MARS BIBLE — RISK & RESILIENCE

Simultaneous loss of several habitats: when refuge capacity becomes the critical resource

“One backup habitat” is no longer enough when an event affects several volumes or the refuge depends on the same network as the lost areas.

A Mars settlement must reason in distributed refuge capacity, network independence, and relocation time, not simply building count.

1 — Two losses can share one cause

Propagating fire, contamination of a common utility, a series-wide structural defect, or a sector power failure can disable several habitats without each having the “same failure”.

Geographic and technical diversity therefore matter as much as building count.

2 — Count truly habitable refuge places

A refuge place needs pressure, air, water, thermal control, power, minimal sleeping, hygiene, and monitoring. An empty room is not automatically refuge capacity.

Distinguish a few hours of shelter from several weeks of habitation.

Dependency diagram for Simultaneous loss of several habitats: when refuge capacity becomes the critical resource
Main scenario dependencies.

3 — Shared utilities can defeat refuge independence

Separate habitats fed by the same electrical bus or water loop are not independent.

Backup paths must be traced to physical dependencies.

4 — Moving people is a system operation

Transfer can involve airlocks, suits, vehicles, reduced-mobility crew, patients, and medicine continuity.

A refuge unreachable within available time is not a credible refuge.

5 — Recovery may take weeks

Repair, decontamination, and structural inspection do not happen at evacuation speed.

The settlement must function in degraded configuration while capacity is restored.

Decision and margin diagram for Simultaneous loss of several habitats: when refuge capacity becomes the critical resource
From detected threshold to stable recovery.

6 — Growth must preserve margin

Adding residents without adding refuge capacity lowers resilience even if daily life still works.

Refuge-to-population ratio becomes a technical governance indicator.

Combined scenario — two habitats lost within one hour

Imagine a settlement made of several pressurized volumes linked by tunnels. A fire first triggers automatic isolation of one sector. Minutes later, sensors detect smoke contamination in another volume that shares part of the ventilation system. The problem is no longer “one building failed”: operators must know which zones remain genuinely independent.

The first decision is to freeze a real-time refuge-capacity map. The crew does not count theoretical beds from the master plan; it counts only volumes that remain pressurized, powered, thermally controlled, and reachable. That distinction looks administrative during normal operations but becomes decisive when several dependencies disappear together.

The second clock is consumables. A refuge may accept one hundred people for two hours but only forty for several days if carbon-dioxide removal, water, or electrical power was sized for a small crew. “Capacity” must therefore always be paired with duration and service level.

The third difficulty is human. A population does not move like boxes on a diagram: some people may be injured, asleep, working far from an airlock, dependent on medicines, or unable to don a suit without help. Real transfer time must be measured in drills, not guessed from map distance.

Finally, the emergency does not end when everyone reaches refuge. A days- or weeks-long degraded phase begins: constrained food service, crowding, extra maintenance, fatigue, and priority decisions. A credible refuge architecture must therefore address life after evacuation, not evacuation alone.

What the architecture should prove before population growth

Before permanently increasing population, the operator should be able to show that one credible common cause cannot remove most refuge capacity at once. That requires mapping power, water, air, computing, cooling, and physical access down to the equipment that is actually shared.

Each major refuge needs an island mode: it must be able to disconnect from questionable networks and sustain vital functions for a defined period. Independence does not necessarily mean duplicating everything; it means knowing exactly which functions remain possible without the main network.

Resource transferability must also be demonstrated. Water trapped behind the damaged zone, medicines stored inside the evacuated building, or an incompatible backup cable are not operational backups. Emergency logistics should be tested with real hardware.

A fourth test concerns the long tail of the event: where does the population live if the lost habitat remains unavailable for thirty days? Sleeping, hygiene, food, work, and medical care must be reorganized without creating a second health or human-factors crisis.

The desired result is not a magical refuge-seat number but evidence: for each retained loss scenario, the settlement knows where people go, how long refuge lasts, which consumable becomes limiting, and which action genuinely increases margin.

Teaching calculation — make margin visible

TEACHING ASSUMPTION: 120 residents and 150 independent refuge places before the event. Two 35-place zones become unavailable: 150−70=80 remain.

80 places for 120 people leaves a 40-place deficit. “150 backup places” is meaningless if part of that capacity shares the failure cause.

Variant: add 30 truly independent places: remaining capacity=110, deficit=10. The model forces dependency analysis before counting.

Questions never to forget

  • Which refuge places remain after the same initiating cause?
  • How many hours can each refuge operate without external utilities?
  • How are patients and people unable to perform EVA transferred?
  • Which consumable first limits refuge duration?
  • At what population must new independent refuge capacity be built?

Primary sources