1. Follow the operating sequence

Consider a spacecraft with several pressure-fed bipropellant thrusters. It performs a sustained orbit-change maneuver, coasts while conducting other activities, and later makes shorter corrections. Different combinations of thrusters may be used across that sequence.

The architecture must establish how propellant, electrical power and thermal control support each operating mode—and the transitions between them.

Operating stages and architecture questions
Operating stage Question for the architecture
Sustained maneuver Can the supply maintain acceptable propellant phase and inlet conditions for the thrusters commanded to operate together, for the required duration?
Coast or standby What must remain powered or thermally controlled, and how much preparation can be allowed before the next maneuver?
Restart and short corrections From the conditions reached during standby, can the system deliver the requested impulse within its timing and accuracy limits?

The same operating sequence should also be examined later in service, with less propellant remaining and potentially different tank, feedline and thruster temperatures; the resulting pressure history depends on the architecture.

The required maneuver outcome has a tolerance; the system's internal conditions may vary within an acceptable operating range. The design decision is where that variation can be accommodated through commands or operating procedures, and where pressure control, thermal management or another architectural measure is needed.

The first physical choices are how to store the propellant, make it available at the tank outlet, and deliver it in the state the thrusters require.

2. Store propellant and make it available

The stored state and the delivered state are separate architecture choices. A propellant stored partly as liquid may be supplied to a gas-fed thruster through deliberate phase management, while another design requires liquid at its inlet. NASA's propulsion assessment describes cold-gas systems that store saturated liquid and vaporize it before expansion through the nozzle. Liquid storage therefore does not, by itself, establish liquid delivery to the thruster. NASA: In-Space Propulsion, Cold Gas

Three locations need to be distinguished: inside the tank, at the tank outlet and at the thruster inlet.

Propulsion architecture: shared dependencies

No firing shown; both branches share upstream functions and spacecraft interfaces.
Generic bipropellant supply and thruster groups Separate fuel and oxidizer supplies feed groups A and B. Both groups depend on shared supply functions and spacecraft power, control and thermal interfaces. Select a view to examine shared demand or branch A isolation.
Fuel Oxidizer Power / commands Thermal coupling
Functional blocks may share hardware. Crossings without dots are not junctions. No calculated flows or demonstrated fault tolerance; not an Aeterna configuration.

Figure 1. Conceptual supply functions and shared dependencies. Fuel and oxidizer remain separate; blocks describe functions that may share hardware. The views illustrate connectivity and isolation boundaries, without establishing remaining maneuver capability or depicting an Aeterna configuration. Principles: NASA propellant acquisition review and Apollo distribution and isolation, pp. 151–152.

Inside the tank: define the storage conditions

Storage arrangements include compressed gas, liquid with a separate pressurant, and a propellant held as coexisting liquid and vapor. These arrangements do not have the same pressure behavior.

For a pure propellant with liquid and vapor in equilibrium and no separate pressurant, the equilibrium pressure follows its saturation-pressure relationship with temperature. That is not a general rule for total pressure in a tank containing an additional pressurant, nor a prediction of a tank's temperature during withdrawal. Self-pressurization does not mean temperature-independent pressure. NIST: Vapor Pressure

At the outlet: acquire the required phase

During low-gravity coast, liquid cannot be assumed to remain over an outlet as it would in an upright tank on the ground. Surface tension, wetting and spacecraft acceleration influence where the liquid and gas reside. Acquiring liquid therefore requires a way to keep it available to the outlet under the relevant operating conditions.

Options include diaphragms or bladders that separate propellant from pressurant, and capillary devices that use surface tension to collect or retain liquid along a path to the outlet. Settling maneuvers are another option where the mission permits them. Each approach has an applicable range of fill levels, acceleration, temperature and withdrawal demand; none should be treated as an unconditional guarantee. NASA: Propellant Management Devices for Low Gravity Propellant Acquisition, sections I–III

At the thruster: deliver the specified state

The intended inlet phase must be explicit. DLR's 2023 research overview, for example, described gas-fed bipropellant thrusters and liquid feeding then under investigation. The propellant chemistry alone does not settle that choice. DLR: From Lampoldshausen to Space, section 4, p. 3

The path from tank outlet to thruster must preserve the required state or deliberately change it—for example, through controlled heating when vaporization is required. Outlet conditions cannot simply be assigned to the thruster inlet. Both fuel and oxidizer paths need this assessment, without assuming identical thermal treatment or acquisition hardware.

Providing driving pressure, acquiring the required phase and conditioning the delivered propellant are distinct functions—not necessarily three separate devices. The architecture must accomplish them together throughout the operating sequence.

The next choice is how to provide and manage that driving pressure.

3. Decide which pressure variation to accept or control

The pressure-control decision is which pressure must remain within which bounds, during which operation?

Accept a changing supply—or constrain it

In a gas-pressurized liquid-propellant blowdown arrangement, the gas already in the tank expands as liquid is withdrawn. Pressure generally falls, with its trajectory also depending on thermal conditions. Regulated tank pressurization instead admits additional gas from a separate supply to keep the propellant-tank pressure within a selected range. NASA's Transit Habitat assessment compares these two approaches; both are pressure-fed systems. NASA: Transit Habitat propulsion architecture assessment, printed pp. 4–5

Regulation can also occur in the propellant path. For example, ESA documents an engineering-model system that conditions and regulates gaseous propellant before delivery to the thruster interface. That controls a downstream feed pressure, rather than the storage-tank pressure. ESA: Electronic Pressure Regulator, System Architecture

Self-pressurization describes how the source provides pressure, not whether downstream regulation is used. The choices can therefore coexist, provided the source supplies enough pressure and flow for the regulator to operate. Its temperature-dependent behavior from Section 2 still matters.

Identify the pressure being controlled

Propellant-tank pressure, regulator-outlet pressure, thruster-inlet pressure and chamber pressure are not interchangeable. Even with stable tank pressure, the inlet conditions reached through the feed network depend on the losses associated with the active flow paths and demand. Chamber pressure results from the coupled feed and thruster operation; it is not simply the regulator setting.

Orion's European Service Module provides a practical precedent. ESA describes on/off helium valves used to manage propellant pressurization for its different engine classes. Its operations account explicitly distinguishes pressure at the source from pressure farther downstream. For the illustrative spacecraft, the same distinction matters: the assessment must address the conditions delivered to each operating thruster, not just the pressure maintained upstream. ESA: How to fly Orion—propulsion

Compare the usable operating ranges

A pressure-reducing regulator needs sufficient upstream pressure above its controlled outlet pressure at the required flow. Its outlet also has a tolerance and a transient response: changes in supply pressure or demand can produce departures from the setpoint. NASA's regulator design guidance treats these as coupled performance considerations, including operation at low supply pressure and high demand. Regulation therefore reduces selected variations; it does not establish constant thrust or replace temperature and phase management. NASA: Liquid Rocket Pressure Regulators, sections 2.1.1–2.1.3

NASA's Transit Habitat concept assessment connects this choice to guidance, navigation and control: blowdown operation requires accommodating decreasing thrust and impulse bit as inlet pressure falls. NASA: Transit Habitat propulsion architecture assessment, printed p. 5

For the sustained maneuver and later corrections, can changing thrust be accommodated by adjusting burn duration while still meeting the maneuver window? Can pulse commands be adapted to meet the required impulse and accuracy? Do those options remain available at lower inventory and different temperatures?

If they do, accepting a wider pressure range may avoid additional hardware. If they do not, pressure regulation may justify its hardware and integration burden—but the resulting inlet conditions still need assessment. Compare pressure-management choices against the same maneuver requirements, including the hardware, control and operational effort each needs.

Several thrusters sharing a supply add another dependency: the firing of one can affect the conditions at another.

4. Supply and command a network of thrusters

The spacecraft in this example may use several thrusters for a sustained maneuver, then a different combination for attitude corrections. The architecture must support those combinations—not merely each thruster operating alone.

Assess the firing combinations

When thrusters share a feed line or distribution manifold, opening or closing one changes demand on the common supply. Pressure disturbances can affect other connected thrusters. The assessment therefore includes transitions between firing combinations, such as short correction pulses while another thruster continues firing steadily.

NASA investigated exactly that interaction during Lunar Module development. Its breadboard campaign included single- and multiple-engine firings, including pulsing alongside steady operation. Feed-pressure fluctuations were more severe than predicted, and the findings led to a reduction in the maximum permitted pulse frequency. The feed-system response helped define which commands the propulsion system could support. NASA: Lunar Module Reaction Control System, printed pp. 7–8

For a bipropellant system, fuel and oxidizer delivery must also be assessed together. Their transient responses need not match: the relative arrival and cessation of the two flows matter during startup and shutdown, as do their inlet conditions during sustained operation. Equal supply pressures alone do not establish the required mixture ratio. NASA: propulsion lessons-learned presentation, slide 37

Revisit Figure 1 to compare shared demand and branch isolation.

Connect commands to delivered response

An electrical firing command, valve motion and the resulting thrust pulse are different events. The control interface therefore needs a characterized relationship between the command and delivered impulse across the intended conditions—not an assumption that thrust starts and stops with the electrical signal.

Monitoring has a separate role. The Lunar Module compared engine-valve commands with chamber-pressure-switch indications to flag mismatches. That provided evidence of firing behavior, not a direct measurement of delivered impulse. NASA: Lunar Module Reaction Control System, printed p. 6

Distinguish what is commanded, what is measured and what is estimated from a model or spacecraft motion. This identifies the information needed for control and for deciding whether a thruster remains available, without prescribing a sensor on every thruster.

Choose useful isolation boundaries

Shared feeds consolidate hardware but also create shared dependencies. An isolation valve can shut off a troubled branch while removing supply from healthy thrusters connected to that branch. NASA's Apollo service-module description illustrates this boundary: each four-engine group shared distribution manifolds, with isolation valves provided for events such as a line rupture or runaway thruster. NASA: Reaction Control Subsystem, printed pp. 151–152

For the spacecraft in this example, the question is which maneuvers remain possible after isolation. Can the remaining thrusters produce the required force directions and torques, with adequate supply and electrical resources? Separate branches do not establish independence if they still rely on the same upstream component or controller.

Choose feed groupings, isolation boundaries and control logic together, based on the maneuver capability they preserve.

5. Make thermal management part of availability

Readiness means that the required thrusters and their supply paths can operate when the maneuver is needed—not simply that the hardware survives the preceding coast. NASA's thermal-control guidance distinguishes survival requirements from operational requirements. NASA: Thermal Control, section 7.1

Choose the standby condition

A planned orbit-change maneuver may allow time to prepare the propulsion system. Corrections required at short notice may instead justify maintaining selected thrusters and feed paths within their ready-to-operate conditions throughout standby.

These choices impose different demands. Maintaining readiness can consume energy during the coast; preparation before firing requires time and sufficient available power. Neither approach necessarily uses less total energy, and different parts of the system may need different treatment.

ESA's Orion operations account makes this connection explicit: thruster availability includes heater preparation, with the time required depending on thermal conditions. This is a spacecraft-specific example of temperature management affecting the maneuver timeline. ESA: How to fly Orion—propulsion

Between firings, the system keeps evolving

Qualitative propulsion operating sequence and standby choices Sustained firing is followed by shutdown, coast and later correction commands. Thermal conditions continue evolving between firings. During coast, selected paths may be maintained ready, or allowed within storage and survival limits before restoring readiness as required. Preparation may occur within coast. No elapsed durations, temperatures, energies or thrust profiles are calculated.
Widths are not durations. Command marks are schematic, not a specified firing count, thrust or flow. Standby choices apply to selected paths; neither establishes unrestricted firing or lower energy use.

Figure 2. Operating sequence and alternative standby strategies. Preparation is conditional; thermal history continues between firings. Stage widths and command marks are schematic, without specifying durations, firing counts, temperatures or energy use. Principles: Orion heater preparation and the analytical NASA-sponsored heat-soak study, p. 97.

Follow the thermal history through shutdown

Tank, line, valve and thruster temperatures do not change together. Their heat capacity, surroundings, connections and propellant flow differ. ESA's account of Artemis I thermal operations describes both the different response rates of tanks and thrusters and the cooling effect of propellant flowing toward the engines. Firing therefore does not imply that every part simply becomes hotter. ESA: How to fly Orion—thermal

Nor does shutdown end heat transfer. Heat retained in a chamber can continue into the injector, valves and nearby structure after firing—often called heat soakback. A NASA-sponsored auxiliary-propulsion study explicitly modeled injector warming from the chamber wall after shutdown, followed by valve warming through the connecting structure. Its analysis tracked firing and between-firing times; it was an analytical study, not flight evidence. NASA: LOX/Hydrocarbon Auxiliary Propulsion System Study, section 6.3, p. 97

The sustained burn, the following off-time and the later corrections therefore need to be assessed together. Acceptable chamber cooling during the burn does not establish acceptable valve or feedline conditions afterward. Any required recovery interval belongs in the maneuver schedule. The relevant result is an operating range that supports the required sequence from its expected initial conditions.

Define the spacecraft thermal interface

Thermal isolation can reduce unwanted heat transfer, but it can also impede a useful path for removing heat. Conductive mounts, insulation and radiating surfaces therefore need to be considered together. NASA's thermal-control guidance treats these interfaces, spacecraft orientation and electrical heating as parts of the overall heat balance. NASA: Thermal Control, sections 7.1–7.3

The thermal interface should identify allowable mounting temperatures, heat transferred into adjacent hardware, required radiative exposure, and heater or conditioning demands. Peak electrical power and energy consumed over an operating sequence are separate quantities. The spacecraft must also accommodate any preparation time or restriction on the next firing.

Thermal design helps determine when maneuvers are available, how closely they can follow one another, and what resources the spacecraft must provide to sustain that capability. These obligations belong in the architecture comparison alongside tanks, feed hardware and control electronics.

6. Compare complete architectures over the operating sequence

Return to the sustained maneuver, coast and later corrections. Each candidate must address the same mission objectives, timing and accuracy limits, service life and specified fault cases, across the relevant inventory and thermal conditions.

Equivalent mission capability does not require identical operating strategies. Candidates may use different burn durations, preparation intervals or firing combinations, provided they remain within those common requirements.

The comparison should answer five questions:

Complete architecture comparison questions
Comparison question What belongs in the assessment
What must the spacecraft carry and accommodate? Installed mass, volume and mounting constraints for propulsion hardware, supports, harnesses and any additional spacecraft power or thermal equipment required by that candidate.
What must be loaded to complete the mission? Propellant consumption, defined reserves, unusable residuals and pressurant, with consistent accounting across candidates.
When is the required capability available? Maneuver duration, preparation and repeat-firing limits, permitted thruster combinations, peak electrical power, energy use and thermal interfaces.
What remains available under the specified faults? The required remaining maneuvers after isolation or reconfiguration, including shared dependencies and remaining consumables.
What does it take to deliver a usable system? Manufacturing and supply availability, integration effort, cost, schedule, and the distinction between demonstrated behavior, predictions and unresolved assumptions.

The comparison boundary matters. A reduction in propulsion-unit mass is not a spacecraft-level saving if it requires a larger addition elsewhere. Likewise, loaded propellant includes the portions assigned to usable reserves and unusable residuals; these are not extra masses to add again. Each candidate's mass and resource estimates must be consistent with its own operating strategy.

Mandatory requirements should remain distinct from preferences. A mass advantage cannot compensate for missing a required maneuver window. A delivery deadline or budget may also be a hard constraint. NASA's decision-analysis guidance distinguishes mandatory from enhancing criteria and considers technical performance, cost, schedule and risk together. NASA Systems Engineering Handbook: Decision Analysis

Unresolved performance is not automatically failure, but it is not demonstrated compliance either. If the preferred architecture depends on uncertain heater demand, usable propellant or pulse behavior, ask whether a plausible change in that assumption would reverse the decision. NASA recommends considering further uncertainty reduction when it could change the choice. The next analysis or test should therefore address the uncertainty most likely to change the architecture choice. NASA: Decision Analysis, section 6.8.1

The outcome is a candidate architecture with defined hardware functions, operating limits and spacecraft interfaces—and a clear account of what remains to be established. The next development step is turning that architecture into dependable hardware, then building the evidence that supports its intended use.

This article is an educational discussion of public sources and a qualitative illustrative scenario. It does not report Aeterna hardware performance, qualification or flight results. Aeterna’s propulsion and fluid-control programs are in development.

← Article 4: Matching propulsion to the mission

Article 6: Turning propulsion architecture into dependable hardware →

All technical articles