1. When the mission becomes improvisation
Jim Lovell and Jeffrey Kluger’s Lost Moon returns as the recalled work because the Apollo 13 mission was supposed to be a lunar landing and became a test of whether the spacecraft and its operators could adapt when the plan fell apart. The end-to-end mission simulation is the desktop’s Apollo 13 rehearsal: it proves that the platform and its operators can handle the plan and its deviations.
This entry defines success and failure for the end-to-end mission simulation test.
2. Minimum success
The end-to-end mission simulation passes if:
- The platform completes the nominal one-year mission scenario without loss of critical functions.
- Power, thermal, compute, storage, and communications budgets remain within design limits across all scenarios.
- A single cell loss is absorbed by the remaining federation without data loss or service interruption beyond policy.
- Ground-link degradation does not cause unrecoverable state or data loss.
- Software updates apply and roll back safely without breaking integrated operation.
- The platform returns to a stable state after each injected anomaly.
This minimum says the desktop can survive a representative mission and its expected perturbations.
3. Full success
A stronger result would add:
- Margin remains after peak-load and long-eclipse scenarios.
- Autonomous responses, such as workload migration or thermal shedding, occur only when intended.
- Degraded-mode behavior is predictable and documented.
- End-of-life predictions match the degradation models.
- Simulation data supports claims of flight readiness and operational planning.
This stronger result supports a claim that the platform is ready for the real mission, not just the simulated one.
4. Failure modes
The test fails if any of the following occur:
- A critical function is lost during a nominal or moderate-stress scenario.
- A power or thermal budget is exceeded in a way that would damage hardware.
- A cell loss causes cascading failures across the federation.
- A software update bricks a cell or creates incompatible firmware versions.
- A ground-link outage leads to unrecoverable state or data corruption.
- The platform does not return to a stable state after an injected anomaly.
- End-of-life predictions are inconsistent with the degradation models.
Each failure mode points to a mission-level fix: architecture, sequencing, margin, or operations procedure.
5. What this changes
- The end-to-end mission simulation has clear pass and fail criteria.
- The criteria separate subsystem survival from mission-level readiness.
- The next entry will close the end-to-end mission simulation test arc.