Terminus: the backbone

Proposal section 9: the backbone

Satellites strung in a ring along the tidally locked planet's terminator, a frozen necklace linked by laser, with the red dwarf glowing low behind the limb

We owe a debt, and it was declared in writing. When we anchored the minds in MEO, we said the architecture "leans on a laser backbone that is asserted, not yet designed." Every question a child asks travels from her terminal up to a satellite of the wheel — and then it must keep going: across the sky to whichever slow giant holds her conversation's working memory, and back, twice per exchange, forever. This section pays the debt: the links between satellites, the routing over them, and the clockwork that keeps a fleet of moving transmitters agreeing about time and frequency.

Between satellites we use light, not radio. Above the atmosphere there is no weather to fade a beam and no rain to schedule around; a telescope the size of a dinner plate throws a beam tighter than any dish, at bandwidths that make the KV-cache torrents of the anchor layer — gigabytes per migration, transcripts streaming to the vault — routine cargo. The star still glares, but a laser link is a needle of light aimed at a known point; pointing is the game, and pointing, as we are about to see, is almost embarrassingly easy here.

The routing insight: rings never talk to rings

Sketch the obvious backbone, and you will draw too much of it: sixty-six laser links meshing all six rings into a web, every satellite reachable from every other. Now remember what the shift schedule actually does. At any moment, one ring — the duty ring, the one currently aligned with the twilight band — is serving every conversation on the planet. The other five are commuting over day and night country, carrying nobody. Traffic never needs to flow from ring to ring, because there is never a second ring with traffic. And when the seam comes every 22.4 hours and duty passes to the next ring, the two overlap for a window — but each serves its own users, and each, independently, can reach the anchors above. The conclusion is a pleasingly empty drawing: no inter-ring links at all. Six rings, six separate threads, none aware of the others' existence.

Within a ring we do string lasers, satellite to neighboring satellite, and here the sky hands us a gift worth pausing on. Twelve satellites sharing one circular orbit are not twelve independent movers — they are a formation, frozen since launch. Each follows the same track at the same speed, 30 degrees behind the next; the distance between neighbors is a constant 4,437-kilometer chord that never changes by a meter, and their relative velocity is exactly zero. Zero motion means zero Doppler and no tracking: each laser terminal points once at its neighbor and holds, for years, like a stretched wire. The ring is less a squadron than a single rigid necklace, nearly 54,000 km around.

Up to the anchors

The feeder link — duty ring up to MEO — is where the real distances live. The toolkit prints the shelves in Earth's catalog shorthand — LEO for the low orbits where the rings fly, MEO for the middle shelf that holds the minds — and the geometry is generous:

cargo run -p terminus-orbits --example backbone

LEO → MEO feeder links (2,200 km → 20,000 km):
  mutual visibility out to 118.0° of separation — 73% of the
  entire MEO shell is above the limb from any access satellite
  range at overhead                17800 km  ( 59.4 ms one way)
  range at 60° (budget policy)     23299 km  ( 77.7 ms one way)
  range at limb-to-limb            31323 km  (104.5 ms one way)
  worst-case range rate: 5.56 km/s

From any satellite of the duty ring, nearly three-quarters of the entire MEO shell hangs above the planet's limb. Whatever the shell finally carries — and later in this post the compass will settle that at 24 — several are always in view, and the routing policy prefers those within 60 degrees — the range that keeps the latency budget honest. So the full path of a question is now concrete: terminal, up to the duty ring; usually no hops at all along the frozen necklace, and up to six when the ring is sharing out its telescopes; one laser bound across 20,000 kilometers to the anchor; and the same road home. No mesh, no routing tables worth the name — a tree, redrawn slowly and predictably as the sky turns.

That “up to six” is not a policy we chose either. A hop moves exactly one place, because that is where the terminal points: each access satellite carries two necklace terminals, aimed at its immediate neighbors and held there for years. A ring of twelve therefore takes six hops to cross.

It is worth separating that from what a satellite can see, because the two are easy to confuse and we confused them ourselves for a while. At 2,200 km, a satellite sees its own ring out to 84 degrees of separation, and ring mates sit 30 degrees apart, so it can see two places along the ring in each direction and the third is behind the planet. But it can talk only to the one it has a laser aimed at. The link graph is a subgraph of the visibility graph, and the spare sightline is margin, not a shortcut — a satellite can see past its neighbor and cannot speak past it.

Unlike the necklace, the feeder link does have Doppler — at worst 5.56 kilometers per second of closing speed, which at optical frequencies is an enormous shift. But notice what kind of problem this is. Both endpoints are spacecraft whose orbits are known to the meter and predicted for hours; the shift is not noise to be searched for but a number to be computed. Each end pre-tunes for the motion — the same move that spared the terminals their search, played an octave higher. Nothing in this network hunts for a signal; everything is told, exactly, where and when and at what frequency to listen.

How many telescopes?

A laser link is not a shared medium. Each end of one needs its own terminal — telescope, steering, laser, detector, and the acquisition and tracking that keeps two moving instruments locked on each other — so a satellite holding four links carries four telescopes, and that count drives mass and power long before bandwidth does. Which links exist is therefore a hardware question before it is a routing one, and the answer runs against the intuition.

Sketch the simplest backbone imaginable: no links along a ring, none across the shell, every conversation reaching its own anchor directly. It is the easiest architecture to describe and the most expensive one to build. The reason is a rule we set two sections ago: a session keeps its anchor for close to two hours, about ten access handovers. So the conversations riding any one access satellite were anchored at different moments, from different places, and are scattered across the shell — and a direct backbone has to turn every one of those pairings into a telescope. Retention is the whole cost driver here, which means the re-anchor margin sets it: hold anchors harder, and the scattering gets worse, not better.

cargo run -p terminus-orbits --example feeder_terminals

  A thousand towns, one long-lived session each, over a day:
  feeder terminals on one access satellite: median 2, p90 4, p99 5, max 7
  feeder terminals on one anchor:           median 4, p90 8, max 13

Read the maximum, not the median. This fleet is built to one drawing — one access satellite, one anchor, qualified once, spared once, every lesson learned in orbit learned once. A peak that occurs somewhere occasionally is a peak that every spacecraft carries forever. Seven telescopes on all seventy-two, idle most of their lives.

The necklace is what rescues this, and it does so by pooling rather than by specializing. A session whose own satellite has no telescope free for its anchor borrows a ring mate's, and since the ring crosses in six hops the whole ring shares what it has. The fleet stays one drawing, and the count collapses:

  feeder terminals on EVERY access satellite:   2   (+ 2 necklace terminals)
  feeder terminals on EVERY anchor:             6   (one per ring)

One decision makes that work, and it deserves stating plainly because it sharpens a word used elsewhere in this proposal. When the activation plan calls a satellite dark, it means the satellite's radio is off — it is serving no towns, and the power that would have gone into a phased array pointed at the ground is saved. Its lasers stay lit. A ring is a standing relay whether or not its members are talking to anybody, and the alternative is worse than it looks: the plan lights the duty ring as a block, but scatters single satellites through the other five rings, and a single whose ring mates are asleep has nobody to borrow from. Measured, that is the difference between two feeder telescopes per satellite and seven. Recorded as ADR-0018.

What the shell keeps, and what it does without

That leaves the anchors, and the instinct that a shell of 24 ought to be a network in its own right. The geometry offers a start: four anchors in a plane sit 90 degrees apart, inside the 152 degrees at which two satellites at 20,000 km still clear the limb, so a plane closes into a cycle of four — reachable the long way round, with the satellite directly opposite permanently behind the planet. Those links are frozen, exactly like the necklace below. But a plane is not the shell, and joining plane to plane is a different animal entirely:

  intra-plane:  37,294 km, 124 ms, 0.00 km/s — frozen, point once and hold
  inter-plane:  nearest partner changes 22 times a day, holding 1.7 h at
                most; 4.89 km/s — steers, precompensates, and re-points

The zero in that first row is real, and the one you might expect in the second is not. Satellites sharing a plane genuinely are frozen relative to each other. Satellites in different planes of the same shell are not, however, identical in their periods: two inclined orbits cross at an angle, and their satellites sweep past each other at kilometers per second. An inter-plane link would be the most demanding in the entire architecture — worse than the feeder link, on a partner that changes twice an orbit.

So: does the routing need either? The obvious precedent says no. GPS flew for decades without crosslinks. But the precedent needs care, and it cuts both ways: classic GPS could do without them because a ground segment did the ephemeris and clock work, and later blocks added crosslinks anyway, for autonomy when that segment is out of reach. This system has no ground segment at all. The real question is whether the wheel can stand in for one.

It can, and not marginally:

  13,248 anchor pairs sampled across a day
    pairs with no access satellite seeing both:       0
    fewest access satellites able to relay any pair:  22

Not one pair, at any instant, lacked a relay beneath it; the worst-served pair still had twenty-two candidates to choose from. The wheel is the shell's control segment. An anchor reaches its two plane mates directly, across the frozen plane links; traffic to any other anchor goes down through the wheel and back up, which makes such a session migration two feeder hops through a single access satellite — and that is precisely what its second feeder telescope is for. Hold the old anchor and the new one at once, and the make-before-break ceremony of the anchor handover falls out of hardware already counted.

Reachable is not resilient

Which would settle it, if nothing ever broke. Ask instead what one failed telescope costs, and the shell's tidy arithmetic turns against it.

The wheel is redundant almost by accident: a ring pools two feeder telescopes on each of twelve satellites, so a conversation that loses one path borrows another and never notices. The shell has no such depth. Pooling is exactly what reduced an anchor to one telescope per ring — which means all 144 (ring, anchor) pairs are singly loaded, and losing one of them does not degrade a link; it severs it:

  of 1,000 sessions, the busiest single (ring, anchor) telescope carries 113
  the busiest anchor holds 170 across all six of its links

113 conversations, stranded at once by one component, every one of them obliged to re-anchor and drag its working memory across the sky in the same moment. A migration storm out of a single failure — and migrations are the one thing this whole architecture was built to make rare.

The cure is the frozen half of what we just declined. Give each anchor the two intra-plane links its plane geometry already permits — 37,294 km, zero Doppler, pointed once at launch and held for years — and a disabled anchor reaches the orphaned ring through a plane mate that still has a telescope into it.

An earlier draft of this section stopped there, and said that the sessions therefore do not move at all: a severed link becomes a detour rather than a dead end. The hardware was right, and the sentence was wrong, and what showed it was measuring the detour instead of asserting it. Every (ring, anchor) pair walked from ring slot 0 at 24 hourly instants — the geometry's whole range, not the anchors the policy happens to be holding:

  (ring, anchor) pairs        144 distinct, 3,456 samples
  extra round trip            median 210 ms, worst 315 ms
  worst round trip            460 ms
  over 300 ms nominal         3,456 of 3,456 samples (100%)
  over 600 ms degraded        0 of 3,456 samples (0%)
  samples with no plane mate  0

The line that matters is the hundred percent, and it is not bad luck. Price the cheapest detour this geometry admits — the radio leg out at the edge of a footprint, the shortest feeder link straight up, the plane hop itself, and two relays, summed one way and doubled — and it comes to 394 ms of round trip. That is a floor, not a sample. No detour anywhere in this sky can meet the RFP's 300 ms to the first token; the arithmetic forbids it before any hour is chosen. What every detour can meet, with room to spare, is 600 ms.

So the proposal asks its customer for a second number rather than quietly missing the first. TER-REQ-003's 300 ms now applies to failure-free operation, and a 600 ms degraded budget prices the failure case: a feeder telescope dark, the session carried around it. That is not a relaxation — the nominal budget is untouched, and the whole network is still sized under it. It is the admission that a cure with a 394 ms floor has to be paid for somewhere, and the specification is the honest place. Against 600 ms, the worst detour measured is 460 ms.

The second thing the measurement showed is what killed the sentence about sessions not moving. A detour is not merely slow; it is long. It adds 31,501 km of one-way path at the median, against the 5,000 km by which a rival must beat the held anchor before the policy will move a session — 6.3 times the margin. A detoured session is beaten several times over by anchors that were never in contention, so the policy abandons that anchor at its very next evaluation, and the whole bucket goes at once. The plane link does not prevent the migration. It never could.

What it buys is that the conversation goes on being answered while the migration happens. The transfer's own half was never in danger and never needed this link: the anchor is alive, five of its six feeder telescopes are untouched, and streaming its working memory to a successor rides the plane link when the successor is a plane mate — or goes down through the wheel exactly as the anchor handover always did, on hardware already counted. What breaks is the user's half. The serving satellite a session is talking through is itself in the ring that went dark, so with no plane link there is no way to reach the anchor at all — all 113 conversations on that pair go silent together, and stay silent until each has been moved somewhere its own ring can still reach. With the plane link the anchor keeps answering over the detour, at the degraded budget, for as long as the move takes. A stranding becomes a migration the session is served through. That is a smaller purchase than the earlier draft claimed, and it is still worth two telescopes an anchor.

Round trip
Budget300 ms nominal
On this pair113 conversations
Sparecold

Break the telescope and the timeline runs: declared after three missed 100 ms heartbeats, detoured through a plane mate at 460 ms against the 600 ms degraded budget, and then the race — a 5 s spare acquisition against a policy that moves a detoured session at its next evaluation. Turn off either Spare or Hold-off and watch the claim fail: one locks onto an empty bucket, the other sits on the detour for nothing. The full 3D console, with the plane links themselves switchable, is the constellation explorer at /terminus/explorer/.

Stillness has to be bought separately, and by two things that are worthless apart. The first half is a seventh feeder telescope on every anchor: steerable, cold, and unassigned, so that when one of the six goes dark it repoints at whichever ring lost it. That restores the direct path, which is why it needs no routing of its own — nothing reroutes, no neighbor is burdened, and the 300 ms budget comes back with the link. But a telescope must acquire before it can carry, and the figure the proposal states for that is 5 s.

Set 5 s against a detour worth 6.3 times the re-anchor margin, and the race is already lost. The policy will have moved every session off the pair before the spare finishes slewing, and a telescope bought on all 24 anchors will finish locking onto a ring whose bucket is empty. So the other half of the purchase is a rule rather than a part: a session whose anchor is known to be reconfiguring a feeder telescope must not be re-anchored during the acquisition window. The hardware is bought on the condition that the policy waits for it. Take the rule away, and the spare protects nobody; take the telescope away, and the rule asks a conversation to sit on a 460 ms detour for nothing. The plane link covers the acquisition window, and the spare ends it. They look like alternatives — twice the telescopes, pick one — and the measurement makes them two halves of a single remedy.

So the shell keeps its necklace and refuses its mesh. Nine telescopes on each anchor: six feeder links down to the rings, two frozen links to its plane mates, and one cold spare for whichever of the six fails first. What stays out is the inter-plane link — the one that steers, re-points twenty-two times a day, and precompensates 4.89 km/s. The one link class this sky is worst at is still the one the architecture does without.

Three honest limits on that. A plane mate relaying for a neighbor carries two rings' worth of traffic on one telescope, and this proposal has not priced that capacity; the hold-off bounds how long it must be carried and raises the peak while it lasts, because a bucket told to sit still does not drain. The spare protects one failure — a second dark ring on the same anchor falls back to the plane link and the degraded budget, which is the world above. And no arrangement of links saves a conversation from an anchor that dies outright: the working memory dies with the machine, and the vault is what answers that, as it always was. Recorded as ADR-0019 and ADR-0024.

flowchart TD accTitle: The Terminus backbone topology and its two deliberate absences accDescr: A terminal in the twilight band reaches its serving access satellite by radio. That satellite sits in a ring of twelve, joined to its ring mates by frozen laser links of 4,437 kilometers that never need re-pointing; the ring is a closed necklace, and, since a terminal points one place, traffic crosses it in at most six hops. Every access satellite carries two feeder telescopes pointing up to the MEO shell 23,000 kilometers away, and every anchor carries six, one for each ring, plus two frozen links to its plane mates so that a failed feeder telescope can be routed around, plus a seventh feeder telescope held cold and unassigned that repoints at whichever ring went dark. There are no links between one access ring and another, and none between one MEO plane and another. TOWN(["Terminal in the band"]) -->|"radio"| SAT["Access satellite<br/>2 feeder + 2 necklace"] SAT <-->|"<b>necklace</b> · 4,437 km<br/>frozen · ≤ 6 hops"| MATE["Ring mate"] SAT -->|"<b>feeder</b> · 23,299 km<br/>5.56 km/s, precompensated"| ANCHOR["MEO anchor<br/>6 feeder + 2 plane + 1 spare"] MATE -->|"<b>feeder</b>"| ANCHOR ANCHOR <-->|"<b>plane link</b> · 37,294 km<br/>frozen · reroutes a dead feeder"| PLANEMATE["Plane mate"] ANCHOR -->|"anchor to anchor:<br/>down and back up"| SAT SAT -.->|"<b>no inter-ring links</b>"| NEIGHBOR["Another ring"] ANCHOR -.->|"<b>no inter-plane links</b>"| PEER["Another plane"]
The finished backbone: three link classes and two deliberate absences. Each ring is a closed necklace of frozen links, each MEO plane likewise; every access satellite reaches the shell directly. Nothing joins one ring to another, and nothing joins one MEO plane to another.

Count the telescopes across the fleet, and the sketches are not close:

  topology                          wheel     shell     total
  direct, no links anywhere           504       312       816
  necklace + feeder + plane links     288       192       480

The cold spare sits on top of that and adds no link class of its own: one more telescope per anchor, +24 across the fleet, 480 becoming 504. Those 24 telescopes are what it costs to have the nominal budget back after a failure instead of living on the degraded one until the bucket has drained.

What flows through them

Counting telescopes says nothing about how fat each one must be. Two flows share these links, and the surprise is how little they resemble each other.

The conversation is a trickle. A token stream is a few dozen small packets a second, and only while the model is actually answering — a person reads, thinks, and types between replies. Twenty tokens a second at sixty-four bytes on the wire, a third of the time, is three kilobits per second. A dial-up modem from the century before last would carry twenty of them.

The working memory behind that conversation is 10.7 gigabytes — a 32,768-token context, a long tutoring session. If its anchor changes, all of it moves.

That if is the whole section. Working memory outweighs the conversation it belongs to by three orders of magnitude, so how much of it crosses these links is not set by how many people are talking — it is set by how often a session changes anchor:

cargo run --release -p terminus-orbits --example link_throughput

  if a session moved     migration rate    vs conversation
           every 2 h          11.9 Mbps              3884x
           every 6 h           4.0 Mbps              1295x
          once a day         994.2 kbps               324x
               never           0.0 kbps                 0x

And as the anchor section showed, nothing in the sky forces a session to move at all. A ring reaches every anchor at every instant, so the row the network lands on is chosen, not imposed. Choosing it is choosing the size of this backbone:

  at the million-terminal ceiling (TER-REQ-005), 10% concurrent,
  busiest feeder link:

  margin (km)   changes/day    conversation      migration
            0        113.37        2.1 Mbps     156.5 Gbps
         2500         19.13        2.1 Mbps      26.4 Gbps
         5000         12.70        2.1 Mbps      17.5 Gbps
        10000          7.08        2.1 Mbps       9.8 Gbps
        20000          4.05        2.1 Mbps       5.6 Gbps
        25000          0.00        2.1 Mbps       0.0 kbps

Four orders of magnitude, decided by one policy number. The bottom row is the tempting one, and the proposal does not take it: holding an anchor until nothing ever beats it means holding a long path, and a 25,000 km margin spends 290 ms of the RFP's 300 ms budget on light and relays, leaving 10 ms for the model to think in. The proposal takes 5,000 km, and the consequence for this section is a bill:

  at the million-terminal ceiling, with the adopted policy:

  link                                sessions   conversation   migration
  radio, terminal to satellite            1389      4.3 Mbps     —
  necklace, borrowed traffic only          347      1.1 Mbps    8.8 Gbps
  feeder (144 of them, both ends)          694      2.1 Mbps   17.5 Gbps

The busiest link in the system carries 17.5 gigabits per second, and all but 2.1 megabits of it is memory rather than speech. That ratio is the thing to take away. Working memory outweighs conversation by three orders of magnitude, so a backbone sized from token rates would have been wrong by a factor of 8,000 — and how far wrong depends entirely on a policy number, not on what anybody says to the machine.

The per-link arithmetic closes on a check worth having: every feeder link has one end on the wheel and one on the shell, so 72 satellites × 2 telescopes must equal 24 anchors × 6. Both come to 144.

Three cautions travel with this, and none of them are small.

The mean is not the sizing. 17.5 Gbps is what the link carries between bursts; it is not what the link must survive. The burst is a whole bucket leaving at once from an anchor that is still alive: the 113 sessions on the busiest (ring, anchor) telescope, pinned to the detour together while the spare acquires and then migrating together the moment the cure above stops covering them — a second ring dark on the same anchor, or a spare that does not lock. Each one drags its working memory with it. One session's 10.7 GB crosses in 0.86 seconds at 100 Gbps, or 8.6 at 10 — but the burst is not one session. It is 113 × 10.7 GB, near enough 1.2 terabytes, and it does not leave down the telescope that just went dark; it leaves down the five the anchor still has. Shared evenly, that is about 23 sessions and 242 GB on each surviving feeder link: 19 seconds with a 100 Gbps link held flat out, and more than three minutes with a 10. Nothing makes the sharing even, so those are the optimistic figures. An anchor that dies is not this case and never was: nothing streams off a dead machine, and its replacement rebuilds from the vault's transcript instead. These links are sized by the live-anchor burst — nearly twenty seconds of saturation on the busiest link in the system, not the eight tenths of a second one session takes — which is why the hundred gigabits the proposal has assumed since section 5 stays in the design.

Load balancing is still not bought. A session moves to shorten its own path and never to spare an anchor's compute, and nothing here models that compute. Sessions will still accumulate on whichever anchor happens to sit over a crowded stretch of the band. The margin is the only lever there is, and it moves every session at once, which is precisely why it is an operating parameter rather than a constant.

The uniform-towns assumption is doing quiet work. Real settlements cluster, and a clustered band would load a few links far harder than this arithmetic suggests while leaving others idle. Concurrency is a guess at one terminal in ten, and everything scales linearly in it. These are a floor on the busiest link, never a description of it.

One time for the whole sky

A network of movers needs one more agreement: when is it? Uplink slots are scheduled; handovers are timed ceremonies; the vault's transcripts must be ordered. And every one of those needs pales beside a customer still two volumes away — for this proposal ships as three volumes: the architecture in your hands, then the transport machinery, then the compass — navigation, where a clock error of one microsecond becomes a position error of 300 meters.

Synchronizing over a link is an old and lovely trick: two-way time transfer. I send you my clock's reading; you send me yours; each stamped message takes the same path in opposite directions, so the path delay — those 77 milliseconds to MEO — appears symmetrically in both exchanges and cancels when we difference them. What survives is the true offset between our clocks, measurable to nanoseconds over the very lasers already carrying the conversations. Even the 5.56 km/s of relative motion is no obstacle: predictable motion corrects out, as always in this sky.

So the timing architecture writes itself along the traffic's own tree: precise master clocks on the MEO shell, each ring's satellites disciplined through their feeder links, each necklace internally locked through its static neighbors. The whole fleet ticks as one.

And here the proposal closes a loop it opened long ago. The RFP demands a positioning, navigation, and timing service — ten meters, a hundred nanoseconds, four satellites visible always — and we deferred its design. We no longer defer its placement. The masters of the timing fabric, the MEO spacecraft, already carry everything a navigation beacon wants: atomic clocks, hours-long visibility, generous power, and now a planet-spanning synchronization web. The navigation service will live on the same MEO shell as the minds — clocks beside the intellects, broadcasting in X-band, well clear of the star's voice. The civilization's compass and its library will be the same points of light. Even the wheel will lend a hand: the low rings' fast motion sweeps out rapidly changing geometry and Doppler that the stately MEO shell cannot offer, and volume 3 will weigh that quick-ranging assist alongside the masters' steady signals. What remains for volume 3 is the service itself — pseudoranges, geometry, integrity — built on a timing fabric that this section has already paid for. Recorded as ADR-0008.

Placement settled, one number follows immediately, and it is not a number the minds would have chosen. A compass needs four satellites in the sky at once — three to fix a place, a fourth to fix the moment, because the receiver's own clock is one of the unknowns. Counting them over the inhabited band, one Earth day of geometry at a time, gives a clean threshold:

cargo run -p terminus-orbits --example navigation_shell

  shell     sats   min visible   mean visible   4 always in view?
  6 × 1        6         0           1.81         no
  6 × 2       12         1           3.62         no
  6 × 3       18         3           5.43         no
  6 × 4       24         4           7.24         yes
  6 × 5       30         6           9.06         yes

24 spacecraft: six planes of four, tilted 55 degrees, their nodes spread around the whole circle rather than the half-circle the polar rings use. The tilt and the spread are navigation's requirements, not anchoring's — a fix wants its satellites scattered across the sky over one town, and polar planes insist on crowding the poles instead. Recorded as ADR-0014.

The honest reading of that table is the first row. Six anchors — one per plane — would hold every conversation on the planet without complaint; sessions need a reachable mind, not a well-spread constellation. The other 18 satellites are bought by the compass. When the fleet is finally priced — an accounting that sits between this proposal's later volumes — they should be charged to navigation, and the proposal should say so plainly rather than let the minds carry a cost that was never theirs.

One caution travels with the number. Four visible is not four useful: satellites bunched in one quarter of the sky give a poor fix however many of them there are, and the geometry work that turns this count into ten meters and a hundred nanoseconds is volume 3's, not ours.

A compass, not a GPS

How different will that service be from the one Earth built? The answer splits beautifully in two.

The familiar half is startlingly familiar. Navigation is timekeeping, and moving clocks in gravity wells do not tick like clocks on the ground: Einstein's two theories each take a toll, and any working navigation system must pay both. Our planet has Earth's mass and Earth's size, and our shell orbits near GPS's altitude — so the tolls come out almost identical to the ones in the terrestrial textbooks:

cargo run -p terminus-orbits --example clock_rates

MEO clock rates vs a surface clock (20,000 km shell):
  velocity time dilation:      -7.27 µs/day (special relativity)
  gravitational blueshift:     +45.61 µs/day (general relativity)
  net:                         +38.35 µs/day (Earth GPS: +38.6)
  uncorrected ranging error:   ~11.5 km/day

Speed slows a clock; altitude quickens it; altitude wins. Left uncorrected, our navigation would drift by eleven kilometers a day — so, like GPS, we bias the clocks before launch and correct the rest in the broadcast. Nothing new under this sun. Except the sun.

The unfamiliar half is the sun. The star's gravity mostly cancels — planet and satellites fall around it together, which is why Earth GPS ignores the Sun entirely — but the tidal residue, the difference in the star's pull across the width of an orbit, does not cancel, and it grows as the cube of closeness. Twenty times closer than Earth means:

Stellar tidal clock modulation (the non-GPS term):
  this system:  ~28.3 ns/day (periodic)
  Earth GPS:    ~0.027 ns/day — ignored
  ratio: 1054x — must be modeled against the 100 ns timing budget

A term GPS engineers rightly discard is, here, a third of our entire timing budget, waxing and waning with each 11.2-day orbit. Volume 3 must model the star's gravity as carefully as the planet's — a sentence no Earth GNSS specification ever needed. Three smaller differences also tilt in our favor: our receivers never move and sit at known altitude, so three satellites can fix a position where GPS needs four; the network already knows nearly where every terminal is (its spot); and X-band suffers roughly twenty-eight times less ionospheric delay than the L-band GPS was forced to use — though the star's flares will make our ionosphere angrier than Earth's when they come.

A timetable, not a telephone exchange

A question worth asking of any routed network: who decides the path, and when? On Earth's internet, routers discover paths, gossiping among themselves, converging after failures at their own pace. Nothing of the kind flies here — because nothing here is surprising. Every orbit is known for years; the duty schedule, every feeder visibility window, every anchor assignment and beam map can be computed to the second, long in advance. So the network runs on a timetable: each satellite carries its routing future the way it carries its ephemeris, and the simulator that produced this proposal replays exactly the network that will fly — same inputs, same paths, byte for byte. Deterministic routing means deterministic latency, no convergence storms, no loops, and a network whose behavior under any scenario can be rehearsed on the ground before the scenario ever occurs.

The timetable has one more column. For every entry — serving satellite, feeder link, anchor — the plan also names the alternate: the backup anchor, the reverse path around the necklace, the adjacent ring near a seam. Choosing between plan and alternate is the only routing decision made in flight, and it is made by the simplest mechanism in this proposal: the keep-alive. Every link murmurs a heartbeat every 100 milliseconds; three missed beats declare a failure, 300 milliseconds after it happened, and the affected nodes start reading the other column. No discovery, no negotiation — the response to every failure was computed before launch. The whole decision procedure, stated once as an algorithm rather than argued, is in the appendix — along with the fine print on how literally "computed before launch" can be read on a station-kept fleet under a star three orders of magnitude more insistent than Earth's.

When a light goes out

Which failures, then, and what do they cost? Three classes.

An anchor dies. The keep-alives from its feeder links fall silent; 300 ms later its sessions re-anchor to the timetable's pre-assigned backup — with 73% of the shell visible, there is always one — and each conversation resumes from the vault's transcript, having lost at most the exchange in flight. This is the failure we designed for from the start.

A ring satellite dies. Its necklace neighbors notice within the same 300 ms, and switching is just as fast — but here honesty matters more than speed: switching to what? A dead duty-ring satellite tears a 30-degree hole in the necklace, and with our coverage minimum of exactly one, some towns face a gap that alternates can only soften — the adjacent ring helps near seam windows, lower-elevation service helps elsewhere. The full cure is the redundancy we have twice declared as debt: coverage sized to a minimum of two, plus dormant spares in each ring that can re-phase along the orbit — a cheap, slow drift into the gap. Pricing it belongs to the fleet economics, between this proposal's later volumes; until then, this is the single sharpest edge in the design, and we say so.

A link dies. Almost a non-event, by construction — and the one place that was not, we fixed above. A necklace is a cycle, so intra-ring traffic that finds one direction dark goes the other way around, and the long way costs hops, never reachability. An anchor's feeder telescope is the singly-loaded one, and it is the one place a link failure takes three things rather than one: a plane mate keeps the orphaned ring answered at the degraded budget, the anchor's cold spare repoints to give the direct path back, and the re-anchor policy holds the bucket still for the seconds in between so that the spare has somebody left to serve. Withdraw any of the three, and the bucket moves anyway. And every satellite carries feeder telescopes of its own, so no conversation is stranded by a broken necklace: at worst a session that can no longer borrow a path to its anchor re-anchors to one it can reach directly, paying a migration it would otherwise have been spared. The necklace is load-bearing for the telescope count, not for service. Recorded, all of it, as ADR-0009.

One thread of the design remains unpriced — how many anchors, how many spares, what the whole fleet masses — and two sections remain to write: the thread that keeps a conversation whole, and the accounting. Then, at last, the proposal can rest.