Electronics CAN Sources list

Compute Bay Housing and Wiring Plan v9.6

Nobotic USV // CD25D Conversion. What this document decides. The two-island power architecture, the isolation bridges between them, the SAFE_LIGHTNING response, and the surge doctrine. On those four subjects this plan wins over every other document. What lives elsewhere. Box-by-box implementation, the hole schedule for each box, part numbers, and the shopping list are in the Electronics and Wiring Plan v9.6, the implementation companion. Version history, decision records, and closed items are in the central Changelog. Terms used throughout.

TermPlain meaning
IslandA group of gear fed from one battery, with no wire path to the other group
Galvanically isolatedTwo circuits pass information with no metal path between them. The signal crosses as light, magnetism, or an electric field
NodeA small team-built box with a microcontroller in it
DiscreteA single on-or-off wire carrying one bit, not data
PoEPower over Ethernet: the network cable carries the device's power as well as its data
PoE classThe power level a PoE device asks the switch for when plugged in (802.3af up to 15.4 W, 802.3at up to 30 W). The switch sets that much aside whether or not the device uses it
SFP moduleA small plug-in module that turns a switch's SFP slot into a port. The copper SFP module gives an ordinary RJ45 jack, data only, no power
Web APIThe switch's own documented command interface over the network. A program on the Pi calls it to turn a port on or off
SNMPA standard way to read a network device's state over the network. On the TSW202 it is read-only: good for checking, not for control
H-bridgeA four-switch circuit that runs a DC motor in either direction
RS-232, RS-485Two wired serial standards most science instruments speak. RS-232 is one device per cable; RS-485 is a shared two-wire line

1. Summary

This document specifies the housing, power architecture, command architecture, and wiring plan for the vessel's compute, its team-built nodes, and the surge and lightning protections around them. The defining decisions:

2. Location and mounting

2.1 Why inboard, aft of the settee

Both boxes mount inboard, aft of the settee, on existing structure, a few feet apart. Zero hull penetrations. The location is chosen for lightning exposure. With strap down conductors running both port and starboard, an inboard mount:

All cable entries are on the bottom face, with drip loops hanging 3 to 4 in below the box. A drip loop is a downward sag in the cable so water runs to the bottom of the loop and falls off, instead of running along the cable into the box. Hanging 3 to 4 in keeps the low point of the loop below the connectors even at sustained heel.

2.2 Mounting the Pi B box

The Pi B box mounts rigid on the settee panel, through-bolted to the 3/16 to 1/4 in solid glass panel aft of the settee. No plywood pad.

The four holes join the shared drilling template. Coordinate with the bilge pumps. They mount on the other face of the same panel, on rubber isolation feet (the Gulpers thump, so bias them toward the Pi B side). Lay out both faces on one template so a pump foot never lands on a compute-box nyloc.

2.3 Mounting the Pi A box

The Pi A box trades some lightning distance for cooling. It is bonded to the hull skin below the waterline, placed aft of the settee and as far from both straps and bar runs as the space allows. The point is to pin one box wall near sea temperature. Bond method, in order:

  1. Grind the hull spot to dull glass.
  2. Sand the box back to bare aluminum and wet it out immediately. Aluminum re-skins with oxide in minutes.
  3. Bed in thickened epoxy, filling the hull curve void-free.
  4. Glass a tab around the perimeter.
  5. Add a strap, or bolts into a bonded pad, as the peel backup.

The CM5 heat block and its gap pad ride this back wall (sec 3.5). Bonds that carry heat (settled 2026-09-11). The bed under this box carries the CM5's heat into the hull, so it is thickened epoxy with a two-grit aluminum-oxide filler: coarse #46 or #80 plus fine #220 or #320, about 2:1, loaded to half the mix. Never 3M 5200 and never microballoons under a heat path. Wet both faces with neat epoxy first. Bond the flat bottom of a box, not a wall, and put the glands in the vertical side walls near the lid. Which other boxes go on the hull, the laminate thickness at the spot and the plate areas are still open (Pending Amendments v9.7), so the rest of this section stands as written. One conflict to settle with that open half: bonding the bottom face means the Pi A box's entries cannot all be on the bottom face as secs 2.1 and 8 say (decision open, Pending Amendments v9.7).

2.4 Condensation in the Pi A box

The Pi A box has a cold wall by design, so condensation is handled by design, not by desiccant:

Desiccant is a commissioning aid here, not the protection. That claim, and the humidity threshold that drives the CM5 duty, are to be checked on the bench with the box closed and the wall cold (Pending Amendments v9.7).

3. Enclosures

3.1 The boxes

Two identical CXCESNS aluminum junction boxes.

ItemSpec
Size11.8 x 8.3 x 3.9 in
SealingIP66, silicone gasket
Price~$66 each, Amazon

One drilling template serves both. Why aluminum. A strike drives tens of thousands of amps through the down conductors, rising in microseconds. A conductive enclosure weakens the magnetic coupling of that pulse into the wiring inside. The silicone gasket seam is acceptable because lightning energy lives below roughly 30 MHz, and at those frequencies the four lid screws tie the lid to the body often enough to work. Therefore: scrape to bare metal under the lid screws and at the bond stud. Bonding. Each box gets one 6 AWG bond spur to the lightning ground network under the substantial metal rule of the Lightning Ground System Guide. Main island box only. See section 5.2 for the backup island exclusion.

3.2 Sealed but not hermetic

3.3 The board plate

Inside each box, a 1/8 in (3 mm) G10/FR-4 plate carries all the boards. G10/FR-4 is fiberglass sheet, an electrical insulator.

3.4 Stacking rule for the CM5

Each CM5 stack is bolted through standoffs at every level: carrier, CAN HAT, and the LoRa bonnet where fitted.

3.5 Cooling the CM5

The heat path runs: SoC (the main processor chip), to thermal pad, to a flat aluminum block, to a gap pad, to the box wall.

3.6 Heat budget, and why Pi A is hull bonded

Heat load per box is modest: the Pi A box runs about 30 W with the SSD and the Hailo, the Pi B box under 5 W. That sheds to cabin air through a painted shell that runs 27 to 36 F (15 to 20 C) above cabin air.

Cabin airInterior resultVerdict
77 F (25 C)SSD near 117 F, CM5 near 136 FComfortable
113 to 122 F (45 to 50 C, sealed boat, tropical sun)153 to 162 FAbove the SSD comfort line, and near the CM5 throttle at 185 F (85 C)

That second row is why the Pi A box is hull bonded below the waterline (sec 2.3), with its CM5 heat path landing on the back wall. Build Guide sec 11.1 holds the pass/fail, in the compute-box thermal test: box interior at or below 122 F (50 C), with a 122 F simulated cabin and the hull spot held at sea temperature.

3.7 Fit check on arrival

Before anything else, offer the vertical carrier plus CAN HAT plus LoRa bonnet up against the box width, and check the bracket footprint.

4. Box contents

4.1 Pi A box (main island)

Pi A: CM5 on the carrier on hand, booting from its own onboard eMMC memory chip. Attached to it:

USB retention rule. The dAISy and the USB isolator hang no mass on their plugs.

Watchdog WD-A: Arduino Nano Every, powered from the main island. It watches Pi A's heartbeat and can cycle Pi A's power rail. It sends the "main island alive" discrete to WD-B through an optocoupler, which passes the signal across a gap of light so no wire crosses. GPS A: a hiBCTR NEO-7M module (bought 2026-09-09 in a 4-pack; two fly, two are Boat 2 stock), TTL serial at 3.3 to 5 V, SMA antenna, for position only. Single-band GPS with GLONASS, accurate to a few yards, which is all the boat needs. Only the antenna coax crosses the box wall. Heading comes from the BNO085 IMUs (three bought 2026-09-08) and the GPS track; the ZED-F9P moving-base heading pair is deleted. IMU A: BNO085, rigidly mounted. Storage: solid state only.

Power section: main island DC-DC regulation (24 V to 5 V, 5 A), TVS, INA226 current monitor on the feed, terminal strips. The box feed is one small branch on its own auto-reset breaker at the busbar (Electronics and Wiring Plan v9.6 sec 7.6); no blade-fuse block.

4.2 Pi B box (backup island)

Pi B: CM5 on its carrier with its own Waveshare 2-CH CAN FD HAT, fed from the emergency bank only, through its own DC-DC converter and TVS. Watchdog WD-B: Arduino Nano Every, powered from the emergency bank. It holds Pi B's rail, runs the duty cycle wake schedule, and owns the entire lightning role:

Pi B also carries a 250 GB NVMe SSD for its synced state copy, in the carrier's M-key slot (CM5 IO Board Rev 2). GPS B: the second NEO-7M module, emergency powered, with its coax entering this box, so the beacon role always has live position. IMU B: second BNO085. Inter-box link: only the main-island-alive discrete from WD-A, through an optocoupler. There is no heading UART between the boxes: the ZED-F9P moving-base pair is deleted, and heading comes from the IMUs and the track on each island by itself. Two of the four ADuM1201 isolators go with it; one stays in each box for its Iridium serial line. No secure element chip here either: the key is a file on the SSD.

4.3 The default-ON watchdog rule

Both watchdog rail switches, WD-A and WD-B, default ON. The pass element conducts while the watchdog is dead, and the watchdog must actively assert to cut or cycle its computer's power. A dead watchdog therefore leaves its computer powered. Bench check: pull the Nano out of its carrier and confirm the computer stays up.

4.4 What is deliberately NOT in these boxes

Not in the boxesWhere it lives
Central node (release channels, monitoring, the Ewellix steering drive and its power-cut relay, the 8-channel relay module of sec 11)One plastic box near the battery, busbars, and compute area
Release Node B (sec 12)The stern
Battery watchman (SBMS0 + JK balancer, on no bus; its EXTIO4 output pauses the five MPPTs through parallel VE.Direct remote cables, sec 9.2)The BMS box as bought, beside the battery box, referenced here, housed in the Electronics and Wiring Plan A4
FSESC boxDeleted at v9.4 with the backup rudder actuator (2026-08-27 single-actuator steering decision)
Aft junction (passive: post-cable terminals, the TSW202 switch and its 54 V supply, photocell and motoring-white relays)The stern
VESC A (VESC B and its phase-transfer contactor are Boat 2 only)Its own sealed enclosure on the cockpit web at the motor
Iridium modem ASmall box near Pi A, main bank
Iridium modem BSmall box near Pi B, emergency bank
AS3935 detector mini-boxWithin 3 ft of Pi B
Starlink electronics and antennaIts own mount; its Cat6 runs to the TSW202 at the stern
The PoE light driver (PoE Texas AT-LED-24V, bare board)A small dry box of its own, on TSW202 port 6

Full contents and every wall entry: Electronics and Wiring Plan v9.6 Appendix A.

5. Two island power architecture

The requirement: no single electrical event, in particular a lightning surge on the main rail, can kill both computers. Two things enforce it. There is no copper power path between the islands. And since the box split, no shared physical space either: each island has its own enclosure, computer, watchdog, GPS, and voice path.

5.1 Main island

Carries the 32 kWh main bank, Pi A, VESC A (VESC B is Boat 2 only), the MPPT bank, the central node and its relay module, the rudder actuator, and every normal load. Pi A runs the boat. The rudder actuator is one Ewellix CAHB-22 at the 12-in station: 10,000 N (about 2,250 lbf), 11.8 in stroke, 24 V DC, self-locking screw, built-in position feedback, no CAN. The central node drives it (sec 10.2). Single-actuator steering: no backup actuator, no FSESC, no encoder B, no pull-pins. It lives on the main island on purpose, fed and driven from the central node, a main-island box. [Boat 2 reference: the Thomson Electrak HD24B026 is a CAN device; an emergency-bank device on a CAN bus would tie the two islands together through its transceiver ground, which is the other reason steering stays on the main island.]

5.2 Backup island

The bank: a bought Dyness 24V 100Ah LiFePO4. 25.6 V, 100 Ah, 2,560 Wh, 42.6 lb, plastic case, built-in 100 A BMS with low-temperature cutoff, about $360. Charged by its own ~50 W panel through a dedicated SmartSolar 75/10. Changed at v9.2. This replaces the team-built 8x EVE LF50 in 8S with a JBD 60 A BMS, which was 1,280 Wh nominal. The bought unit is its own enclosure, so no box or gland list is drawn for it, and its plastic case cannot tie the floating emergency-island negative into the strike path. Build Guide sec 4.3 carries the restraint, terminal boots and 30 A ANL fuse. What it powers, and nothing else: the Pi B box (Pi B, WD-B, GPS B), Iridium modem B, and the detector mini-box. No steering actuator. No CAN device. No diode OR to the main rail. The one bridge: the Victron Orion-Tr Isolated 24/24 stays, as a float and monthly exercise path. It is transformer isolated, treated as sacrificial in a strike, and has no disconnect relay in its path. The floating negative. The backup island's negative is bonded to nothing. It touches the world only through its own solar panel, the isolated Orion, and the isolation bridges of section 6. Therefore the Pi B box gets NO ground network bond spur, ever. Its lid screws are its only lid continuity, and that is correct. This exclusion is repeated in the Lightning Ground System Guide so that a bond-everything instinct cannot violate it during the build. Operation. Pi B runs duty cycled, waking about 5 minutes per hour to sync state over Ethernet. WD-B can force it awake. If the main island is lost, Pi B runs a low power beacon over Iridium B with live GPS B position, indefinitely, on the emergency solar budget.

5.3 Backup island power budget

LoadDrawWh/day
WD-B (Nano Every + regulator)~0.3 W continuous~7
Iridium B, listen standby~0.2 to 0.3 W~5 to 7
Pi B, duty cycled ~8%~3 to 3.5 W awake~10 to 15
GPS B~0.3 W duty cycled with Pi B~1 to 2
Design point, normal operation~25 to 32
Post strike beacon modeduty cycled + few sessions/day~15 to 25

Checked against the installed hardware: the ~50 W panel harvests roughly 18 to 43 Wh/day in Southern Ocean gale conditions (peak sun hours 0.5 to 1.2, system factor K 0.72), and 54 to 90 Wh/day in a typical Southern Ocean summer. So solar carries the design point in nearly all conditions, and the bank on its own bridges well over two months of total darkness at the ~25 to 32 Wh/day design point (2,560 Wh nominal, roughly 2,300 Wh usable 90 to 10 percent). Updated at v9.3 for the Dyness bank. The old figure, one month, was computed on the superseded 1,280 Wh team-built bank.

6. Isolation bridges

The islands communicate only through galvanically isolated paths:

PathHow it is isolated
CAN, both busesEach HAT's onboard 5 kV isolation. Each bus is a separate barrier crossing
EthernetTransformer isolated per port by the standard. Each Pi runs its own Cat6 to the TSW202 at the aft junction. The switch may die in a strike, costing Starlink, the cameras and the Pi-to-Pi Ethernet, not both Pis; the CAN buses and the alive discrete still cross
Inter-box link (main-island-alive discrete only)One optocoupler on one M12 cordset. The heading UART and its two ADuM1201 isolators are gone with the ZED-F9P pair
Orion-Tr IsolatedTransformer isolated, sacrificial (sec 5.2)
StorageThe SSD attaches to Pi A only. Pi B keeps its own synced copy of essential state (position, mission phase, recent telemetry), refreshed over Ethernet each wake

What this does not cover. These bridges close the rail path only. Antenna line surge and ground reference shifts are handled by the surge doctrine (sec 14), the conductive enclosures, and the physical separation of the two Iridium chains.

7. Grounding and shields

Three different jobs share the word "grounded." They are not interchangeable.

  1. Chassis to lightning network. The Pi A box gets one 6 AWG Layer 2 bond spur to the nearest ground network point, on its own dedicated stud and nut, carrying nothing except during a strike. The Pi B box gets none (sec 5.2).
  2. Circuit ground to chassis: never. The main negative references the network exactly once, at the battery junction, per the Lightning Guide. One reference is the maximum. A second tie at a box would close a loop that strike current runs through the electronics. So: boards on insulated standoffs, and plates and boxes carry no circuit current.
  3. Cable shields. The CAN shield drain lands on the Pi A bond stud and nowhere else. Everywhere else shields float. At Pi B nothing conductive touches the wall at all: plastic glands and couplers, UTP Ethernet.

Commissioning check: on each CAN drop, meter continuity from the far shield end to the Pi A stud. Budget cordsets sometimes omit the shield entirely, and a shield connected at neither end is an antenna.

8. Wall penetration schedules

Rules for every entry, both boxes:

How each cable type gets in:

CableMethod
CAN dropThe male half of a cut Micro-C cable, plugged into the tee outside, glanded in
Point-to-point runOne Micro-C cable cut in the middle, glanded at both ends
EthernetIP67 RJ45 coupler
CoaxSMA F-F bulkhead

The tables below list the entries. Hole sizes, and the schedules for every other box on the boat, are in Electronics and Wiring Plan v9.6 Appendix A. Every gland is nylon IP68, as bought.

8.1 Pi A box (11 entries + vent + bond stud)

(The Electronics Plan A1 table is the hole-count authority. Entries 9, 10 and 14 are not drilled: the box switch is gone, so Pi B and Starlink run to the TSW202 at the aft junction, and the RTL-SDR whip is gone. Not yet in the count: the glands for the science serial leads from the USB hub, settled with the hub's location at fit-out; three more holes fit under the 14-hole cap.)

#EntryType
1Main island 24V feedGland
2CAN control drop (from the multiport)Gland PG7 (cut Micro-C drop; shield drain to the bond stud)
3CAN house drop (from the multiport)Gland PG7 (cut Micro-C drop)
4VESC A UART throttle + GPIO killGland PG7 (one Micro-C cut in the middle, glanded both ends), never shares a CAN cable
5Iridium A serial (Iridium A box near Pi A)Gland PG7 (cut Micro-C, isolated inside)
6Inter box link to Pi B (main-island-alive discrete only)Gland PG7 (cut Micro-C, optocoupler inside)
7SBMS0 USB, watchman telemetry (optional, else a plugged spare)Gland PG7
8Ethernet to the TSW202 at the aft junction (switch port 7)IP67 RJ45 coupler
9(not drilled at v9.6: Starlink now runs to the TSW202)-
10(not drilled at v9.6: Pi B now runs to the TSW202)-
11GPS A antenna coaxSMA bulkhead (verify SMA not RP-SMA); no arrestor, no bias tee
12dAISy AIS receive coax (its own below-deck antenna)SMA bulkhead
13915 MHz pod link whipSMA bulkhead
14(not drilled: RTL-SDR whip, gone)-

8.2 Pi B box (9 entries, entry 7 a blank spare)

(Numbered as the Electronics Plan A2 table.)

#EntryType
1Emergency bank feedGland PG7
2CAN control drop (Pi B, isolated HAT)Gland PG7 (cut Micro-C drop)
3CAN house drop (Pi B, isolated HAT)Gland PG7 (cut Micro-C drop)
4Iridium B serial (Iridium B box near Pi B)Gland PG7 (cut Micro-C)
5Inter box link (alive discrete from WD-A, optocoupler inside)Gland PG7 (cut Micro-C)
6AS3935 detector lead, 7-core, under 3 ft (to WD-B)Gland PG7
7(blank; spare)
8Ethernet to the TSW202 at the aft junction (switch port 8); a long run to the sternIP67 RJ45 coupler (plastic), UTP
9GPS B antenna coaxSMA bulkhead; no arrestor, no bias tee

Both boxes fit their entries on the 11.8 in bottom face in two staggered rows, holes on 1.2 in (30 mm) centres, plus the vent and stud. No load current passes through either box except its own feed. The switched loads and their harness live out at the central node and the aft junction. The boxes pass buses, radio, and coax only. Everything else on the boat lands on the central node, the aft junction, or a purchased controller.

9. Cabling and routing doctrine

9.1 CAN cable and topology

Cable: NMEA 2000 Micro-C (M12 A coded, 5 pin). 120 ohm impedance, a twisted shielded data pair plus a 22 AWG power pair in one jacket. Connectors: molded tees on the backbone, cut molded cables for the drops, and molded terminator plugs on the spare port of the tee at each physical end, nowhere else. Shield: grounded at the Pi A box only. Topology, per bus: one linear backbone. Stubs under about 3 ft. Never a star, never a ring. Speed: both buses run 250 kbps. Bus power: 24 V, injected once per bus from its own busbar branch, through a 5 A automatic-reset breaker (rated 12/24/48 V) at a tee beside the compute multiport. Never inject bus power from inside a Pi box, so that a Pi A fault cannot darken a bus. The pair carries roughly 1 A, and hungry loads have their own feeds.

9.2 Two buses

Control bus:

House bus:

Release Node B is on the house side deliberately, so no single bus failure can strand both release nodes. [Boat 2 reference: the house bus on Boat 2 also carries the backup VESC with its phase-transfer contactor, and the Electrak steering actuator (J1939) rides the control bus. Boat 1 sails with one VESC; propulsion loss is a schedule delay because the wing sails the boat.] On no bus at all: the battery watchman (SBMS0 + JK balancer in the BMS box as bought, beside the battery box; housed in the Electronics and Wiring Plan A4, referenced here). Its optional USB lead goes to Pi A; no CAN, no RS-485 from the BMS. The watchman has one hand: the charge pause. The SBMS0's EXTIO4 output drives five Victron VE.Direct non-inverting remote on/off cables (ASS030550320) in parallel through a 1k 1 W resistor. It pauses all five chargers on a high cell, on a pack below 32 F, or on its own power loss. A dead SBMS0 pauses charging for at most 10 minutes; then charging continues. The node's charge-continue bypass (relay channel 8, sec 11) closes when the watchman stream has been quiet 10 minutes with the pack above 32 F, and opens again when the stream returns. It controls no load, and the Pi never controls charging. The five MPPTs' own lithium profiles (absorption 27.6 V, float 27.0 V, temperature compensation off, RX pin set to "Remote on/off") stay as the backstop. The telemetry stream needs the Electrodacus WiFi/USB add-on board (ordered). Wiring detail: Electronics and Wiring Plan v9.6 sec 6.7. The rules. Devices have one CAN port each and live on exactly one bus. Only the Pis touch both, and cross-bus information moves through Pi software. Why split at all. Containment. A babbling device failure, likeliest on the house side, cannot delay steering or throttle traffic. The software cost is near zero: Linux presents can0 and can1 identically, and each device gets a one-line routing table entry.

9.3 Loop area rules

Induced strike voltage scales with the area a circuit encloses and how close it runs to the down conductors. So:

9.4 Ferrites

A ferrite is a clip-on magnetic collar that soaks up high-frequency surge current riding on a cable. Material: genuine mix 31 only. Fair-Rite 0431 series or Palomar 31-xxx. The anonymous kits are the wrong material, and lightning lives below 30 MHz where only mix 31 works. Placement: one per cable, per box wall crossing, outside the box just below the entry. Sizing:

CableCore ID
Micro-C, Cat6, coax0.30 in
12 to 8 AWG feeds, or a two-pass loop of a small cable0.5 in
The three bundled phase leads at the VESC1.0 in

A core must never hang on its cable. A core swinging below a gland fatigues the cable at the gland lip. Instead:

Keep cores off the hull skin and away from the lightning straps. About 60 ferrites boat wide. Counts are in Electronics and Wiring Plan v9.6 Appendix A. Ferrites have no failure mode.

10. Command architecture

10.1 The four patterns

Every commandable device on the boat uses exactly one of four patterns.

#PatternHow it worksWho uses it
1CAN with a translator nodeThe device is dumb (burn wire, solenoid, relay coil, DC motor) and the central node drives it by plain wireRelease channels, switched loads, the Ewellix steering actuator
2CAN nativeThe controller is built into the device and the Pi talks to it in its own dialectVESC A in VESC format; the em-trak in NMEA 2000 (Boat 2's Electrak in J1939)
3Direct lineData-heavy conversations on private serial, USB, or EthernetIridium x2, dAISy, GPS, Starlink, the PoE cameras, the TSW202 (Web API out, SNMP back), the science instruments on FTDI serial, and the optional SBMS0 text stream
4Radio915 MHz LoRaThe wing pod only

The watchdog relationship points the other way. Each Pi reports heartbeats, and the watchdogs hold the rails. The command philosophy. The Pi sends intentions. Devices execute mechanics. Every device has a designed answer to command silence:

DeviceAnswer to silence
Ewellix steering actuatorThe self-locking screw holds position; the drive is de-energized
FSESCBox dead means phases shorted [Boat 2 reference / superseded for Boat 1 at v9.4 - no FSESC on Boat 1]
VESCRamps to zero
Release channelsStay disabled: enable relay open, every MOSFET off (the burn-wire short relays are DELETED at v9.5)
Wing podHolds trim, then feathers on timeout
Switched-load relaysDe-energize with the node (sec 11)

10.2 Node platform

Two nodes are team built: the central node, specified here, and the minimal Release Node B at the stern (sec 12). The processor. The central node runs on one microcontroller: an STM32 G4 on a NUCLEO-G431 (KB or RB, whichever is bought; the RB is on the bench; about $11), sitting in a Nano screw-terminal carrier with a CAN transceiver breakout. Chosen for CAN on the chip itself and the most mature embedded Rust ecosystem (Embassy), which matches the team's stack. The expander. The node needs more pins than the 22 on the Nano header, so one MCP23017 I2C expander board, screw-terminal version (~$6), joins the Nucleo. An I2C expander is a small chip that adds 16 on/off outputs over the Nucleo's two-wire I2C link. It drives ONLY the convenience outputs: the switched-load relays and the charge bypass (sec 11), and the steering power-cut coil. Every release channel and the enable relay stay on native Nucleo pins, so the expander is never in the release chain. If the expander or the I2C bus dies, its outputs go high-impedance: the loads drop out (same as a dead node, already accepted) and the steering power-cut relay de-energizes to CLOSED, so steering keeps its feed. Pull-down resistors on the expander outputs under the terminal screws, so a reset reads as OFF. Pin budget: 17 of 22 Nucleo pins used with 5 spare before the Ewellix; the reversing drive's two direction lines and its current-sense and position-feedback inputs come off native pins, never the expander. Recount at firmware time. The alternative, a Nucleo-64, gives 50 I/O but does not fit the Nano screw carrier and its extra pins are on bare 0.1 in headers, which the no-push-on-jumpers rule forbids in release logic. Everything else is bought or passive. The TSW202 and the relay boards need no node at all. The aft junction is a passive terminal box. The Ewellix steering actuator is a plain DC device driven from this node (below). [Boat 2 reference: the Thomson Electrak takes position commands over J1939; an FSESC drove the backup rudder motor and read encoder B.] Nothing inside the central node is soldered. All on DIN terminals, pre-mounted, the same circuit as section 10.3:

Not in the box: burn-wire short relays, branch current meters, a VE.Direct reader board (the five MPPT VE.Direct ports carry the charge-pause cable instead, sec 9.2). Every logic line between the Nucleo and the relay, MOSFET, and opto boards lands under a screw terminal or a latched connector. No push-on jumper pins anywhere in release logic. Board preparation, in order:

  1. Buy it with a spare.
  2. Run a week of powered burn-in.
  3. Run a thermal cycling screen.
  4. Conformal coat it.
  5. Stake it in its carrier, after burn-in.
  6. Seal it in its box.

Steering command paths.

Wing pod computer. The same STM32 platform (NUCLEO-G431, KB or RB), hosting an RFM95W radio module. The trim actuator is the Thomson Electrak MD, CNO control option (MD24A025-0050CNO): the pod talks J1939 CAN to it through the G431's own CAN and the same CAN transceiver breakout used at the central node, with 120 ohm terminators at each end (control PGN 61184; status PGN 126720 every 100 ms). This short pod CAN never touches the hull buses. The MD sleeps under 2 mA, so its 24 V feed is not switched. The MAX3485 breakout stays in the pod for one job only: the wing-tip wind sensor, the Calypso ULP CMI1017, is RS485 (allocation: CMI1017 at the wing tip, CMI1018 UART/I2C on the post to the central node).

10.3 Release node channel recipe

One solenoid channel, repeated per channel on both release nodes, built entirely from screw-terminal modules. The power path:

  1. Fused feed (Littelfuse FHAC0002ZXJ holder, ATO fuse).
  2. To the enable relay, one channel of a 24 V 8-channel relay module.
  3. To the release bus terminal strip, which is dead until enabled.
  4. Release bus to solenoid positive.
  5. Solenoid negative to a dual-MOSFET switch module load terminal. Low-side switching, 3.3 V logic input driven directly by the STM32 pin, with signal ground accompanying it.
  6. A 1N5408 flyback diode across the solenoid terminals under the screws, striped end to positive.

Burn wire channels add nothing (v9.5). The normally-closed short relays across the burn wires, and the daily continuity check they carried, are DELETED at v9.5 (GPIO review, Mike 2026-09-05) on both nodes; the v9.4 addition of both to Release Node B is reversed. The release bus is already dead until the enable relay closes, and each channel also needs its MOSFET on. Two conditions remain; the third is dropped. Nothing checks the burn wires between launch and use. Confirmation microswitches are DELETED at v9.5. Drogue deployment is confirmed by the speed drop and the aft camera only; the node knows what it commanded, so relay-state readback is gone too. All landings on Dinkle DK2.5N DIN rail terminals. Release sequence (renamed at v9.4: ARM is now ENABLE, FIRE is now RELEASE - fire is a bad word on a boat):

  1. A signed ground command arrives.
  2. Pi sends ENABLE.
  3. Node closes the enable relay and reports.
  4. Pi sends RELEASE, channel n.
  5. Node raises the gate and reports (no short to open and no confirmation input at v9.5).
  6. The enable timer expires and kills the bus.

Channel assignment across the two release nodes:

NodeChannels
Release Node B (stern)The drogue horn-B channels only (sec 12)
Central nodeThe four JSD release actuators and the drogue horn-A channels. Channels 7-9 are reserved for Boat 2's aux rudder, unwired on Boat 1; the pull-pin channels 10-15 and the trim-decouple channel 16 are retired at v9.4

The full channel map is owned by Electronics and Wiring Plan v9.6 sec 4.3. Open selections: the pull solenoids (stroke and force come from pin geometry at fit out), and burn wire gauge (settled by the required bench trigger campaign).

11. Distribution switching

This section owns the switched-load channel map. The Electronics and Wiring Plan, the Box Wiring Sheets, Node Boxes Explained, the lid labels and the firmware all follow this table. The switched loads run on a 24 V 8-channel relay module in the central node, driven through the node's MCP23017 expander (sec 10.2). Five of the eight channels carry switched loads (1, 2, 4, 6, 7). Channel 8 is the charge-continue bypass. Channels 3 and 5 are spare.

#ChannelNote
1Starlink power
2Science payload groupConfirm podlink does not already own that switching
3SPARE (was the PoE switch)The TSW202 is the boat's only network switch. It is always on from the house branch, never on a relay: shedding it would blind Starlink and cut the Pi-to-Pi Ethernet in one act. Camera power saving is per-port PoE control on the switch (Electronics and Wiring Plan v9.6 sec 6.1)
4em-trak AIS transponderOn demand, through its normally closed contact so it fails ON. The dAISy receiver is always on, unswitched
5SPARE (was the white strobe, deleted: not a legal navigation light)
6Bilge pump manual-onDrives the primary pump only; the backup pump stays on its Water Witch alone
7The two all-round motoring whitesThrough a 30 A relay in the aft junction
8Charge-continue bypass: battery + through a 1k 1 W resistor to the VE.Direct yellow bus in the watchman boxClosed by the node after 10 minutes of silent watchman stream with the battery probes above 32 F; opened when the stream returns. A dead watchman never stops charging for more than 10 minutes

The loads reach the aft junction on five 16/2 duplex runs through two PG13.5 glands at each end (three and two per gland). Fit-out flag: which physical relay is the enable relay. The release-bus enable relay (sec 10.3) is drawn on the Box Wiring Sheets as the first relay of this same 8-channel module, which cannot be right while channel 1 is Starlink. Settle it before the lid is labelled: the enable relay takes one of the two spare channels here, or its own 30 A single-channel module as Release Node B already has. The channel numbers in this table do not move (Pending Amendments v9.7). The nav lights proper are not on this board. Red and green side lights and the stern light run on a hardware dusk-to-dawn photocell relay in the aft junction, with no computer in the loop. There is no Pi backup channel and no current sense on the light circuit: the photocell relay is hardware only, and the cameras show the lights. There is no current telemetry on these channels. The INA226 on the Pi A box feed is the only branch meter left. Both Iridium modem feeds are hard wired always on, never switched, so no distribution failure can cost the voice. Pi rail switching belongs to the watchdogs, never this board. Failure posture, stated honestly:

That is acceptable because propulsion, steering, the battery watchman, the bilge pumps (they run on their own Water Witch switches; only the manual-on override for the primary pump is on this board), the nav lights, the network switch, and Iridium never ran through this board.

12. Release command authority

Every release path is three things in series: the command source, then a separate enable relay that is energized only during a valid enabled window with an automatic disable timeout, then the release driver. Two independent faults are required to release. Release circuits read shorted when idle. Two nodes carry the release channels. The central node (sec 10) carries most of them. Release Node B, a second minimal node, sits at the stern on the house bus with its own fuse. It carries the drogue-lid horn-B channels only, using the same enable-then-release interlock. Its shape: enable relay B, MOSFET channels for horn B of boxes 1 and 2, CAN with a DIN-rail surge module on the drop, five Nucleo pins, no opto board, no short relays. The detail is in Electronics and Wiring Plan v9.6; this plan keeps the architecture statement. Authority by channel:

ChannelAuthorityWhy
JSD deploy (burn wire cone exit)Signed ground command only. No autonomous pathDeployment is forecast driven with hours to days of lead, and the dual always-on Iridium chains exist precisely so the command link is never lost
JSD release (T8 fid pull)Signed ground command only. Never autonomousIrreversible, and there is zero time pressure on the drogue. It fails toward held: the self-locking screw cannot back-drive, so power loss leaves the drogue attached
Steering pull pins and aux rudder release [Boat 2 reference / superseded for Boat 1 at v9.4 - no pins or aux rudder on Boat 1]Per the existing three-path designs, same enable-then-release interlockAux rudder deployment is never autonomous, per Routing Guide 11.4

13. Autonomous lightning safing (SAFE_LIGHTNING)

A nearby storm detector triggers an autonomous protective response. The response is tiered, distance based, and tunable from shore. Storm intensity is deliberately ignored. Damage risk is set almost entirely by how far away the stroke is. A weak cell overhead is more dangerous than a violent squall line 19 miles (30 km) away.

13.1 Detector and triggers

The sensor: an AS3935 Franklin sensor on a SparkFun SEN-15441 breakout, alone in a tiny plastic box within 3 ft of the Pi B box, touching no metal. It runs on a 7-core lead (3.3 V, ground, I2C, interrupt) to WD-B, which powers it from the emergency bank. Range is about 25 miles (40 km), with a distance estimate per stroke. Why it sits outside the aluminum boxes: the boxes shield the very signal it is listening for. Why it sits as far from the VESCs as the lead allows: motor controllers are the classic false-trigger source. Bench-check the false-trigger rate with VESC A running before committing to the location. If it is bad, move the sensor forward on a small node with an isolated transceiver. Reporting: WD-B publishes rich data on the bus when the Pis are awake, and always keeps the alert itself. Triggers. All thresholds are settable by signed ground command:

ConditionResponse
Activity beyond the trigger radius (default about 9 miles, 15 km)Logged and warned, but ignored, regardless of intensity
Multiple strokes with decreasing distance inside the trigger radiusStart the safing sequence
Any single stroke inside the close radius (default about 3 miles, 5 km)Trigger immediately

13.2 Safing sequence and recovery

The sequence, in order:

  1. Send a short "going dark" Iridium message with position and cause.
  2. Command the wing pod to hold current trim.
  3. Sync state and flush logs to the SSD.
  4. Command zero throttle.
  5. Power down both Pis through the watchdog rails.

The Iridium stubs are the only coax protection during this. The boat keeps sailing while dark. The rudder holds its angle on the brake and the wing continues self trimming at held tab, so the boat keeps making way, wandering some in heading. The pod's own link-loss rule is to hold trim for a settable window (default 60 to 90 minutes) and then feather, so an abnormally long outage still ends in the passive state. What stays awake: WD-B and the detector, drawing under half a watt in total. WD-B treats commanded-off rails correctly by construction, suppressing heartbeat expectations until re-power. Recovery is adaptive, not a fixed timer. WD-B re-powers the Pis when either no stroke has been detected inside the trigger radius for a settable window (default 10 minutes), or the distance trend is receding, whichever comes first. The boat then resumes active sailing immediately. Expected cost. A typical cell passage costs roughly 15 to 25 minutes dark. With the lightning climatology routing layer, events concentrate in the ITCZ crossing days, and expected total downtime over the voyage is tens of hours.

13.3 Hardware and exclusions

Net new hardware is the detector mini-box. Nothing else. There are no coax safing relays. The two Iridium chains rely on their quarter-wave stub arrestors alone, which have no sacrificial element; the post-strike check is a DC-short reading on a meter. Starlink is sacrificial. AIS is entirely below deck. The two GPS chains are each other's redundancy. Deliberately excluded from the shutdown:

Never touched by any mode: bilge pumps, Water Witch paths and the battery watchman. (No gas sensors: deleted, do not re-propose. The cell-temperature trip on the pack probes is the battery trip.)

14. Surge protection doctrine (Layer 3)

Rule zero: no relays. Then four rules:

  1. Nothing sacrificial on a survival channel. Stubs or isolation only.
  2. Gas discharge tubes only where they age open and sit behind redundancy.
  3. MOV-class clamping only as thermal disconnect modules. Never bare. Plain modules, no status contacts, no remote signalling: nothing can be done about a burnt clamp at sea. Every clamp is checked with a meter at each refit and at the post-strike check (Lightning Ground System Guide v9.6 sec 7.6).
  4. Convenience channels may be declared sacrificial outright.

A few definitions, since this section is dense with them:

TermPlain meaning
TVSA fast clamp diode that catches a small spike and holds the voltage down
MOVA ceramic block that dumps a large surge, and wears out doing it
SPDAny surge protection device, used as the general word
Quarter-wave stubA shaped piece of coax that shorts lightning frequencies to ground while passing the radio signal. Nothing in it can wear out

The survival channels carry quarter-wave stubs, which cannot wear out. SAFE_LIGHTNING still powers the computers down for the storms seen coming. Everything below is for the strike that arrives anyway.

14.1 By conductor

Iridium A and B coax: Fairview FMSP1066 stub arrestors, two on hand (a PolyPhaser TSX-NFF is also on hand). No failure mode. AIS: no arrestor and no changeover relay, because nothing AIS is above deck. The em-trak transmit whip stands under the panel-free deck patch, and the receive antenna is short and below deck. The deck itself is the shield, and the receivers are cheap. GPS coax, both chains: no arrestor and no bias tee. A plain stub is impossible because the receivers feed DC up the coax to their active antennas. DC-pass gas tubes are rejected outright: a gas tube that fails shorted silently kills its antenna for the rest of an unmanned mission while still looking healthy. That is exactly the failure this doctrine forbids on a channel the boat cannot inspect. The protection is instead the two independent chains (different receivers, antennas, and boxes), the ferrite at the wall, and the low cost of a receiver sitting behind a Starlink GNSS cross-check. (The Electronics and Wiring Plan v9.6 sec 6.6 and the Lightning Guide follow this rule; the earlier stub-plus-bias-tee text there was stale.) Starlink and cameras: declared sacrificial, no arrestors. Ethernet transformer isolation is the box-side boundary. CAN, both buses: TVS on the HATs. At the central node and Release Node B drops, a Taidacent RS-12V/2S DIN-rail surge module (two on hand) in place of SM712 chips. Iridium serial runs: digital isolators at the compute boxes. For data lines, isolation beats clamping, and it matches the island discipline. VESC UART and kill pair: unprotected, by choice (Mike, 2026-09-07). Battery bus, the graded MOV ladder: four MOV thermal disconnect modules, clamping classes laddered at approximately 35, 40, 45, and 56 V DC, all above the 29 V charge ceiling.

Solar strings: PV-type SPD modules, Type 2, thermal disconnect (Phoenix Contact or Citel class, roughly 100 to 150 VDC rating), plain, no remote signalling. One per hull entry; no contacts land on the central node. Behind them the MPPTs remain fused per branch and semi-sacrificial by architecture. Backup island: its own TVS at the Pi B DC-DC, at the WD-B regulator, and on the detector lead, all referenced to the island's floating negative, never to the ground network. Remote driver boxes: TVS on each power input. Release release lines need nothing extra, because normally shorted is its own protection.

14.2 Beyond components

Ranked levers that add no failure-prone parts:

  1. Routing (sec 9.3) attacks induced energy before any clamp has to act.
  2. Lightning climatology joins the ERA5 routing pipeline, so the ITCZ crossing longitude is chosen against satellite flash density. This is the largest single exposure lever available.
  3. Radio link metrics (Iridium signal quality, GPS carrier-to-noise, Starlink SNR) are trended in telemetry, which converts invisible coax chain degradation into a watched number.
  4. Clamp ratings are bought one energy class above requirement.
  5. A POST_STRIKE state. After logged very close activity, it audits every device and the radio metrics (the clamps themselves are meter-checked at the post-strike refit; there are no status contacts), then reports a protection status to ground, which can bias routing away from further lightning regions for the rest of the leg.

15. Connector and materials standards

Glands first. Every box entry is a nylon IP68 gland:

GlandFor
PG7One cable, 1/8 to 1/4 in
PG9Small bundles
PG11Actuator bundles
PG13.5Paired harness entries; the switched-load duplex runs (five 16/2, three and two per gland); the battery box signal bundle
PG162 AWG: the VESC feed and the battery mains

Nylon IP68 everywhere, as bought. (A nickel-brass gland where standing water is possible was the earlier wish; not bought, not required.) No M12 receptacles on any box. Three reasons: nothing on the boat needs to unplug at a box, a gland is the better seal, and receptacles ship from China in weeks. The M12 joints that do exist: the molded tees on the two CAN backbones, and the molded male-female coupling in the middle of a cut Micro-C cable on point-to-point runs. Female on the box side of the joint, male on the cable, boat wide. Everything else:

Cable rules. Pre-molded Micro-C cordsets only, cut once for drops. No field-made connectors. Cut ends get adhesive-lined heat shrink, plus ferrules and labels at both ends. On budget parts. Budget import Micro-C parts are acceptable throughout the sealed hull interior, with a contact protectant (DeoxIT) at every mating, hand tight. Every mated joint passes the powered salt-spray and thermal-humidity tests of Build Guide sec 11.1 before flight. Documented brand parts are reserved for genuinely hostile locations, and those are already handled by glassed domes and dedicated glands rather than by connectors.

16. Document impacts and open items

16.1 Sections updated at the v8.4 set pass (applied 2026-08-05)

Section moved to the Changelog.

16.2 Open items

#ItemWhat settles it
aWaveshare HAT on CM5, and the vertical carrier + HAT + bonnet on its L-bracket against the box widthVerify on first bench hardware; confirm connector directions on the edge
bSteering actuatorThe Ewellix CAHB-22 is confirmed as the Boat 1 part (the Thomson HD24B026 order was cancelled 2026-09-11). Still open: choose the reversing drive (relay pair or H-bridge) and the current-sense part; read the position-feedback type off the Ewellix datasheet
cPull solenoid selection, and burn wire gaugePin geometry at fit out; bench trigger campaign
dOrion-Tr monthly exercise enableTwo relay channels are spare again (3 and 5, sec 11); assign one, or confirm the exercise needs none
eScience payload switching ownershipConfirm against podlink before assigning the distribution channel
fDownstream TVS ratings vs MOV ladder stage-four let-throughThe calculation section 14.1 requires
gState sync software: the essential state set Pi B mirrors, and the wake schedule; plus the wing pod hold-then-feather timeout parameterDefine
hEncoder A landing via the aft junction trunk to the central nodeConfirm at fit-out
iEmergency bank enclosure and its gland listSETTLED: the bank is a bought Dyness 24V 100Ah (2,560 Wh, 42.6 lb) in its own enclosure - no box, no gland list (sec 5.2)
jWhere the central node's release release lines physically run aftTwo trunks to a passive transom terminal box (Electronics and Wiring Plan A3 entries 3, 4 and A16); actuator power only at v9.5, fire pairs 12-14 AWG, 22 AWG for what remains, cores counted at loom time. Release Node B covers its own channels at the stern (sec 12)
kHailoSETTLED: three Hailo-8L bought. One flies on Boat 1, on the carrier on hand beside the NVMe SSD; the other two are Boat 2 stock, not spares (sec 4.1). Bench-prove both slots together
lDetector false-trigger rate within 3 ft of Pi B with VESC A runningBench check (sec 13.1)
mTSW202 bench checksFive checks before the loom (Electronics and Wiring Plan v9.6 sec 6.1): Web API port off and on with the request and firmware recorded; SNMP readback; per-port watts; whether per-port power priority exists; all seven PoE devices at once and the total read
nAft junction box sizeTen RJ45 couplers and about 21 entries; measure the box before the loom
oUSB hub location and the science serial glandsIn the Pi A box, or a small dry box nearer the instruments (sec 4.1, sec 8.1)
pEnable relay positionWhich physical relay on the 8-channel module, or its own module (sec 11 fit-out flag)
qPi A box bonded faceSec 2.3 wants the flat bottom bonded; secs 2.1 and 8 put every entry on the bottom face. Settle with the open half of the hull-bonded cooling decision
rGPS receiver partCLOSED 2026-09-15: the NEO-7M modules bought 2026-09-09 fly, one per island
sQuad-UART HAT per PiCLOSED 2026-09-15: no. No serial add-on boards; the FTDI cables and the powered hub are the whole serial path (sec 4.1)
tWing trim actuatorCLOSED 2026-09-15: Thomson Electrak MD CNO on CAN; sec 10.2