dimensional inspection, material traceability, possible heat treatment and appropriate testing.
Sometimes the best spare is a common standard. If ten machines use ten different pump or connector families, the settlement needs a larger inventory. Maintainable architecture standardizes interfaces, fasteners, voltages, sensors and motors so one reserve can support several systems.
Digital inventory must know condition, compatibility and shelf life
Knowing that a seal exists in a warehouse is not enough. Lot, age, material, chemical compatibility, storage conditions and shelf limits can matter. Electronics adds version, firmware and connector family; medicine adds temperature and expiry. Digital inventory is therefore configuration management, not merely a quantity spreadsheet.
Every movement preserves history. A part returned after test is not identical to a new one; a bearing harvested from a motor becomes risky if its service hours are unknown. Inventory is industrial memory.
Digital inventory and configuration control. Each critical item should be linked to location, compatibility, life limit, history, documentation and the tools needed for replacement. Part-number errors become dangerous when nearly identical versions are not interchangeable. Fleet configuration therefore needs the same discipline as inventory quantity.
Digital inventory: existence is not enough; condition matters. A useful inventory tracks more than quantity. For a critical item it may include location, compatibility, serial number, manufacture date, storage conditions, use history, inspections, shelf-life limits and calibration status.
Approved substitutions should also be recorded before an emergency: if item A is unavailable, can item B be used safely and under what conditions?
Calculate stock coverage: filters, bearings, medicine and consumables
A simple calculation makes policy visible. If a filter is replaced every 30 days and an habitat uses four, nominal demand is 48 filters per year. Adding 20 percent reserve gives about 58. Over three years the mass can become large, forcing a new question: stock finished filters, stock filter media, or manufacture some locally?
Bearings, seals and chemicals require similar calculations but failure demand is stochastic. Dust events may increase wear across several systems at once. A margin based only on average historical demand can therefore be inadequate.
Teaching calculation: filter-stock endurance
Deliberately simple scenario
Suppose one filter is used every 20 days on average and the base stores 12 compatible filters. If there is no recovery or manufacturing, theoretical coverage is 12 × 20 = 240 days.
This is not a 240-day guarantee. Contamination can increase consumption, several systems may share the same part, and stored filters can be damaged. The calculation converts inventory into coverage time and exposes the assumptions.
From 4 to 1,000 people: from mission manifest to maintenance economy
With four people logistics still resembles a mission manifest: nearly every object is known. At twenty, consumption and repair justify a technical store. At one hundred, inventory manages thousands of references, lots and workshops. At one thousand, logistics becomes an economy of local suppliers, service agreements, reuse, multi-site reserves and make-repair-import decisions.
Growth does not remove Earth; it changes what Earth supplies. Early missions import complete systems. Mature settlements can concentrate transport on medicine, chips, instruments or catalysts with exceptional functional value per kilogram. Logistics becomes one of the clearest measures of real autonomy.
Maturity level: separate demonstrated building blocks from settlement design
Established fact — technologies, methods or constraints are documented by space operations, tests, standards or primary technical work.
Prospective choice — the complete architecture, redundancy level, sizing and organization of a Martian city remain design choices that are not demonstrated today at city scale.
This system within the settlement. SYSTEM DEEP DIVE
Martian logistics must plan for failure before knowing exactly what will fail
To move beyond a descriptive fact sheet, we must follow inventories, criticality, interchangeability, storage, obsolescence, local manufacture and resupply delays at the same time. The subject becomes a chain of decisions: which function must remain available, which quantity reveals degradation, how much time remains before a dangerous threshold, and which alternatives truly exist locally?
A rare pump fails while three other machines use an almost identical electric motor: standardisation can turn an impossible inventory into a genuinely shared reserve. The scenario shows why nominal operation is not enough. A credible architecture must define decision thresholds, backup resources and the conditions under which the situation can be declared safe again.
Stock should be sized by failure consequence, replacement lead time and substitution options; simply counting parts does not measure resilience. This should be verified through representative tests, failure logs and procedures the crew can execute without hidden knowledge. Redundancy that has never been brought online under realistic failure conditions remains a promise.
A spare-parts strategy is judged by the time it buys after an unpredictable failure. Stock depth must therefore be tied to criticality, failure history, repair time and the next realistic resupply opportunity. A pump seal, control board or bearing can carry more operational value than a much heavier structure if its absence stops a life-support or production chain. Local fabrication changes the calculation only when drawings, feedstock, machine capability, inspection and acceptance criteria are all available. The inventory should distinguish items that can be repaired, items that can be reproduced, and items whose absence still requires an imported replacement.
Learning calculation: turn capacity into time or delivered service
LEARNING SCENARIO — a stock of 12 usable parts against average demand of 2 per day gives 12 ÷ 2 = 6 days of arithmetic coverage. Real logistics must then split that inventory by part number, criticality and reproduction lead time; six days on average can conceal zero days for the component that has actually failed.
The combined scenario that can invalidate the nominal calculation
For strategic reserves, the critical case is correlation between consumption and replacement capacity: several parts in one family become suspect while the tooling needed to reproduce them is unavailable. Nominal inventory then stops being a margin; planning has to count qualified parts, inspection capability and alternate manufacturing routes.
For spare logistics, recovery means the critical function is no longer hostage to one unavailable item: stock has been replenished or a qualified substitute exists, replacement lead time fits the degraded mode, and the next identical failure would not immediately recreate the same emergency.
Additional interfaces and boundary conditions
Inputs, outputs, dependencies and limits. ARCHITECTURE PROSPECTIVE DELTA-SIERRA / ARCADIA
Connecting this subsystem to a complete city. Arcadia's master plan is used as a systems-integration scenario. Its sizing and timeline choices remain prospective and are kept separate from demonstrated technology.
Spares are insurance against the tail of the failure distribution
The ISS can receive cargo and replacement hardware from Earth. NASA Mars-maintainability studies emphasize that this model does not transfer to deep space: required spares must travel with the mission, be pre-positioned or be repairable/manufacturable locally. Inventory therefore becomes a probability problem: how many failures, which ones, in what order, and which failures share a common cause?
Expected value is not sufficient inventory; it says nothing about dispersion or criticality.
An average cannot size the store room. Suppose for illustration there are 100 critical component types and a mean annual failure probability p = 0.02 per type. Over t = 5 years, expected failures are λ = Npt = 10. The symbol λ is the expectation in this simplified model. It does not mean ten spare parts are enough: repeated failures of one type, common-cause events and single catastrophic items all matter.
Inventory should therefore be layered. High-criticality, hard-to-make items are pre-positioned. Simple massive parts may be represented by qualified feedstock and design files. Repairable equipment needs seals, bearings, electronic modules and tools. Noncritical assets may become controlled donor systems. Cannibalization must be planned so that solving one problem does not quietly create the next.
Additive manufacturing does not eliminate inventory; it moves it into powders, wire, polymers, cutting tools, filters, nozzles, build plates and post-processing consumables. The settlement also needs validated process data and inspection. A printer without material or metrology is simply a different kind of dead stock.
Operational data should continuously change the spares model. If a nominal five-year pump develops repeated wear in eighteen months, the base should update failure estimates, inspections and preventive manufacturing. If another component proves exceptionally robust, later campaigns may reduce its reserve allocation.
The key measure becomes survival time without Earth. For every vital function: how long after the first failure, after the second, and after loss of the workshop itself? If all resilience depends on one machine tool, that machine tool is arguably the most critical spare on Mars.
Over time, logistics should evolve from a catalog of exact parts toward a library of repairable functions: common motors, bearings, seals, materials and interfaces that can rebuild multiple machines. That is the transition from Earth-catalog dependence to local industrial culture.
Inventory should change as the mission learns. Suppose one pump family suffers two early failures when the model expected almost none. That is not only an incident; it is evidence that the risk distribution was wrong. The base can increase inspections, limit duty cycles, manufacture parts preventively and reserve surviving units for vital functions. Conversely, five years of exceptional reliability can justify reallocating future cargo mass to other risks.
Standardization creates virtual spares. If ten systems share a bearing, motor, connector or power board, one inventory supports many functions. The gain has a cost: a common defect can now affect more equipment. Designers therefore need to choose where to standardize and where diversity is valuable. The objective is not one universal part but a small set of well-understood families.
The repair capability itself needs spares. Furnaces, printers, lathes, inspection equipment and workshop software are critical systems. Inventory therefore has a second layer: the parts that repair the machines used to repair everything else. This recursion is one of the boundaries between a supplied outpost and a genuinely industrial settlement.
A spares stock is a portfolio of physical risks. Two equal-mass parts have different value if one can disable a life-critical function and the other a secondary machine. Sizing should link failure rate, replacement delay, repairability, cannibalization and mission consequence instead of multiplying unit counts mechanically.
Local manufacturing changes this portfolio but does not erase it. It can reduce bulky simple spares while creating its own dependence on tools, feedstock, metrology and skills. Strategic reserves will often favor hard-to-produce, low-mass items that can restore several equipment families.
Spares should be designed as a risk portfolio. Carrying one copy of every part is neither sufficient nor necessary. An unreliable pump that can be repaired from simple components may require fewer complete spares than a highly reliable unit whose one proprietary control board cannot be reproduced. The decision combines demand frequency, criticality, Earth resupply delay, cannibalization options, repair duration, and local manufacturing capability. Low-mass, high-criticality items often justify multiple copies; large simple items may be covered more efficiently by feedstock and tooling.
Inventory must remain physical, not merely digital. Every withdrawal, cannibalization, repair, and downgrade changes the reserve that actually exists. A settlement that lists “two pumps” while one has been dismantled to recover a bearing no longer has two backup paths. Logistics therefore needs to connect configuration state, location, inspection date, and compatibility with installed versions. Over time, the most valuable reserve also includes drawings, software, tolerances, process recipes, and qualification procedures, because a substitute part only matters if the crew can prove that it can safely return to service.
A useful reserve policy separates demand uncertainty from consequence uncertainty. For some parts, failure frequency may be well known but the consequence of depletion is severe; for others, the failure rate is uncertain because the Martian environment has not produced enough operating history. The first case favors calculated stock depth, while the second may justify broader substitution capability, inspection, or redundant design. Bayesian updating is conceptually useful even without formal mathematics: every repair and every non-failure adds evidence that should change future procurement. A static list frozen before launch will gradually become less rational than an inventory policy that learns from the settlement’s actual fleet.
Commonality is another strategic lever. If five life-support assemblies use five different connector families, seals, controllers, and tools, the spare inventory grows even when each individual design is reliable. Standardizing interfaces can reduce the number of unique items and make cannibalization more practical, but excessive commonality can create a common-cause vulnerability. The best design therefore distinguishes interchangeable consumables and interfaces from critical components that benefit from diversity. Logistics becomes part of architecture: the settlement is easier to sustain when designers deliberately shape the demand that the warehouse will later have to satisfy.
Forecasting should include mission phase. The parts demanded during construction, early habitation, industrial expansion, and mature civic operation are not the same. A warehouse optimized for the first crew can become badly mismatched once the settlement adds greenhouses, machine tools, vehicles, laboratories, and public infrastructure. Replenishment plans therefore need to anticipate architecture changes rather than extrapolate the failure history of yesterday’s equipment indefinitely.
Sources and documentary findings
Deciding what deserves storage before counting kilograms: the references below are retained because they contribute a result, technology status or verification framework directly useful to this subject.
NASA Safety and Mission Assurance — Reliability and Maintainability
NASA's July 2026 advanced robotic-mobility studies also expose a logistics issue: a surface fleet consumes more than electrical energy. It consumes wheels, seals, actuators, sensors, lubricants, filters, diagnostic time, and workshop capacity. Speed and autonomy remain useful only if the spare-parts system can support them.
ERNEST's March 2026 desert field test is useful here as a logistics reminder: long-range mobility exposes wheels, actuators, batteries, sensors, and communications to failures far from the workshop. A credible fleet therefore sizes recovery, towing, critical spares, and diagnostics alongside speed and autonomous driving.