Technical Manual · Fire Control
Fire Suppression System — Control Cockpit
Methodology behind the operational fire-system cockpit: ISA-18.2 alarm state machine, VESDA staged cause-effect matrix, FM-200 pre-action and N2 purge discharge logic, manual controls, and the current Conventional authority for site context and fire-water reserve. This cockpit is state-driven — the dominant logic is a discrete event machine, not a mass-equation calculator.
▶ Open the live Fire System Cockpit01 Purpose & scope
The fire-system cockpit (fire-system.html) is an operational BMS dashboard for monitoring and simulating the data-centre fire-suppression system: pre-action sprinkler zones, FM-200 / inert-gas clean-agent cylinders, and the N2 purge system. It documents alarm progression, cause-effect interlocks, and manual override controls — it is not a sizing calculator. Agent-quantity math lives in the separate fire-calculator.html (documented in manual/fire.html).
Truth boundary: Hall A–D and the 2,000-rack total provide site and rack-footprint context, not agent or fire-water sizing. Neither the current four-hall operating basis nor a capacity study may scale cylinder quantity, pump flow, tank duration or cause/effect by proportion; those remain subject to hazard classification, surveyed gross-enclosure geometry, hydraulic or clean-agent calculations, and AHJ-approved design.
The cockpit serves four operational questions: what is the current alarm stage, which cause-effect actions have been triggered, are the manual abort / bypass / simulation controls in a safe state, and does the current site and fire-reserve authority match the rest of the DC suite. All state is deterministic — no Math.random(), no back-solved constants.
02 Inputs — controls & locked basis
The cockpit has three input categories: manual operator controls (abort / bypass / simulation), the locked engineering basis inherited from conv-engine.js, and the read-only alarm-state inputs driven by the cause-effect rule machine.
Manual operator controls
| Control | Type | Effect | Interlock |
|---|---|---|---|
| Manual Abort | Pushbutton / software | Halts the countdown timer at Stage 4; returns to Stage 3 (Confirmed, not yet armed). Does NOT reset detection. | Active only when state.stage === 4 (Armed). Disabled at all other stages. |
| Bypass (zone) | Toggle per zone | Inhibits a VESDA or detector zone from advancing the state machine. Zone shows ISA-18.2 suppressed state. | Requires conscious ARM + confirmation step in simulation mode to prevent accidental zone lockout. |
| Simulation Arm | Toggle | Arms the simulation so staged fire scenarios can advance stages 0→5. Cockpit is in DEMO mode only — not wired to a real FACP. | Simulation badge is displayed prominently (amber dashed border) per doc-05 §1; advancing stages is blocked unless ARM is active. |
| Stage advance | Simulation only | Manually advances the alarm state machine one stage at a time (used for training/demo). Each stage triggers the full cause-effect output for that stage. | Blocked unless state.armed === true. |
| Reset / Lockout release | Manual | Resets cockpit to Stage 0 Normal after a post-discharge lockout. In a real system this requires a physical key-reset at the FACP. | Only available at Stage 5 (Discharged / Lockout). |
Locked engineering basis (read-only)
| Parameter | Symbol | Value | Source |
|---|---|---|---|
| Site IT load | IT_LOAD_KW | 30,000 kW (30.00 MW) | CONV_CALC.snapshot.site.it_load_kw — current Conventional authority |
| Data halls | campus.hall_count | 4 (Hall A–D) | CONV_CALC.snapshot.campus.hall_count |
| Physical racks, site total | RACKS | 2,000 | CONV_CALC.snapshot.campus.racks_total |
| Rack-footprint context | SITE_RACK_FOOTPRINT_CONTEXT_M3 | 7,200 m³ (non-sizing proxy) | Derived: round(2,000 × 1.2 m² × 3.0 m); not gross-enclosure volume |
| Pre-action zones | ZONE_COUNT | 5 (PACV-01 .. 05) | Fixed — data-hall layout |
| VESDA zones | — | 8 (4 halls × 2 circuits each) | Site design — coverage per NFPA 72 |
| Fire-water reserve | fire.stored_m3 / reserve_capacity_m3 | 104.9 m³ available / 114 m³ installed | CONV_CALC.snapshot.fire at the simulated 92% level |
| Fire-pump demand | fire.pump_demand_lpm | 2,500 L/min | Assumed hydraulic design basis in CONV_CALC.snapshot.fire |
| Required reserve | fire.required_duration_min / required_capacity_m3 | 60 min / 150 m³ | 2,500 L/min × 60 min |
| Available duration | fire.duration_min | 42 min at the current 92% level | 104.9 m³ × 1,000 ÷ 2,500 L/min |
| Installed-capacity shortfall | fire.capacity_shortfall_m3 | 36 m³ | 150 m³ required − 114 m³ installed; does not meet the stated duration |
SITE_RACK_FOOTPRINT_CONTEXT_M3 = 7,200 m³ from the site-wide rack footprint (2,000 × 1.2 m² × 3.0 m) solely to keep operational context aligned with the Conventional snapshot. It is not a protected-enclosure measurement and must not drive cylinder mass, sprinkler density, pump selection or tank sizing. The 2,688 m³ gross enclosure in §06 is an illustrative geometry for the worked calculation; a real zone volume must be surveyed and reconciled through the qualified fire-protection engineer, FACP/suppression supplier and AHJ.03 Alarm state machine methodology
The cockpit's dominant logic is the ISA-18.2 seven-state alarm model, implemented in js/rz-alarm-state.js (RZAlarmState v1.43.4). The module provides state definitions, severity tiers, a colour-discipline arbiter, and an equipment-state mapper — all without DOM mutation at load time.
ISA-18.2 alarm states
RZAlarmState.resolveColor(). Colour discipline: status wins over domain. Red is permitted ONLY when alarmActive === true (unack or ack). All other states use their own non-red colour.ISA-18.2 · STANDARD
Severity tiers
| Tier | Rank | Colour | Trigger examples |
|---|---|---|---|
| Critical | 4 | #ef4444 (fault-red) | Active discharge, fire pump trip, pressure below low-low alarm |
| High | 3 | #f97316 (orange) | Pressure below low alarm, VESDA action, confirmed cross-zone fire |
| Medium | 2 | #f59e0b (amber) | VESDA alert, pre-action armed, jockey pump run |
| Low | 1 | #eab308 (yellow) | Standby / OOS / bypass / suppressed states, tank below 80% |
Equipment-state to alarm-state mapping
RZAlarmState.deriveFromEquipment(). Maps RZLineModel / RZBreakerSymbols data-state into the inspector Alarms tab. Only fault/tripped produces alarmActive = true and thus the red colour channel.ISA-18.2 · STANDARD
04 Cause-effect matrix & staged discharge
The cockpit implements a 6-stage cause-effect rule machine (var CE[0..5]) that advances linearly on alarm confirmation. Each stage triggers a deterministic set of outputs — no probabilistic branching. Stage 5 discharge must complete within the NFPA 2001 10-second limit for halocarbons (FM-200). The N2 purge for pre-action valve supervision operates as a continuous standby function, not a timed discharge event.
| Stage | Name | Colour | Cause-effect outputs |
|---|---|---|---|
0 | Normal | Green (is-normal) | All quiescent. Jockey pump holds 12.5 bar static. FACP and VESDA under continuous supervision. Pre-action valves closed. N2 supply at 2.4 bar standby pressure. |
1 | VESDA Alert | Amber (is-active) | Aspirating smoke concentration above alert threshold. Warning only — no output action. Operator notified for physical investigation. |
2 | VESDA Action / Smoke Detector | Amber (is-active) | First-stage sounder activated. Pre-alarm sent to BMS and building management. Operator acknowledge required. Still no suppression output. |
3 | Confirmed Fire (cross-zone) | Red (is-active) | Two independent detection zones confirmed (cross-zone logic). AHU / CRAH units commanded off. Fire dampers commanded closed. Pre-action valve charge initiated. Smoke-control mode engaged per ASHRAE 62.1. |
4 | Suppression Armed | Amber (is-armed) | Release circuit armed. Countdown timer active (configurable delay, typically 30–60 s). Manual abort station live. Fire pumps transition to AUTO-run on pressure drop below 10.5 bar (FP-01) / 9.5 bar (FP-02). This is the last safe window for manual abort. |
5 | Discharge / Post-Discharge Lockout | Red (is-active) | Pre-action solenoid valves open. FM-200 cylinders (or inert-gas bank) discharge to protected zone. Discharge must complete within ≤10 s (halocarbon, NFPA 2001). Hold time ≥10 min. Post-discharge lockout is maintained until a qualified technician performs manual key-reset at the FACP. |
N2 purge — pre-action supervision
data-state="standby" (ISA-18.2 normal, not an alarm). Amber pipe colour in the SVG is DOMAIN colour for N2/inert-gas medium — not a status colour.NFPA 13 / ASHRAE 62.1 · STANDARD
#ef4444) is reserved exclusively for active alarm / trip / fire / active discharge (stages 3 and 5, and any pipe in flow-fire animation). The N2 supply pipes are rendered in amber (--n2-amber: #fbbf24) because amber is the domain colour for inert-gas medium, not a fault indicator. Confusing domain colour with alarm colour is a known BMS anti-pattern per doc-10 §Color and doc-27 §3.3 — this cockpit does not repeat it.05 Pressure thresholds & pump start logic
The fire-pump ladder is driven by a set of deterministic pressure setpoints. The jockey pump maintains static pressure; progressive pressure drops trigger each successive pump start. All thresholds are displayed explicitly in the cockpit per doc-05 §Pressure Thresholds.
| Setpoint | Value (bar) | Meaning |
|---|---|---|
P_STATIC | 12.5 | Normal static system pressure maintained by jockey pump. |
P_JOCKEY_ON | 11.5 | Jockey pump start (minor leakage / test demand). |
P_JOCKEY_OFF | 12.8 | Jockey pump stop (normal pressure restored). |
P_FP1_ON | 10.5 | Main fire pump FP-01 (electric · 227 m³/h · 75 kW) auto-start. |
P_FP2_ON | 9.5 | Diesel standby pump FP-02 (227 m³/h) auto-start. |
P_LOW_ALM | 8.5 | Low pressure alarm — operator intervention required. |
06 Worked example — 2 688 m³ gross volume → FM-200 agent mass band
This example bridges the cockpit context (operational state machine) to the NFPA 2001 agent-quantity lookup. The cockpit does not execute this calculation — it is shown here as illustrative context linking the protected enclosure geometry to the sizing basis. Full calculation is in manual/fire.html and js/fire-engine.js.
- Gross enclosure: 32 m × 20 m × 4.2 m = 2 688 m³
- Agent: FM-200 (HFC-227ea). NFPA 2001 Class-A design concentration: 7.0%
- Specific vapour volume at 20 °C:
s = 0.1269 + 0.0005132·20 =0.13716 m³/kg - Agent mass:
W = (2688 / 0.13716) · (7.0 / 93.0) =1 478 kg - Intensity check:
1478 / 2688 =0.550 kg/m³ — within the NFPA 2001 design band of 5.1–5.5 kg/m³ per 100 m³ basis. - Occupant safety: NOAEL 9.0% > design 7.0% → margin 2.0 pts ✓
- Discharge time limit (halocarbon): ≤ 10 s — cockpit Stage 5 triggers the discharge sequence; the physical cylinder bank must meet this limit.
- Post-discharge hold time: ≥ 10 min before ventilation re-entry. Cockpit shows lockout state until manual key-reset.
SITE_RACK_FOOTPRINT_CONTEXT_M3 = 7,200 m³ value is a non-sizing, site-wide rack-footprint proxy. The 2,688 m³ gross enclosure above is an illustrative input to the agent-mass example, not evidence that the current site has that protected volume. Production sizing requires surveyed gross and net zone volumes, leakage and room-integrity evidence, and approval by the qualified fire-protection engineer, suppression supplier and AHJ.07 References & standards
- ISA-18.2 — Management of Alarm Systems for the Process Industries: seven-state alarm model (Normal, UNACK, ACK, RTN, Shelved, Suppressed, OOS), severity tiers, colour discipline (status wins over domain).
- NFPA 2001 (2022) — Clean Agent Fire Extinguishing Systems: FM-200 / Novec 1230 / IG-541 agent quantity equations, design concentrations, NOAEL, discharge time (≤10 s halocarbon), hold time (≥10 min).
- NFPA 72 — National Fire Alarm & Signaling Code: VESDA zone coverage, spot-detector spacing, FACP supervision, alarm notification.
- NFPA 13 — Installation of Sprinkler Systems: pre-action system piping, N2 supervisory pressure, wet-pipe / dry-pipe differences.
- ASHRAE 62.1 — Ventilation for Acceptable Indoor Air Quality: smoke-control mode on confirmed alarm (AHU/CRAH shutdown + fire-damper close).
- Alarm engine source —
js/rz-alarm-state.js(RZAlarmState v1.43.4): ISA-18.2 state model + resolveColor() + deriveFromEquipment() + audit(). - Cockpit source —
fire-system.htmlinline script (deterministic state machine, no PRNG) +js/conv-engine.js(CONV_CALC basis snapshot) +js/rz-line-model.js(SVG pipe tagging) +js/rz-inspector.js(click-through inspector).
08 Assumptions & limitations
The cockpit is a demonstration and training tool only — it is not connected to a real FACP, real smoke detectors, or live suppression cylinders. Simulation mode requires explicit ARM before any stage can advance, and all staged scenarios are deterministic (no random alarm generation). Pressure values are simulated based on the stage rules, not measured from real transducers.
The 7,200 m³ rack-footprint context uses 2,000 racks × 1.2 m² × 3.0 m only for BMS-suite reconciliation. It is not a protected-volume derivation and deliberately excludes the surveyed gross/net zone geometry, raised-floor void, ceiling plenum, obstructions, leakage and actual clear height required for suppression design. Final system design and AHJ approval must be performed by a qualified fire-protection engineer. The NFPA 2001 agent-mass worked example in §06 is illustrative; it does not substitute for a sealed engineering calculation.
The ISA-18.2 alarm-colour rule (red reserved for alarmActive = true states only) is strictly enforced in the cockpit UI. Operators trained on systems that use red for "anything abnormal" must note that amber and grey are the correct colours for shelved, suppressed, and OOS states in this implementation.