01simulation2026

Cryogenic Flow Simulation

Rust process simulation informed by Siemens and Rockwell PLC experience: 29,500 entities at 30 Hz with fixed-seed replay, extended in September 2026 into a bounded engineering program with a fault library, two commodities, a software controller, structured import, a browser projection proof and a localhost Unreal Engine camera.

The scaled system ran 29,500 entities at 30 Hz and recovered to 30 Hz after deliberate overload. Its fixed-seed deterministic capture produced 1,800 frames with raw output pinned by SHA-256 inside the same executable, seed, GPU-adapter, and driver scope. Coordinated close, open, and restore waves moved across all 15,000 valves; the shipped video changed 24.3% of label-excluded fleet pixels versus a legacy 1.0% whole-percent comparator. A measured warmed 5.29 MB full JSON state snapshot compared with a 6.8 KB representative warmed binary delta, about 779× smaller, with static layout retained separately. Between 2026-09-07 and 2026-09-11 the project then ran as a milestone program: ten milestones, each with an exit criterion fixed before the work, a pre-registered budget file and negative controls, graded clause by clause with three verdict states (pass, fail, unmeasurable) and recorded in a private program repository with every decision and evidence record. The last graded commit passed 734 workspace tests with the reference run's final state hash unchanged across every increment, and the localhost Unreal Engine camera showed a seam-vapour cue 109 ms after the adapter applied it.

Open the project video
Deterministic Stage 1 capture at 1920 by 1080.
Role
Controls-domain translation, Rust workspace architecture, simulation implementation, capture pipeline, and artifact validation.
System boundary
Since September 2026 the workspace also holds a fault library with a declared 13-mode supported set and a connection-seam leak that modifies process truth, a versioned imported-model contract that accepts only repository-authored synthetic sources, a per-commodity liquid property path for oxygen and nitrogen from a pinned MIT-licensed source, a software controller inside the core, a practice engine graded as an engineering demonstration, a renderer-neutral read-only projection contract with a browser 3D proof, and a localhost Unreal Engine 5.8.2 adapter whose WebRTC signalling is relayed by the Rust service. A Rust workspace drives three crates: cryo-core owns the physics domain model, cryo-service exposes an Axum HTTP layer, and cryo-web serves the browser-rendered SVG/HTML/CSS dashboard. Playwright orchestrates the Stage 1 capture scenario and validates the artifact.
Primary constraint
All behavior must be deterministic from a fixed seed so artifacts are reproducible and auditable.
Strongest evidence
Measured scale, real-time recovery, and byte-identical deterministic replay for the 29,500-entity generated plant.

The situation

Control sequences are difficult to rehearse when the real facility is unavailable, incomplete, or too costly to place into every fault and boundary condition. The simulator needed reproducible state transitions across valves, tanks, pipes, and instrumentation without depending on live hardware.

A simulation that hides its assumptions can create false confidence at the exact conditions where engineering errors are most costly: low temperatures, pressure differentials, actuator timing, alarms, and recovery sequences.

Constraints

  • All behavior must be deterministic from a fixed seed so artifacts are reproducible and auditable.
  • No live hardware dependency; the simulation must run entirely from a Rust service with a browser-rendered UI.
  • The capture pipeline must verify its own output with measurable thresholds, not just visual inspection.
  • The current demonstration is not plant-calibrated, connected to PLC or DCS control logic, safety-authoritative, or an operational digital twin.
  • Every increment is graded against an exit criterion fixed before the work starts; a milestone that misses a clause is recorded as not verified, never softened to pass.

My responsibility

Controls-domain translation, Rust workspace architecture, simulation implementation, capture pipeline, and artifact validation.

The system

Since September 2026 the workspace also holds a fault library with a declared 13-mode supported set and a connection-seam leak that modifies process truth, a versioned imported-model contract that accepts only repository-authored synthetic sources, a per-commodity liquid property path for oxygen and nitrogen from a pinned MIT-licensed source, a software controller inside the core, a practice engine graded as an engineering demonstration, a renderer-neutral read-only projection contract with a browser 3D proof, and a localhost Unreal Engine 5.8.2 adapter whose WebRTC signalling is relayed by the Rust service. A Rust workspace drives three crates: cryo-core owns the physics domain model, cryo-service exposes an Axum HTTP layer, and cryo-web serves the browser-rendered SVG/HTML/CSS dashboard. Playwright orchestrates the Stage 1 capture scenario and validates the artifact.

Architecture descriptionA three-crate Rust workspace with a physics core, Axum service layer, and browser-rendered SVG/HTML/CSS dashboard captured by a Playwright scenario harness.

Critical decisions

01

Fixed-seed capture

Choice
Drive the Stage 1 scenario from a fixed seed and scenario name.
Alternatives considered
  • Depend on live hardware or an unpredictable animation loop.
Tradeoff
The capture favors reproducibility and auditability over live-system variability.

02

Threshold-based validation

Choice
Validate OCR, motion, flow, tank, pipe, telemetry, and clamp thresholds after capture.
Alternatives considered
  • Rely on visual inspection alone.
Tradeoff
Thresholds are more trustworthy than inspection alone but require calibration against known-good runs. The September 2026 program generalized this: every milestone's exit criterion, budgets and negative controls were written before building and graded clause by clause with three verdict states (pass, fail, unmeasurable); several milestones were graded not verified on a first pass and re-graded only after the gap was measured and fixed.

03

Sell a bounded outcome before a platform

Choice
Start with a facility-specific control-sequence rehearsal engagement built from approved customer engineering information and acceptance scenarios.
Alternatives considered
  • Build a general simulation platform or multi-tenant SaaS before proving paid customer demand.
Tradeoff
Manual customer translation limits early software scale, but it tests the buyer, inputs, fidelity, acceptance criteria, and delivery economics before making a larger product commitment.

Proof

Scale simulation proofMeasured scale, real-time recovery, and byte-identical deterministic replay for the 29,500-entity generated plant.

Evidence boundary
Generated-scale evidence combines a deterministic offline capture from a fixed seed with a separately measured live real-time run; source commits and measured validation thresholds are recorded. The September 2026 program figures come from its exit-evidence records on a single Windows workstation and one Linux second device; each is a bounded current project claim, not a customer or facility result.
Known limits
Byte determinism is scoped to the same executable, seed, GPU adapter, and driver; the deterministic offline capture does not claim wall-clock real-time performance. The physical model is a bounded reduced-order model at demonstrator fidelity: two commodities on the liquid saturation path only, a single generated model under every graded scenario, a qualitative seam-vapour cue that is symbolic and not a concentration, release-rate, dispersion or hazard-distance analysis, and a software controller reaching two of four tick loops. The practice workflow is an engineering demonstration, not training, qualification or credit; the public interactive demonstrator is not built (the service shares one run among all clients); the optical-character-recognition ingestion milestone is deferred. Nothing here is consequence analysis or live-equipment control: it is simulation-only, with no write-capable path to live plant, launch hardware or safety systems.

Engineering signal

Why this matters to engineering teams

CryoSim connects practical controls-engineering experience with a deterministic software architecture that makes facility behavior easier to rehearse, inspect, and explain.

Controls experience

Earlier facility simulation in integrated Siemens and Rockwell PLC logic modeled commodity inventories, temperatures, pressures, and other sensor and actuator feedback for sequence, interlock, alarm, and recovery rehearsal.

Testable domain core

The no-I/O Rust core keeps state transitions deterministic and directly testable before service or browser code is involved.

Measured scale

Generated topology, compact transport, and semantic rendering sustain an operator-readable 29,500-entity demonstration.

Evidence boundaries

Offline determinism, live runtime behavior, and future facility integration are reported as separate claims, and the ten September 2026 milestones (control panel and P&ID, fault library, structured import, two commodities, software controller, engineering-practice workflow, browser projection proof and a localhost Unreal Engine camera) each carry a pre-registered budget file, negative controls and a recorded verdict.

Reflection

The scaled system ran 29,500 entities at 30 Hz and recovered to 30 Hz after deliberate overload. Its fixed-seed deterministic capture produced 1,800 frames with raw output pinned by SHA-256 inside the same executable, seed, GPU-adapter, and driver scope. Coordinated close, open, and restore waves moved across all 15,000 valves; the shipped video changed 24.3% of label-excluded fleet pixels versus a legacy 1.0% whole-percent comparator. A measured warmed 5.29 MB full JSON state snapshot compared with a 6.8 KB representative warmed binary delta, about 779× smaller, with static layout retained separately. Between 2026-09-07 and 2026-09-11 the project then ran as a milestone program: ten milestones, each with an exit criterion fixed before the work, a pre-registered budget file and negative controls, graded clause by clause with three verdict states (pass, fail, unmeasurable) and recorded in a private program repository with every decision and evidence record. The last graded commit passed 734 workspace tests with the reference run's final state hash unchanged across every increment, and the localhost Unreal Engine camera showed a seam-vapour cue 109 ms after the adapter applied it.

  • Deterministic seeds make simulation artifacts auditable in a way that live hardware captures cannot be.
  • Separating domain logic into a no-I/O core crate forces the physics model to be fully unit-testable before any service or UI code depends on it.
  • Threshold-based artifact validation is more trustworthy than visual inspection alone, but the thresholds need calibration against known-good runs.
  • An instrument can pass a black frame: the first packaged Unreal scene rendered black because a rotator's positional order is (roll, pitch, yaw), and a file-existence check and an orphan count by the wrong process name both graded it a pass. Both instruments were corrected before any verdict, and a still now carries its measured luminance.
  • A measurement can name the wrong column: a memory gate summed working sets and read a 14-process browser at 1.03 GiB for the page a 7-process browser rendered at 0.63 GiB; the gate moved to private resident bytes with every earlier reading retained and the budget unmoved.
  • The instrument's browser is not the owner's browser: ten automated runs of the streamed camera passed while the owner's own browser showed no video, because a decoded-frame callback never fires for a background tab. First-frame detection now uses three signals, and a visual is verified in the owner's client before acceptance.