02 Fast read path and the plant-side writer
- Status
- direction
- Conceptual layer
- ② Context connectors and ① write-back
- Repo layer
- L1
connectors-edge - Source
- architecture section 7, section 5.8 WriteRequest, section 6 AL2–AL3 · ADRs 034, 035 · D10 · Index: README.
1. Fast local read path#
The edge agent polls each connector at poll_interval_s, an integer number of seconds, and delivers readings through a durable buffer and uplink. Push-level decisions need more.
| Change | Detail |
|---|---|
| Sub-second sampling | Add sampling_interval_ms. OPC UA monitored items at 100–250 ms, deadband 0 for counters; Modbus block reads at 200–500 ms |
| Push detection | Prefer PLC counters (a counter can't be missed between polls); rising edges as fallback |
| Local fast publish | Readings go straight to a plant broker on stamped/v1/{org}/{plant}/fast/{line}/{asset}/{signal} with PLC time, edge time and sequence number; QoS 0, local only |
| Durable upload unchanged | The same readings still go through the buffer to L2 |
| Readers stay read-only | No write function codes in the edge agent |
Target: read, decide and write within about 1 s. Millisecond loops and trips stay in the PLC.
Plant broker: listens only on the plant network and localhost. ACLs follow the topic registry in 07: the edge agent publishes fast/#; the twin reads fast/# and writer/write/result and publishes twin/#, records/# and messages/out; only the writer reads twin/write/request and twin/heartbeat.
2. Time synchronisation#
The Plant BoxPlant-side computer for the fast loop (direction; D4) (D4) runs chrony. The edge agent tracks the PLC clock offset on every read. An offset move over 2 s flags the window in records and stops the writer until stable. Records keep PLC time as event time.
3. stamped-writer#
A separate Go program in connectors-edge/packages/stamped-writer, on the Plant Box only, with its own credentials. The only Stamped component that writes to a PLC (D10: OPC UA write only; twin publishes WriteRequestPlant Box write path request (direction; closure/action-intent.json retired) direction on twin/write/request).
3.1 Allowed and forbidden tags#
Allowed, each after its own site check: process setpoints of the heater and press (temperature setpoint or window, hold power, cycle time, then press settings within the maker's range).
Not on the write list, refused at load time even if configured: interlocks, trips, E-stops, safety PLC areas; alarm thresholds and sort limits; manual drive commands; any heat-treatment furnace, quench or ageing setpoint; quality hold, release or acceptance signals; anything not on the site packVersioned, owner-reviewed plant configuration including topology allow-list. The allow-list is signed by the plant's production head and checksummed.
3.2 The machine switch#
No write happens unless a "Stamped auto" bit on the machine's own screen is on, so the operator can always cut Stamped off without a phone. A PLC-side watchdog ignores Stamped's writes when the writer's heartbeat register stops changing. Without that PLC change, the asset stays at AL1Autonomy levels (direction; fast-loop stages 1–3 = AL1–AL3).
3.3 Checks for every write request#
A request carries tag, value, reason, procedure id, acceptance reference, twin state hash and a 5 s expiry. The writer checks in order:
- Tag allowed and not forbidden.
- Value within minimum and maximum; step within the largest step; rate within the maximum.
- Machine switch on.
- AL3: enabled this shift by the named in-charge. AL2: confirmed by a person in the last 2 minutes.
- Twin heartbeat under 2 s and state not uncertain.
- Request not expired.
- The PLC value equals Stamped's last written value; otherwise a person changed it, and the writer yields.
Any failure: no write, a log line and, except for expiry, an alert to the in-charge. The predictive safety filter owner is D15; VoR pattern depth is D17.
3.4 Safeguards#
| Safeguard | Rule |
|---|---|
| Read-back | Within 1 s; mismatch means stop, restore, alert |
| Operator wins | A value Stamped didn't write stops that tag until re-enabled |
| Restore on stop | On any stop, write back the operator's own value recorded when the tag was enabled |
| Start switched off | After any restart every tag is off |
| Heartbeat and freshness | Twin heartbeat over 2 s or readings over 5 s old: restore and stop |
| Process guard | Per tag, from its hazard row (for example a rising reject rate or exit drift) |
| Visible | Current state and value shown to the in-charge and on L6 |
| Tamper-evident log | Every write and refusal, hash-chained, forwarded to L2 ledger.write_log (the record); the L5 evidence store keeps references |
3.5 Staged authority#
| Stage | Authority |
|---|---|
| AL1 | No writes |
| AL2 Confirmed | A person taps Apply on the proposed value; token valid 2 minutes (path in 07) |
| AL3 Standing | The accepted procedure writes within limits while the in-charge has it switched on for the shift |
4. Fail state#
Without a PLC watchdog the PLC keeps the last value written; because the writer restores the operator's value on every stop, that is normally the operator's own. The PLC watchdog closes the remaining gap and is required before press tags reach AL2.
5. Hazard analysis#
Every writable tag has an FMEA-style row (failure mode, effect on metal and equipment, detection, safeguard, residual), rated with the plant before AL2. Starting rows for the forging sector pack:
| Tag | Failure mode | Safeguard |
|---|---|---|
| Heater temperature setpoint | Too high: billets over the sort limit | Maximum well below the sort limit; small steps; guard on reject rate; the PLC's own over-temperature trip |
| Heater temperature setpoint | Too low: reheats and cold-edge parts | Minimum inside the part window; guard on low rate |
| Heater temperature setpoint | Wrong part's value after changeover | Writes paused until the new part has run a set number of billets |
| Hold power | Too low or too high during stops | Limits and hold timer from the step test; restore at timer end |
| Cycle time | Too fast or too slow | Floor and ceiling; one write per push; guard on waiting |
| Any | Wrong register | Allow-list by address and type, verified against the HMI; read-back |
| Any | Stale state or partition | Heartbeat, freshness; restore |
| Press setpoints | Changes the forged part | Only after heater tags; maker's limits; PLC watchdog; first-part check after every change |
6. SCADA access options#
| Route | Latency | Writes | Ask on site |
|---|---|---|---|
| OPC UA server | 100–250 ms | If the server allows | Endpoint, security mode, nodes, owner |
| Modbus TCP | 200–500 ms | Holding registers | Register map; second master allowed? |
| SQL database | 1–5 s | No | Type, table, logging interval, read-only account |
| File export | Minutes | No | Export frequency and location |
Fast and writable work needs OPC UA or Modbus for reads; writes use OPC UA only (D10). SQL and files serve scheduled items and replay.
7. Site check per tag#
For every tag before AL2: a step test showing the process follows the setting as the twin predicts; register address and type verified against the HMI; read-back working; the machine switch blocking writes when off; restore putting back the operator's value. Recorded in the site pack with date, people and result. Order follows how many signals each tag removes.
Page history: last 3 changes
- docs(technical): rewrite fast-loop/; all architecture diagrams in house style
7330f47 - docs(fast-loop): interfaces and ownership; one topic registry; control-today wording; amend ADR-033 and ADR-036
df796e9 - docs(decisions): add ADR-033..038 (twin runtime, fast read path, plant-side writer, message classes, alerts and quality-to-lot link, part-keyed parameters), fast-loop technical set, rebuilt index with renumbering map; fix bare-number link text and ranges
22e2872