For the system engineer or AIT manager of a CubeSat: the satellite goes from simulation to flatsat to flight model, and the tests written first should not be rewritten at each step.
Repository: stellar-systems-eu/control-usecase-satellite-integration · Try it.
The satellite#
| Subsystem | Package | CSP address | Powered by |
|---|---|---|---|
| On-board computer | cubesat-obc | 1 | always on |
| Electrical power system | cubesat-eps | 2 | battery and solar arrays; switched channels ADCS, COMMS_TX, PAYLOAD, HEATERS, AUX |
| Thermal control | cubesat-thermal | 3 | heaters of four zones, on HEATERS |
| Attitude control | cubesat-adcs | 4 | ADCS |
| UHF transceiver | cubesat-comms | 5 | receiver always on, transmitter on COMMS_TX |
| Hyperspectral camera | hsc-100 | 6 | PAYLOAD |
Each subsystem is a catalogue of its own, as its supplier would deliver it. The platform
cubesat-6u imports their components (uses, from), and procedures address them under
their names on the platform: sat.eps.state_of_charge, sat.channel[PAYLOAD], sat.camera.mode.
See Importing Components.
Three stages, one topology#
| Environment | Target | Links | Rules |
|---|---|---|---|
SIM | sat-sim | simulated | no confirmation |
FLATSAT | flatsat-1 | CSP over CAN (bench interface), CSP over UHF (GSE radio, KISS) | hazardous commands confirmed by the operator |
FM | sat-fm-1 | CSP over UHF first, CAN umbilical for recovery | released packages only; operator then supervisor |
The links differ, the platform and the procedures do not. See Environments and Policies and Links.
The functional acceptance#
packages/sat-acceptance, Functional acceptance:
- Health of the platform: OBC and EPS answer, power budget (state of charge above 60 %), radio silent (transmitter off on the table).
- The payload chain, powered alone:
- ADCS on, detumbling then nadir pointing;
- heaters on, the payload bay above 15 °C;
- payload on;
- the camera's first light.
- Only that chain: the transmitter and the auxiliary channel never went on; the procedure checks it.
- Back to the safe configuration, in reverse order. On a failure,
if failedcuts the payload channel.
Transmitter test emits for a minute only after the operator confirms that an RF load is connected (enable_tx is hazardous). See Safety Rules.
stellar run --dry runs/acceptance-sim.yaml --repository . # in simulation, on your machine
stellar run runs/acceptance-flatsat.yaml # the same procedure on the flatsat
stellar run runs/acceptance-fm.yaml # and on the flight modelKnown limits#
- In simulation, a subsystem behind a switched channel of the EPS answers even with its channel off: the effects of a telecommand stay in its own component.
- The flatsat and the flight model need the driver of the satellite (or those of its subsystems, link by link) and the CSP over CAN transport: they are not part of the repository.