MARS BIBLE — RISK & RESILIENCE
Thermal-control failure on Mars: when heat or cold shuts down a settlement
Surviving Mars is not only about staying warm: a settlement must also reject heat from people, computers, batteries, and machines.
Thermal control keeps every device and habitat volume inside an acceptable range. A stopped pump, leaking loop, degraded radiator, or fouled heat exchanger can overheat a local system even while the outside environment is extremely cold.
Heat must move just like electricity or water
Nearly every watt of electrical power consumed eventually becomes heat somewhere. Computers, lights, motors, electrolysers, and people all add thermal load, so heat must be collected, transported, and rejected.
Failure can cascade: equipment overheats, protects itself by shutting down, its function disappears, and other systems must work harder. A robust settlement knows thermal limits and how long each device can operate without nominal cooling.
Radiators, loops, and pumps: where is the bottleneck?
A radiator does not manufacture cold; it rejects thermal energy by radiation. Its capacity depends on temperature, area, orientation, and radiative environment. Dust, poor deployment, or obstruction can reduce that capacity.
Fluid loops add pumps, valves, heat exchangers, leakage, and freezing concerns. A second loop is real backup only if it avoids the same failure point. NASA treats thermal control as essential to keeping crew and hardware within required temperature limits.
Detect drift before shutdown thresholds
Temperature alone may react late. Engineers can monitor supply-return temperature difference, fluid flow, pump speed, electrical power, loop pressure, and valve position. A growing temperature difference can reveal fouling or insufficient flow before an overtemperature trip.
Alarms should be staged: early warning, load limitation, thermal load shedding, controlled shutdown, then emergency shutdown. Stopping an electrolyser may be acceptable at one threshold; stopping medical equipment at the same threshold may not be.
Thermal load shedding: decide what to stop
When rejection capacity is lost, the base can reduce the heat it generates by limiting or stopping loads. The objective is not only electrical saving but staying below the remaining heat-rejection capability.
Manufacturing or laboratories may be cut before life support and communications, but delayed consequences matter. Shutting down a greenhouse saves power and heat now while creating a food problem if the outage lasts.
Check whether remaining heat rejection is enough
LEARNING CALCULATION — ASSUMPTIONS ARE EXPLICIT
Exercise: the settlement dissipates 80 kilowatts of heat. A failure removes 30% of heat-rejection capability from a system originally capable of 100 kilowatts.
Remaining capacity: 100 × (1 − 0.30) = 70 kW. Load is 80 kW, so the immediate thermal deficit is 80 − 70 = 10 kW. At least 10 kW of thermal load must be removed, more if a margin is required.
The kilowatt, kW, is power: energy per unit time. Real design also includes radiator conditions, temperatures, transients, thermal storage, and engineering margins.
Think in transients, not only steady state
Thermal mass can absorb excess heat for a while without immediately crossing a temperature limit. That inertia buys time but is finite. Procedures need time-to-limit estimates for each load scenario.
Recovery should also be staged. Restarting every machine at once can recreate the thermal peak that caused the emergency. A thermal restart plan adds loads in steps and verifies stability after each one.
Decision questions specific to this hazard
- How much heat can actually be rejected with one radiator or pump unavailable?
- Which equipment reaches its temperature limit first, and in how many minutes?
- What load shedding removes heat immediately without creating another life-critical failure?
- Do the two cooling loops share a pump, exchanger, sensor, or power supply?
- How are loads restarted without again exceeding available thermal capacity?