SpaceX's Starship Mk1 just blew off its bulkhead in a pressurization accident
twitter.com
twitter.com
Manufacturing and assembly of high strength hardened steel is near black art.
Pathfinders do exactly what they say, they lead you through unknown territory to the outcome of the manufacturing journey you embarked on. Often things go boom, you find out why, add it to your corpus of black art knowledge, and keep pathfinding until you run out of budget / succeed / change mission.
So as manufacturing pathfinder, this is what success often looks like.
Also, someone on twitter said a horizontal weld failed. If this is true I'm surprised they didn't do two things: - tune their welding procedure by destructive testing with the same type of steel - and X-ray (or use another non-destructive method) the welds after assembly.
Welding (including more interesting metals) is my hobby so I had an opportunity to see that there a huge amount of knowledge in the field. There are routine testing procedures that ensure situations like this one don't happen.
Of course, they might also be on a deadline, and just went ahead and built it to spec and test it. But I don't think you can just say there's routine testing procedures that ensure rockets never blow up. If that were the case we wouldn't have needed SpaceX to reinvigorate the space industry.
Yes, that is also a possibility. I'm not sure how likely is it that a pressure vessel would fail along a weld if that weld was without faults and as strong as other surfaces. Perhaps it matters that there is also a sharp corner there?
>Of course, they might also be on a deadline, and just went ahead and built it to spec and test it. But I don't think you can just say there's routine testing procedures that ensure rockets never blow up.
I agree if they are trying to make it as light as possible and pushing the boundaries a bit while experimenting. One can't innovate without risk.
It would be good if they released more info about this incident.
The welding process probably isn't optimized or fully inspected and the weakest parts would expectedly be the welds.
I do this pretty much any time I’m doing something new - I have three revisions of a solar panel stand sat out on the lawn right now, each better than the last, as I needed to build the thing to see how it actually held up to forces as it’s easier and more accurate (ah, how do I fit a screwdriver in this gap to fasten this?) than doing an engineering simulation.
The design engineer: "We know on paper how the product needs to function in terms of strength, weight, durability, etc"
The manufacturing engineer: "We've never made something like this before. I've got a couple ideas how we can bend/shape/form/machine/weld these materials into the shape, but I don't know how those bend/shape/form/machine/welding operations are going to affect the underlying physical properties of the material. I know on paper these operations should be OK, and we can inspect them as we go, but again we've never done them before, we most likely will overlook something or discovery something new, so let's try one of them and break it early before we get too far down a potentially bad path."
The test engineer: "Well it worked up until X point then failed, here's the data for you design engineer and you manufacturing engineer, better try something else".
Design engineer: "Shoot, what we thought we were manufacturing isn't actually what got manufactured. Hmmm, is it even possible to make the part we need? Or do we now need to redesign the part because it can't actually be made. Let's try another approach. And maybe it's smart to pursue a few of these in parallel to increase our overall chance of success"
Those 3 roles can be the same person or separate organizations of hundreds/thousands of people. Requirements documents, manufacturing/quality reports, test reports, inspection reports are the language of this technical interchange.
With that said, the cult that surrounds his projects where people say things like "this is what success looks like" when a big metal thing blows up unexpectedly or robot car goes flying off an exit ramp is a never ending source of amusement.
The rocket has static landing coordinates, and if the boat were to move a few meters to either side it would miss it.
But there are definitely no “static coordinates”, it would have to move a lot more than a few meters for the rocket to miss, and it would be due to trajectory and fuel constraints rather than ability to maneuver.
When something doesn't behave as desired, it is a failure. You can learn from failure, that's how you get to success, but the failure itself is not a success.
"So as manufacturing pathfinder, this is what success often looks like. "
If blowing up a prototype enables changes to the manufacturing process that prevent the same thing happening later with a live crew on board, then it's considered a success. It doesn't matter who the CEO of the company happens to be.
AFAIK nobody has built something like this before. To have it fail during an early test doesn't seem unusual.
Suppose SpaceX had used a very similar prototype, but some process or engineer had caught the fault. Few here would be taking the lack of an explosion as evidence that SpaceX are not innovative. Instead, if anything, they would be praising the superb processes in addition to the cool prototype.
So, there is always room to improve. The reaction to this essentially anodyne point here has been really interesting.
See also: Soyuz 1, Soyuz 11, Challenger, Columbia, Apollo 1 - and that’s purely spacecraft which have killed people, never mind the vast list of experimental aviation deaths.
Much better to blow up some prototypes than some humans.
I don't see any constructive reason to look at it negatively, failure is part of testing. We don't test to find success, we test to find failures so that we can get them out of our systems.
We are silly animals. Links I can't help but click on....comments I can't help to respond to. The algorithms are winning.
In a Chemistry Lab, I put two elements together to show off a little explosion to my students, if it did. It was a successful demonstration, if it didn't go according to plan, it was a failure. And we will be wondering why this didn't work.
The OP said it from his perspective of pathfinder. And I assume these results were expected. And if it didn't blew up and they did not understand why it didn't, it create more uncertainty and variables during real launch. And I am sure everyone would want to minimise of that happening.
I am not sure how hard this is to see thing from his perspective, I would agree if Elon calling it a success would be hyperbole, but the OP stated he is a pathfinder, and finding out failure is exactly his job.
Experimental rocket/spacecraft (that's a fairly rapid prototype as far as rockets are concerned), made out of non-traditional material for rockets, fails one way yielding tons of data to do it better on the next version.
That's some modicum of success no matter how you slice it. Go plug 'rocket launch fail' or 'rocket explosion' or some such into YouTube and watch various rockets failing spectacularly on the launchpad both during development and carrying actual payloads and compare it to this failure at this stage of development.
I mean, look at stuff like Apollo 1. An electrical fire killed all of the crew during a test less roughly a month before launch. Starship is a very early prototype that probably yielded more actionable data than the Apollo 1 accident did.
I find it fascinating that we get to observe this all playing out in real time. You might agree.
Lynda Resnick
Less facetiously, a thin-walled cylinder's stress is a function of pressure, radius and thickness with the equation:
sigma = P*r/t
whereas for a sphere (including the spherical end caps on a cylindrical pressure vessel), it follows the equation:
sigma = Pr/(2t)
To me, it looked like it failed around the join between the spherical end cap and the cylindrical body, where this transition between stress regimes occurs, which is a common weak spot in the above analysis. This is a canonical early engineering statics problem.
It's worth noting, though, that all of the above is almost certainly a gross simplification and likely has very little bearing on the actual problem. It's fun to simplify and hypothesise, though! Also, unplanned failures make for great viewing :)
Source: article 6.8.2.2 of this document; https://www.faa.gov/about/office_org/headquarters_offices/as...
Edit: I didn't see the "/s" before writing this comment.
Safety factors feel like p-values. Why .05? Because. What if it's not good enough? We'll move the goal post.
Safety factor is really just a (somewhat blunt) method of managing risk. It's just admitting that we don't know the true load spectra that a design is exposed to, so we take what we believe is the max load and then slap a multiplier on it to manage how much uncertainty we expect, be it from estimates of that load, or dynamic factors, etc. etc.
We then also consider the consequence (since risk = likelihood x consequence). If the consequence of a failure is that our balsa-wood model bridge falls over, we shrug and keep it low. If it's that our pressure vessel undergoese a BLEVE [1] in the middle of a population centre then you jack it right the hell up.
There's nothing that specifically requires a safety factor. We could spend millions of dollars and thousands of hours understanding exactly the load spectra a design experiences, but that may be prohibitively expensive in the case of designing a bridge, so we instead accommodate more risk by overdesigning the item. In a space application where every kg of launch mass represents big $$$, then spending that extra time and money to understand the load specifics in more detail makes sense.
In less words, I'm eternally thankful that I work in an era where much of the older equipment I used was designed in an era of slide rule. This means there's a bit of extra 'meat' in the designs which often means that when I do a more precise computational analysis, I can deal with 10% material loss through corrosion, or extend out the life by some period of time because it's not been designed precisely to the material limits.
Yes, I feel this way too. The knowledge and tooling of modern engineers is amazing, and can do miracles when applied to tasks that seemed impossible just a century ago. But more often than not, it's used to pinch pennies from old designs. This makes me wish for infrastructure projects to be forced to be designed with slide rules again - the less precise your determination of maximum load is, the less the beancounters can "optimize" it.
This is doubly sad in our era, where matter is cheap and labor is expensive - adding extra safety margin can be almost free, but it's an easy target for cost reduction.
Keep in mind that weld strength is not one single number, it is a wide range. You can inspect a weld with X-ray, UT, MT, and PT methods to narrow the range, but there are still variable heat input, soluble hydrogen content, pre-heat and post-weld heat treatment factors that ALL affect the final hardness/brittleness and ultimate strength of a welded fabrication.
"Where'd you get that idea?"
"What do you mean, where did I get that idea? It's in the impulse engine specifications."
"Regulations 42/15: 'Pressure Variances in IRC Tank Storage'?"
"Yeah."
"Forget it. I wrote it… A good engineer is always a wee bit conservative, at least on paper."
- La Forge and Scott, Star Trek TNG "Relics"
A bit before that it is supposed to do a manned moon flyby in 2023.
New York to Shanghai slightly more than economy ticket by 4/2028:
https://www.vox.com/2018/4/11/17227036/flight-spacex-gwynne-...
Moon 2023:
https://www.scientificamerican.com/article/spacex-plans-to-f...
“SUCCESS! We now now max pressure the tank can hold and the damage a rupture might do.”
But they have learned to be more careful with the welds going forward. Though, admittedly, they only used panel welding on the first prototype and have already switched it up for the second one.
Don't get too excited about the damage, in space it does not matter much, the crew is screwed anyway.
If they pumped it until it explodes it would be a kind of test (also called experiment) where it makes sense.
If you design something with a margin of safety, then pump it to working pressure and it blows, then it means you made a mistake. If you made a mistake it shows you don't know what is necessary to design a rocket (yet).
Seriously, they don't build skyscrapers or bridges and leave for 5 days to see if they topple to prove the design was correct.
They gave up on carbon fiber awhile ago.
*I think they still use small composite overwrapped pressure vessels for fluids they need less of than CH4 and O2, just referring to giving up on carbon for the main tanks.
My understanding is that the skin is the pressure vessel. The reason for going with stainless steel at all is because it maintains integrity at high temperature. Carbon fiber does not. So a stainless steel combined heatsink and structure can maintain integrity at 1000C or whatever, while carbon fiber+ceramic heatshield will need to hold temperatures below 400C or whatever.
And even though the fiber structure is much, much lighter, the amount of heat protection required is massive. And the stainless steel "cheats" by performing double duty. And you get a second free lunch because the heat protection requirements are slimmer.
It wouldn't be the first time I've been wrong today though. Nor the second.
Edit: "So in summary. SpaceX chose stainless steel over carbon composites because it’s about as light, it can handle higher temperatures which means less heat shield is need, which then makes it lighter, it reflects heat which means even less heat shield which again makes it even lighter, it’ll be cheaper and quicker to build AND it’ll look FREAKING AWESOME."
AFAIK everybody is.
_Lifting_ that fuel is NOT CHEAP. See also, the rocket equation.
But we're essentially arguing whether max payload per launch or payload efficiency to orbit is more important.
So yes, fuel is cheap.
With one and done you have a larger mass fraction to work with. Reusable spacecraft operate on much tighter constraints. Every single wasted pound in Space X’s design likely costs them 100’s of thousands of dollars in lost profit over time.
Reusable means cost savings, but it has a dramatic reduction in cargo capacity. This means more trips to get the same mass into orbit, which means mire fuel directly used and every extra lb in the design is then carried up multiple times while further requiring more trips.
Or, equivalently, in one trip with a bigger rocket you have left over from another launch, because you didn't ditch it.
Which again demonstrates reusability is really expensive, though clearly not always as expensive as a new rocket.
Remember while the first stage is significantly more valuable, it's not just a question of fuel the upper stage is destroyed with both approaches. So, combined with significantly lower payloads the cost per kg does not drop as much as you might think.
It doesn't make fuel cheap, let alone very cheap.
Actually another significant part of SpaceX business is modern engineering and modern mean of production. They used to launch without recoverability for some high orbit payloads and they were competitively priced for that too.
SpaceX's greatest contribution has been to look at rocketry from the point of view of economics of running a rocket launching business as opposed to a "per launch cost plus" model realizing that fuel cost for launching a rocket is close to trivial compared to the facrication cost of making a rocket.
So their entire design philosophy is around reusability and reusability seems to push costs down low enough that you can get more payload up by simply doing more launches. While SpaceX is famous for not filing patents and instead protecting their IP using the trade secret approach and fabricating everything in-house, you can bet they'll be operating with more engineering headroom to get reliability and reusability.
Evidence for their bet having been right is the fact that they have grabbed virtually 100% of commercial and quasi-governmental launches and some part of US government launches. Other players in this space now almost entirely depend on defence contracts or national prestige contracts to survive.
Any rocket HAS to be very close to the limits of what materials used allow, and not the +50% margin of error you routinely seen in other fields. What you say about SpaceX is true, but only relative to the rocket industry as a whole. E.g. SpaceX uses cheap, available materials and simple designs over exotic composites and complex mechanisms. But they still operate close to the margins, as they have to in order to have any payload capacity at all. In fact, the move to steel probably reduced their mass margins even further.
EDIT: Actually maybe I shouldn't have used a car as an example: https://www.youtube.com/watch?v=pJdrlWR-yFM
"Have you got a spare billion dollars?"
"No. That's why we came to you."
Yeah, sure SpaceX doesn't know what's necessary to design a rocket.
Perhaps a better analogy is carving a violin top. Skyscrapers and bridges can be overbuilt without destroying their utility, but a violin has to be as thin as possible without breaking if you want it to function well as a violin.
https://www.krgv.com/news/spacex-extends-buyout-offer-deadli...
Suppose you bought a used car, and the brakes failed before you could drive it off the dealer's lot. The dealer graciously fixes the problem, and points out the great news - that nothing catastrophic happened, and that the problem is now fixed!
You would, of course, start wondering - what other unexpected failures are going to take place, after you drive out of the dealership. Maybe nothing. Maybe something life-threatening.
If the failure was a surprise for everyone involved, I'd be worried - because other surprises might not get caught in testing. If it was a 'Well, we're not sure what would happen', I'd be less worried.
https://en.m.wikipedia.org/wiki/1980_Damascus_Titan_missile_...
Not far enough, though.
Poor bastard.
Also with nuclear weapons, as much engineering has gone into safety as into weapon design itself. It's astronomically improbable for a modern nuclear weapon to detonate prior to arming even if the explosive lens is set off.
The reentry vehicle is designed to come down at circa mach 14 so a little bit of heat and jostling isn't going to bother it.
Cool video about some of the engineering involved: https://www.youtube.com/watch?v=97t7Xj_iBv0
Not blowing up when you don't push the button doesn't have a name.
When they actually dropped a pair by accident from a B-52, both got very far into their ignition sequence before something failed. Questions were Asked, after. So it is probably better now. Here. Russia? Israel? India? No telling.
We have come a long, long way since then in nuclear safety both in weapons and reactors.
Does it include Rick Perry? You are aware that the supposed secret "nuke launch code" was seventeen zeroes?
By the time you've punched in the code, whether it's an OTP or seventeen zeroes, you've already committed a missile to a target and you're already 100% going to go through with the launch because two missile combat crew members turned their keys.
Russia doesn't even bother with these kinds of codes. Their second strike capability is fully autonomous and will launch even if all of c&c infra is destroyed.
This also has absolutely nothing to do with the mechanical intrinsic safety of the actual nuclear weapon during a fire or the RV that carries it. Which is the original topic at hand. The code is just an extra step to arm the weapon. The physical safeties are there to 99.999% guarantee that the weapon will not detonate unless armed. Even if you try really really hard to detonate it.
More thinking has gone into each tiny element of this process including the kind of paint used on bombs, than you have given to the topic as a whole.
They are entirely constrained by thrust versus mass, so the designers make the structure as light/thin as possible while still being able to handle the acceleration forces when fuelled and pressurised.
If the weight of the rocket itself is too high it will not be able to lift any payload. If it is too light it falls apart in flight (or in one spectacular case, crumples in on itself when pressurisation fails).
[0] https://www.nasa.gov/mission_pages/station/expeditions/exped...
If a government regulator runs the investigation, you might. I don't know if a regulator's going to get involved in this, though.
You really think this? My perception is that their PR is fairly blunt and upfront. while they may not tell you everything they dont seem to be trying to "spin" anything
I'm not sure if this was deliberate spin, but it seemed pretty shady to me at the time.
WaPro: http://archive.is/j8zjc
Compare their statements about the cause of the CRS-7 explosion to NASA's.
> Compare their statements about the cause of the CRS-7 explosion to NASA's.
Did NASA's and SpaceX's statements differ in content?
NASA accident investigation report: https://www.nasa.gov/sites/default/files/atoms/files/public_...
TBF the NASA report came much later than the SpaceX explanation. However it might be of interest to compare:
SpaceX explanation of why looking at the right telemetry is hard vs "Technical Finding 4" from NASA.
SpaceX explanation of the strut's "certifications" and max load vs "Technical Finding 1" (and the longer explanation earlier in the document, you can do a control-f for "Where the IRT differs with SpaceX is in regards to the initiating cause")
Hmm.. Isn't this a common cost-cutting strategy for Musk's companies? The touchscreen in the Model 3s was (is?) also industrial grade, if I recall correctly.
Isn't that exactly what it should be? Or would you expect aerospace grade material there? Or is there yet another grade in between called 'automotive'?
https://www.youtube.com/watch?v=bvim4rsNHkQ
So much for very carefully managing PR.
That is simply wrong. Their business depends on reliably launching rockets and delivering payloads to station. And that is what they have done.
> If a government regulator runs the investigation, you might. I don't know if a regulator's going to get involved in this, though.
They are not going to. Starship is a SpaceX project that is not financed by NASA or the DoD.
For those who aren't keeping up with this the failure was on the Mk1 prototype. Mk2 has been build nearly in parallel with Mk1 and will take over early flight testing (20km hop). Elon has tweeted that this team will jump to Mk3 instead of trying to repair Mk1.
Here's an aerial video from beginning of october: https://www.youtube.com/watch?v=ChXMhSmqYqs
Official SpaceX statement: https://twitter.com/thesheetztweetz/status/11973066177605591...
Water, for example, can be pressurised without actually compressing, and therefore doesn’t undergo rapid expansion when a failure occurs.
There may be reason that precluded pressure testing with a fluid tough.
Edit: correction, looks like they're using methane/LOX. Methane is 422g/L and LOX is 1141g/L (compared to water at 1000g/L). If it was the LOX tank then they could have probably hydro tested it. Not so much with the CH4 which is probably the upper tank? It also bears mentioning that they would want to test at the appropriate temperatures. Water isn't great for hydro testing at LOX/liquid CH4 temps.
However...
To me there is an issue with large diameter pressured tubes - the point where the tube connects to the top is affected by the surface area divided by the diameter. Obviously one of those scales linearly, and the other squared.
That suggests to me (I'm definitely not a rocket scientist!) that the upper bound might be smaller than this diameter, or the weight will have to increase in order to beef up the strength of this point.
Pretty interesting problem to deal with now that they are this far into the design. I'm sure there are many possible solutions, and it will be fun to see what they come up with.
The argument has been that this is good enough to start testing structural features, and probably also good enough to do a little bit of low-stress flying as well. The first argument seems sound. I'm not so sure about the second... there are a lot of welds. At least a few of them are likely to be structurally unsound, and assessing weld quality is difficult.
In any case, for the "real" Starship, they plan to use a technique similar to the one they use on Falcon, where they roll a huge metal plate and then stir-friction weld along the seam. This kind of tooling is difficult and expensive to set up, and the configuration of the machinery and the material depends a lot on the actual design, which hasn't been finalized yet.
Apparently they're using thicker steel then they plan to use on the monolithically constructed version to compensate for weld quality, but I don't know... weld seams are great stress concentrators, and stress concentrations are where fractures are likely to form, and fractures on the skin of a rocket are usually catastrophic failures. All it takes is one defect.
Here's a similar effect on windows:
https://c8.alamy.com/comp/D60B28/distorted-reflections-in-a-...
That's why Starship can look a lot better when photographed from nearby - the view is tilted more upwards and the sky is reflecting in it which does not have enough details to let one see these wrinkles.
That way, since water is non-compressible, if it fails, you just get a small hole or buldge somewhere rather than the catastrophic damage seen here.
Perhaps they already tested with water and now needed to test with the real fuel/oxygen to get the temperature correct?
Every single one of my electronics prototypes look like shit. About one five of them produce smoke and burn marks. Every twentieth does something dramatically unexpected (usually entertaining).
This was a prototype that they've publicly said was most likely never to reach orbit, they are building this stuff right now to learn, test, and prove that their design works and find improvements that can be made.
There is no space mission in the near decades worth the loss of human life. Economy in terms of money is no priority if you are to undertake human space flight. Move fast and break things is cute for a global search index or regressing public discourse and attention span; it's astronomically stupid and not acceptable for safety of human life.
If this were a billionaire playboy stroking his ego and putting his own money and life on the line who cares. It's not, he's using my tax dollars and is going to hurt others for negligible gain.
And this Starship MK1 is/was a prototype designed to test some aspects of their design in the real world. It was never going to be anywhere close to taking people onboard. Even this incident had all people far away before they started doing anything like pressurising.
This is active development, every single rocket company or program in existence has had explosions and test failures, and they will continue to have them. The important part is that they are doing this safely and nobody is getting hurt, these are controlled tests.
It may not be the way you think rockets should be designed and built (I'm personally kinda skeptical that they will actually build the full prototypes/rockets outside like this), but it's not more dangerous than any other rocket company.
The air force has given them some money for development on their Raptor engine, and they've talked about wanting more government funding for starship itself, but they've also talked about how starship has been privately funded so far.
This is a weird assertion. Tens of thousands of people die in car accidents each year, but no one proclaims that going to the grocery store isn't worth the risk to human life.
I assumed that was a consensus. The thing isn't trying to win any beauty contests, it's covered in ugly seam welds.
And none of that matters, not one bit.
SpaceX has proven themselves over and over again of being more than capable of achieving their goals in light of people like you.
Meanwhile SpaceX is on their way to building a global internet constellation, have a working full flow combustion engine, and has multiple prototype Mars rockets in development.
I'd love to take your 10 year bet. Easy money.