Status
direction
Conceptual layer
② Context connectors and ① write-back
Repo layer
L1 connectors-edge
Source
architecture section 7, section 5.8 WriteRequest, section 6 AL2–AL3 · ADRs 034, 035 · D10 · Index: README.

1. Fast local read path#

The edge agent polls each connector at poll_interval_s, an integer number of seconds, and delivers readings through a durable buffer and uplink. Push-level decisions need more.

ChangeDetail
Sub-second samplingAdd sampling_interval_ms. OPC UA monitored items at 100–250 ms, deadband 0 for counters; Modbus block reads at 200–500 ms
Push detectionPrefer PLC counters (a counter can't be missed between polls); rising edges as fallback
Local fast publishReadings go straight to a plant broker on stamped/v1/{org}/{plant}/fast/{line}/{asset}/{signal} with PLC time, edge time and sequence number; QoS 0, local only
Durable upload unchangedThe same readings still go through the buffer to L2
Readers stay read-onlyNo write function codes in the edge agent

Target: read, decide and write within about 1 s. Millisecond loops and trips stay in the PLC.

Plant broker: listens only on the plant network and localhost. ACLs follow the topic registry in 07: the edge agent publishes fast/#; the twin reads fast/# and writer/write/result and publishes twin/#, records/# and messages/out; only the writer reads twin/write/request and twin/heartbeat.

2. Time synchronisation#

The Plant BoxPlant-side computer for the fast loop (direction; D4) (D4) runs chrony. The edge agent tracks the PLC clock offset on every read. An offset move over 2 s flags the window in records and stops the writer until stable. Records keep PLC time as event time.

3. stamped-writer#

A separate Go program in connectors-edge/packages/stamped-writer, on the Plant Box only, with its own credentials. The only Stamped component that writes to a PLC (D10: OPC UA write only; twin publishes WriteRequestPlant Box write path request (direction; closure/action-intent.json retired) direction on twin/write/request).

3.1 Allowed and forbidden tags#

Allowed, each after its own site check: process setpoints of the heater and press (temperature setpoint or window, hold power, cycle time, then press settings within the maker's range).

Not on the write list, refused at load time even if configured: interlocks, trips, E-stops, safety PLC areas; alarm thresholds and sort limits; manual drive commands; any heat-treatment furnace, quench or ageing setpoint; quality hold, release or acceptance signals; anything not on the site packVersioned, owner-reviewed plant configuration including topology allow-list. The allow-list is signed by the plant's production head and checksummed.

3.2 The machine switch#

No write happens unless a "Stamped auto" bit on the machine's own screen is on, so the operator can always cut Stamped off without a phone. A PLC-side watchdog ignores Stamped's writes when the writer's heartbeat register stops changing. Without that PLC change, the asset stays at AL1Autonomy levels (direction; fast-loop stages 1–3 = AL1–AL3).

3.3 Checks for every write request#

A request carries tag, value, reason, procedure id, acceptance reference, twin state hash and a 5 s expiry. The writer checks in order:

  1. Tag allowed and not forbidden.
  2. Value within minimum and maximum; step within the largest step; rate within the maximum.
  3. Machine switch on.
  4. AL3: enabled this shift by the named in-charge. AL2: confirmed by a person in the last 2 minutes.
  5. Twin heartbeat under 2 s and state not uncertain.
  6. Request not expired.
  7. The PLC value equals Stamped's last written value; otherwise a person changed it, and the writer yields.

Any failure: no write, a log line and, except for expiry, an alert to the in-charge. The predictive safety filter owner is D15; VoR pattern depth is D17.

3.4 Safeguards#

SafeguardRule
Read-backWithin 1 s; mismatch means stop, restore, alert
Operator winsA value Stamped didn't write stops that tag until re-enabled
Restore on stopOn any stop, write back the operator's own value recorded when the tag was enabled
Start switched offAfter any restart every tag is off
Heartbeat and freshnessTwin heartbeat over 2 s or readings over 5 s old: restore and stop
Process guardPer tag, from its hazard row (for example a rising reject rate or exit drift)
VisibleCurrent state and value shown to the in-charge and on L6
Tamper-evident logEvery write and refusal, hash-chained, forwarded to L2 ledger.write_log (the record); the L5 evidence store keeps references

3.5 Staged authority#

StageAuthority
AL1No writes
AL2 ConfirmedA person taps Apply on the proposed value; token valid 2 minutes (path in 07)
AL3 StandingThe accepted procedure writes within limits while the in-charge has it switched on for the shift

4. Fail state#

Without a PLC watchdog the PLC keeps the last value written; because the writer restores the operator's value on every stop, that is normally the operator's own. The PLC watchdog closes the remaining gap and is required before press tags reach AL2.

5. Hazard analysis#

Every writable tag has an FMEA-style row (failure mode, effect on metal and equipment, detection, safeguard, residual), rated with the plant before AL2. Starting rows for the forging sector pack:

TagFailure modeSafeguard
Heater temperature setpointToo high: billets over the sort limitMaximum well below the sort limit; small steps; guard on reject rate; the PLC's own over-temperature trip
Heater temperature setpointToo low: reheats and cold-edge partsMinimum inside the part window; guard on low rate
Heater temperature setpointWrong part's value after changeoverWrites paused until the new part has run a set number of billets
Hold powerToo low or too high during stopsLimits and hold timer from the step test; restore at timer end
Cycle timeToo fast or too slowFloor and ceiling; one write per push; guard on waiting
AnyWrong registerAllow-list by address and type, verified against the HMI; read-back
AnyStale state or partitionHeartbeat, freshness; restore
Press setpointsChanges the forged partOnly after heater tags; maker's limits; PLC watchdog; first-part check after every change

6. SCADA access options#

RouteLatencyWritesAsk on site
OPC UA server100–250 msIf the server allowsEndpoint, security mode, nodes, owner
Modbus TCP200–500 msHolding registersRegister map; second master allowed?
SQL database1–5 sNoType, table, logging interval, read-only account
File exportMinutesNoExport frequency and location

Fast and writable work needs OPC UA or Modbus for reads; writes use OPC UA only (D10). SQL and files serve scheduled items and replay.

7. Site check per tag#

For every tag before AL2: a step test showing the process follows the setting as the twin predicts; register address and type verified against the HMI; read-back working; the machine switch blocking writes when off; restore putting back the operator's value. Recorded in the site pack with date, people and result. Order follows how many signals each tag removes.

Page history: last 3 changes
  1. 2026-10-07 docs(technical): rewrite fast-loop/; all architecture diagrams in house style 7330f47
  2. 2026-10-03 docs(fast-loop): interfaces and ownership; one topic registry; control-today wording; amend ADR-033 and ADR-036 df796e9
  3. 2026-10-03 docs(decisions): add ADR-033..038 (twin runtime, fast read path, plant-side writer, message classes, alerts and quality-to-lot link, part-keyed parameters), fast-loop technical set, rebuilt index with renumbering map; fix bare-number link text and ranges 22e2872

Diagram

100%

Search the architecture