Stellar ControlMission control · by Stellar Systems v0.1.0

Use Cases

Satellite Integration

A 6U CubeSat described once, over CSP on the radio and the CAN bus: the same functional acceptance in simulation, on the flatsat and on the flight model.

For the system engineer or AIT manager of a CubeSat: the satellite goes from simulation to flatsat to flight model, and the tests written first should not be rewritten at each step.

Repository: stellar-systems-eu/control-usecase-satellite-integration · Try it.

The satellite#

SubsystemPackageCSP addressPowered by
On-board computercubesat-obc1always on
Electrical power systemcubesat-eps2battery and solar arrays; switched channels ADCS, COMMS_TX, PAYLOAD, HEATERS, AUX
Thermal controlcubesat-thermal3heaters of four zones, on HEATERS
Attitude controlcubesat-adcs4ADCS
UHF transceivercubesat-comms5receiver always on, transmitter on COMMS_TX
Hyperspectral camerahsc-1006PAYLOAD

Each subsystem is a catalogue of its own, as its supplier would deliver it. The platform cubesat-6u imports their components (uses, from), and procedures address them under their names on the platform: sat.eps.state_of_charge, sat.channel[PAYLOAD], sat.camera.mode. See Importing Components.

Three stages, one topology#

EnvironmentTargetLinksRules
SIMsat-simsimulatedno confirmation
FLATSATflatsat-1CSP over CAN (bench interface), CSP over UHF (GSE radio, KISS)hazardous commands confirmed by the operator
FMsat-fm-1CSP over UHF first, CAN umbilical for recoveryreleased packages only; operator then supervisor

The links differ, the platform and the procedures do not. See Environments and Policies and Links.

The functional acceptance#

packages/sat-acceptance, Functional acceptance:

  1. Health of the platform: OBC and EPS answer, power budget (state of charge above 60 %), radio silent (transmitter off on the table).
  2. The payload chain, powered alone:
    • ADCS on, detumbling then nadir pointing;
    • heaters on, the payload bay above 15 °C;
    • payload on;
    • the camera's first light.
  3. Only that chain: the transmitter and the auxiliary channel never went on; the procedure checks it.
  4. Back to the safe configuration, in reverse order. On a failure, if failed cuts the payload channel.

Transmitter test emits for a minute only after the operator confirms that an RF load is connected (enable_tx is hazardous). See Safety Rules.

Shell
stellar run --dry runs/acceptance-sim.yaml --repository .   # in simulation, on your machine
stellar run runs/acceptance-flatsat.yaml                     # the same procedure on the flatsat
stellar run runs/acceptance-fm.yaml                          # and on the flight model

Known limits#

  • In simulation, a subsystem behind a switched channel of the EPS answers even with its channel off: the effects of a telecommand stay in its own component.
  • The flatsat and the flight model need the driver of the satellite (or those of its subsystems, link by link) and the CSP over CAN transport: they are not part of the repository.

Stellar Control · v0.1.0

↑↓ to moveEnter to open