1. When the mission becomes improvisation

Jim Lovell and Jeffrey Kluger’s Lost Moon returns as the recalled work because the Apollo 13 mission was supposed to be a lunar landing and became a test of whether the spacecraft and its operators could adapt when the plan fell apart. The end-to-end mission simulation is the desktop’s Apollo 13 rehearsal: it proves that the platform and its operators can handle the plan and its deviations.

This entry defines success and failure for the end-to-end mission simulation test.

2. Minimum success

The end-to-end mission simulation passes if:

  • The platform completes the nominal one-year mission scenario without loss of critical functions.
  • Power, thermal, compute, storage, and communications budgets remain within design limits across all scenarios.
  • A single cell loss is absorbed by the remaining federation without data loss or service interruption beyond policy.
  • Ground-link degradation does not cause unrecoverable state or data loss.
  • Software updates apply and roll back safely without breaking integrated operation.
  • The platform returns to a stable state after each injected anomaly.

This minimum says the desktop can survive a representative mission and its expected perturbations.

3. Full success

A stronger result would add:

  • Margin remains after peak-load and long-eclipse scenarios.
  • Autonomous responses, such as workload migration or thermal shedding, occur only when intended.
  • Degraded-mode behavior is predictable and documented.
  • End-of-life predictions match the degradation models.
  • Simulation data supports claims of flight readiness and operational planning.

This stronger result supports a claim that the platform is ready for the real mission, not just the simulated one.

4. Failure modes

The test fails if any of the following occur:

  • A critical function is lost during a nominal or moderate-stress scenario.
  • A power or thermal budget is exceeded in a way that would damage hardware.
  • A cell loss causes cascading failures across the federation.
  • A software update bricks a cell or creates incompatible firmware versions.
  • A ground-link outage leads to unrecoverable state or data corruption.
  • The platform does not return to a stable state after an injected anomaly.
  • End-of-life predictions are inconsistent with the degradation models.

Each failure mode points to a mission-level fix: architecture, sequencing, margin, or operations procedure.

5. What this changes

  • The end-to-end mission simulation has clear pass and fail criteria.
  • The criteria separate subsystem survival from mission-level readiness.
  • The next entry will close the end-to-end mission simulation test arc.