Flood response on a half-dead network.
A serious flood does not take the network down cleanly — it leaves fragments: a cell on a generator here, a dry ridge with coverage there, a satellite dish at the staff. This mission is about operating on those fragments as if they were a network, because for the days that matter, they are the only one there is.
Civil protection agencies, municipal crisis staffs, fire services and volunteer formations directing boats and crews across a flooded area.
Cells are drowned or on failing generators; the survivors are saturated. Coverage becomes a patchwork no single device can plan around.
One mesh over whatever remains — surviving cells, the teams’ own radios, a satellite dish at the staff — with coordination ranked first.
The laptops, vehicle computers and companion computers the agency already fields. One Linux binary, one configuration file, no infrastructure of its own.
The mission
The dike gives way overnight and by morning a district is under a metre of water. The crisis staff sets up on dry ground at the edge of the basin; boats work the streets, an aircraft flies the waterline, and people are waiting on rooftops. The headquarters must direct all of it — which boat to which street, which rooftop first, where the water is still rising — across an area whose communications infrastructure is partly underwater, partly on dying generators, and everywhere overloaded by the population trying to reach relatives.
What breaks
Flood damage to a network is not an outage; it is an erosion. Base stations in the basin flood or lose power in the first hours. The ones on high ground survive — until their generators run out, one by one, over the following days. And every cell that still transmits carries the traffic of all the drowned ones plus an entire population in distress, so the surviving fragments are also the most saturated network the region has ever had. The result is a patchwork in both space and time: coverage here but not there, now but not in an hour, and no crew can know in advance which kind of street they are turning into.
The classical answers each solve a fragment of the problem. Satellite phones give the staff voice to a few crews — no video, no positions, no shared picture. A carrier’s emergency cell-on-wheels arrives after the critical first day, covers one spot and inherits the same saturation. And doctrine that assumes “the network is down” wastes the fragments that are, in fact, still up.
The architecture on this mission
Headquarters, vehicles, boats and aircraft each run the same software node and form one encrypted mesh over whatever their radios and modems can currently reach — surviving cellular here, the teams’ own IP radios there, the satellite terminal at the staff as the shared way out of the basin. No node depends on any particular fragment: each link is probed several times a second, and traffic simply rides the paths that measure alive right now. A boat that has left the last cell’s reach relays through the boat that has not; the aircraft over the waterline carries its video down whichever path currently holds.
Traffic is classed, because a half-dead network is above all a narrow one. Coordination and voice hold reserved floors; positions and tasking rank next; aerial video is elastic and sheds quality first when a fragment tightens. And the traffic that must not be lost — the coordinates of people sighted on rooftops — travels store-carry-forward: it queues on the boat’s node through any gap and delivers, in priority order, on the next contact. A gap delays that list; it no longer deletes it.
None of this requires the crews to know where coverage is. That is the point: the patchwork is measured continuously by the network itself, several times a second, and re-decided without a switchover event. “Have signal / don’t” stops being a binary the operation has to plan around and becomes a quantity the software manages.
How the operation unfolds
- The dike breaks at 02:00. The staff activates on dry ground; the headquarters node comes up bonding the satellite dish with whatever cellular survives at the site. Vehicle and boat kits authenticate by key and join as they power on — no configuration ceremony at the waterline.
- First light. Boats enter the streets. The near boats hold a surviving cell; the far boats’ traffic re-routes through them automatically. The aircraft’s video of the waterline reaches the staff over the best remaining path — the headquarters has a picture instead of a phone tree.
- A generator dies. Mid-morning a surviving cell goes dark and takes its fragment with it. Degradation is detected and traffic reweighted onto the remaining paths within roughly half a second to three quarters of a second — the crews notice nothing; the journal records everything.
- The rooftop list. A boat working beyond every fragment logs sighting after sighting. The coordinates queue on its node, ride store-carry-forward to the next contact — another boat, the aircraft passing overhead — and deliver to the staff in priority order. Late by minutes, lost never.
- Saturation peaks. The whole basin’s population is on the surviving cells. Ordered degradation engages: video sheds resolution, position updates thin, and the coordination channel — a few kilobits on a reserved floor — does not flinch.
- The debrief. The journal holds a per-link, per-hour record of what actually survived, saturated and died across the basin. That record rewrites the flood communications plan with data — and answers the after-action review with measurements instead of recollection.
What each mechanism contributes
- Self-forming mesh — headquarters, boats, vehicles and aircraft as one encrypted network over whatever fragments remain; relaying is automatic and per-hop encrypted. Shipped.
- Multi-link bonding at the staff — the satellite dish and surviving cellular as one measured connection out of the basin; the expensive link spent deliberately. Shipped.
- Class floors and ordered degradation — coordination and voice reserved, video elastic; a saturated fragment narrows the picture, never the command channel. Shipped, opt-in.
- Store-carry-forward — rooftop coordinates and sighting reports queue through gaps and deliver on the next contact, priority first. Shipped, opt-in.
- Continuous measurement and the journal — a timestamped record of every fragment’s life and death, for the debrief and the next flood plan. Shipped.
The honest boundary: Atlas cannot dry out a base station or conjure coverage where nothing transmits at all — where no fragment reaches, a node must physically go there: a boat, a vehicle on a bridge, an aircraft overhead. The boats, the aircraft, the rescue doctrine and the rescue itself are the agency’s. What the mechanisms demonstrably survive is exactly what this mission is made of: fragments appearing, saturating and dying under load.
What a pilot should prove
- One basin exercise on a real patchwork: the per-link record showing traffic riding surviving fragments, against a single-carrier baseline that goes dark.
- Coordination continuity through an induced cell loss, with the reweighting interval read from the journal, not estimated.
- Rooftop-coordinate delivery: positions generated beyond all coverage arrive complete and in priority order after reconnection.
- A debrief artefact: the per-fragment journal, usable as the measured basis of the basin’s flood communications annex.
One basin, one staff, one exercise day. The evaluation format covers the structure.