Module 6: Manuals & Deployment Documentation
| Document ID | Revision | Date | Owner | Status |
|---|---|---|---|---|
| MR-ENG-M6-001 | A | 2026-09-13 | Field Operations & Documentation | Released for review |
6.1 Scope
This document contains three parts: Part A Assembly & Deployment Guide, Part B Field Service Manual, and Part C Operator Configuration Manual, for the Money Roll micro-ATM.
Part A: Assembly & Deployment Guide
A.1 Exploded View and Parts Callout
(1)
|
+------v------+
| Top cover |
+------+------+
|
+------v------+ (2) Bezel + Apex 7000 validator assembly
| Front panel |<----
+------+------+ (3) Card dispenser bezel slot (CRT-591)
|
+------v------+
| Main chassis|---- (4) STM32F407 controller board
| frame |---- (5) Raspberry Pi CM4 carrier
+------+------+---- (6) LSM6DSO IMU mount point
|
+------v------+
| Cassette bay|---- (7) Steel cassette, Abloy Protec2 lock
+------+------+---- (8) EE-SX671 beam-break emitter/receiver
|
+------v------+
| Base / anchor|--- (9) Anchor plate, 4x M10 holes
| plate |--- (10) Grounding stud
+---------------+
| Callout | Part | Reference |
|---|---|---|
| 1 | Top cover, powder-coated steel | Module 3 drawing MR-M3-100 |
| 2 | Bezel + Pyramid Apex 7000 validator assembly | Module 1, Section 1.5.1 |
| 3 | Card dispenser bezel slot, Creator CRT-591 | Module 2, Section 2.2 |
| 4 | STM32F407 real-time controller board | Module 4 drawing MR-M4-030 |
| 5 | Raspberry Pi CM4 carrier board | Module 4 drawing MR-M4-031 |
| 6 | LSM6DSO IMU mount point | Module 1, Section 1.6.1 |
| 7 | Steel cassette assembly, Abloy Protec2 cam lock | Module 1, Section 1.5.3 |
| 8 | EE-SX671 beam-break pair | Module 1, Section 1.6.1 |
| 9 | Base anchor plate, 4x M10 clearance holes | This document, Section A.2 |
| 10 | Single-point PE grounding stud | This document, Section A.4 |
A.2 Floor and Wall Anchoring
A.2.1 Floor Mount (Primary Method)
| Parameter | Specification |
|---|---|
| Anchor type | 4 x M10 wedge anchors |
| Substrate | Concrete, minimum 20 MPa compressive strength |
| Embedment depth | 60 mm |
| Tightening torque | 45 N.m |
| Anchor pattern | Rectangular, per base plate template MR-M3-101 |
WARNING: Do not anchor into concrete rated below 20 MPa or into slab thinner than 100 mm. Verify slab rating with facility documentation or a core sample test before drilling.
A.2.2 Wall-Mount Alternative
| Parameter | Specification |
|---|---|
| Substrate | Steel studs, minimum 1.6 mm gauge, 400 mm on-center |
| Fasteners | 4 x M10 through-bolts with backing plate spanning at least 2 studs |
| Load rating requirement | Bracket and studs must support 3x static unit weight (unit weight approx. 95 kg fully loaded) |
A.3 Thermal Dissipation
| Path | Description |
|---|---|
| Intake | Lower rear vent, filtered, draws ambient air across CM4 and STM32F407 boards |
| Exhaust | Upper rear fan (12 V DC, PWM-controlled), exhausts warm air away from customer-facing bezel |
| Fan direction | Rear-intake, top-rear-exhaust, negative-pressure bias to reduce dust ingress at the bezel |
| Thermal interlock | CM4 SoC temperature above 75 C ramps fan to 100 percent duty; above 85 C triggers a service-menu warning and throttles non-essential background tasks |
A.4 Grounding
| Parameter | Specification |
|---|---|
| Ground point | Single-point PE (protective earth) stud on base plate |
| Bonding resistance | <= 0.1 Ohm chassis to PE stud |
| Conductor | 4 mm squared green/yellow insulated copper |
| Verification | Continuity test with calibrated milliohm meter at commissioning |
WARNING: All exposed metal enclosure sections must bond to the single PE stud before mains power is connected. Do not create secondary ground paths through building steel; this can defeat the dye-pack fire circuit's isolation assumptions (Module 1, Section 1.3, Module 4).
A.5 Mains Power
| Parameter | Specification |
|---|---|
| Inlet | IEC C14 |
| Fuse | 6 A slow-blow (T6A), in-line at inlet |
| Input range | 100-240 V AC, 50/60 Hz, auto-sensing supply |
A.6 Commissioning Checklist
- Confirm anchoring torque (45 N.m) on all 4 anchors with calibrated torque wrench.
- Confirm PE bonding resistance <= 0.1 Ohm.
- Power on, verify STM32F407 and CM4 boot, confirm boot log has no fault codes.
- Verify Apex 7000 validator STATUS response over ID-003 (Module 1, Section 1.3).
- Verify CRT-591 dispenser STATUS response and hopper count (Module 2, Section 2.5).
- Load empty test cassette, confirm micro-switch presence detect and RFID identity read.
- Run tamper self-test: open front door in DISARMED state, confirm log entry, no fire.
- Arm system, confirm state machine transitions to ARMED on service menu.
- Confirm network connectivity: Ethernet primary link up, LTE fallback registers to carrier.
- Confirm Horizon connectivity per
/etc/moneyroll/stellar.toml(Part C, Section C.5). - Run one end-to-end test transaction: insert test note, confirm ledger credit, dispense test card.
- Sign and file commissioning report with unit serial number, cassette RFID ID, and technician ID.
Part B: Field Service Manual
B.1 Cassette Swap Protocol
WARNING: Cassette swap requires dual control (two authorized technicians) and must only be performed with the system in DISARMED state.
- Both technicians authenticate at the service menu (PIN plus fleet 2FA token) to enter Service Mode.
- Confirm arming state indicator reads DISARMED (physical LED off). If ARMED, execute disarm procedure (Section B.1.1) before proceeding.
- Technician A opens the rear service door using the physical key.
- Technician B visually confirms the mechanical safety pin is inserted into the dye canister carriage (Module 1, Section 1.7.4).
- Release the cassette sliding rail latch, withdraw the loaded cassette along its rail.
- Confirm micro-switch reports cassette-removed and log entry is generated (expected, non-alarming while DISARMED).
- Insert replacement empty cassette, confirm rail latch engages and micro-switch reports cassette-seated.
- Confirm RFID reader reads and logs the new cassette identity.
- Remove the mechanical safety pin from the canister carriage only after the new cassette is confirmed seated.
- Close and lock the rear service door.
- Re-arm the system via the service menu; both technicians acknowledge the tamper log summary presented on screen before exiting Service Mode.
- Transport the removed cassette in a sealed, logged transit case to the cash processing facility.
B.1.1 Dye-Pack SAFE-ARM / DISARM Checklist
WARNING: Never bypass the mechanical safety pin. Capacitor-backed reserve power can fire the canister even with mains disconnected (Module 1, Section 1.7.4).
DISARM (before service):
- Enter Service Mode with valid 2FA.
- Confirm on-screen state reads ARMED before initiating disarm (sanity check).
- Issue disarm command; confirm physical arm-indicator LED turns off.
- Insert mechanical safety pin into canister carriage.
- Confirm log entry: DISARM event, technician ID, timestamp.
ARM (after service, before closing unit to customer traffic):
- Remove mechanical safety pin.
- Confirm rear and front doors closed and latched (micro-switch state clear).
- Confirm cassette seated (micro-switch and RFID both report present).
- Issue arm command from service menu; confirm arm-indicator LED illuminates.
- Confirm log entry: ARM event, technician ID, timestamp.
- Acknowledge tamper log summary before exiting Service Mode.
B.2 Card Hopper Refill
- Enter Service Mode.
- Open front service panel to access CRT-591 hopper.
- Load up to 200 CR80 card blanks, orientation per hopper label arrow.
- Close panel, issue STATUS command from service menu, confirm hopper count matches load.
B.3 Bill Validator Lens Cleaning
| Parameter | Value |
|---|---|
| Interval | Quarterly |
| Materials | Pyramid Apex 7000 manufacturer cleaning card, isopropyl alcohol (IPA) 99 percent, lint-free cloth |
| Procedure | Insert cleaning card per manufacturer instructions, cycle 5 times; wipe accessible bezel glass with IPA-dampened lint-free cloth; do not use abrasive materials |
B.4 Roller and Belt Inspection
| Interval | Check |
|---|---|
| Monthly | Visual inspection of silicone transport rollers for glazing, cracking, or debris buildup |
| Quarterly | Belt tension check on stepper-driven transport, replace if deflection exceeds 3 mm under 500 g load |
| Annually | Full roller replacement regardless of visible wear |
B.5 Dye Canister Inspection and Replacement
| Parameter | Value |
|---|---|
| Shelf life | 5 years from manufacture date printed on canister label |
| Inspection interval | Annually, check for seal integrity, pressure indicator (if equipped), and corrosion |
| Replacement | Required at 5-year shelf-life expiry or immediately after any FIRED event |
B.6 Preventive Maintenance Schedule
| Task | Interval |
|---|---|
| Bill validator lens cleaning | Quarterly |
| Card hopper refill | As needed, approx. weekly |
| Cleaning card pass through CRT-591 | Monthly |
| Roller/belt visual inspection | Monthly |
| Belt tension check | Quarterly |
| Dye canister inspection | Annually |
| Dye canister replacement | 5 years or after FIRED event |
| Cassette swap and cash pickup | Per fleet cash-management schedule, typically weekly |
| Tamper sensor functional test | Quarterly |
| Firmware/OS patch review | Monthly (Part C, Section C.1) |
| Full preventive maintenance visit | Semi-annually |
B.7 Troubleshooting Table
| Symptom | Likely Cause | Action |
|---|---|---|
| Validator rejects all notes | Dirty optical/IR lens | Perform lens cleaning (Section B.3) |
| Validator not responding to poll | ID-003 UART cable disconnected or optoisolator fault | Check J4 connector seating, test optoisolator continuity |
| Note jams repeatedly at bezel | Bezel misalignment beyond tolerance | Re-fixture bezel per Module 1, Section 1.5.1, verify with alignment gauge |
| Cassette will not seat | Rail obstruction or bent guide | Inspect rail, clear debris, replace bent guide |
| Cassette RFID not read | Tag damaged or reader antenna misaligned | Replace RFID tag, re-seat cassette, check reader wiring |
| False tamper alerts on door | Micro-switch debounce fault or worn switch | Replace Omron D2F-01L switch, verify debounce firmware config |
| False tamper alerts on tilt | IMU mounting loose or miscalibrated zero reference | Re-torque IMU mount, recalibrate zero-tilt reference in service menu |
| Dye pack fires unexpectedly | Fault in tamper relay board or bypassed safety pin during service | Immediately DISARM, inspect Module 4 relay board, review tamper log, escalate to engineering |
| Card dispenser reports E01 hopper empty | Hopper depleted | Refill hopper (Section B.2) |
| Card dispenser reports E02 jam | Debris or misfed card in transport path | Open service panel, clear jam, run cleaning card |
| Card dispenser reports E03/E04 encode failure | Chip/antenna contact fault or corrupted personalization data | Retry, if persistent replace encode station or escalate to Module 2 vendor support |
| Reader fails authentication repeatedly | Card cloned/damaged, or fleet key mismatch after rotation | Check card status server-side, verify fleet key version, reissue card if legitimate |
| Network offline, LTE fallback also down | SIM/APN misconfiguration or carrier outage | Check ModemManager status, verify SIM, escalate to carrier if outage confirmed |
| Unit fails to boot | Corrupted overlayfs upper layer or TPM unlock failure | Boot to recovery partition, restore known-good overlay image, verify TPM state |
| Fan not spinning, thermal warning shown | Fan connector disconnected or fan failure | Inspect connector, replace fan (12 V DC PWM) |
| Ink stain visible on cassette exterior with no FIRED log entry | Canister seal leak, not a genuine trigger event | Treat as hazard, wear gloves, replace canister and cassette, inspect for external damage |
B.8 Spare Parts List
| Part | Vendor/Part Number | Typical Stock Qty per Depot |
|---|---|---|
| Bill validator | Pyramid Apex 7000 | 2 |
| Card dispenser | Creator CRT-591 | 2 |
| Micro-switch | Omron D2F-01L | 10 |
| Beam-break sensor pair | Omron EE-SX671 | 4 |
| IMU module | STMicroelectronics LSM6DSO breakout | 4 |
| Stepper motor | NEMA 17, 17HS4401 | 4 |
| Stepper driver | TMC2209 | 4 |
| Cassette lock cylinder | Abloy Protec2 cam lock | 4 |
| Dye canister assembly | 60 ml solenoid-actuated ink cartridge | 6 |
| RFID tag | NXP NTAG213 | 20 |
| NFC/EMV hybrid reader | Creator CRT-310 | 2 |
| Fan assembly | 12 V DC PWM, 80 mm | 4 |
| Fuse, mains inlet | 6 A slow-blow (T6A) | 20 |
Part C: Operator Configuration Manual
C.1 Debian 12 Hardening
| Control | Implementation |
|---|---|
| Root filesystem | Read-only via overlayfs, with tmpfs upper layer discarded on reboot for non-persistent state |
| Data partition | LUKS2-encrypted, key sealed to TPM 2.0 PCRs (boot chain measurement), auto-unlocked via clevis and tpm2-tools at boot |
| Unused services | Disabled: bluetooth, cups, avahi-daemon, rpcbind |
| SSH | Key-only authentication, password auth disabled, reachable only via out-of-band WireGuard management VPN, not exposed on customer-facing network interfaces |
| Unattended upgrades | Enabled, pinned to security-only repository, staged rollout via fleet canary group before full deployment |
| Audit | auditd enabled, rules watching /etc/moneyroll/, key management operations, and sudo usage |
| Mandatory access control | AppArmor profiles enforced for moneyroll-reader.service, moneyroll-firmware-bridge.service, and the kiosk UI process |
C.1.1 Example nftables Ruleset
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
iif "lo" accept
ct state established,related accept
iif "wg0" tcp dport 22 accept
ip protocol icmp accept
counter drop
}
chain forward {
type filter hook forward priority 0; policy drop;
}
chain output {
type filter hook output priority 0; policy accept;
}
}
C.2 Network Configuration
| Interface | Role | Priority/Metric |
|---|---|---|
| eth0 | Primary Ethernet uplink | Metric 100 (NetworkManager) |
| wwan0 (LTE modem, managed by ModemManager) | Fallback WAN | Metric 600, activated by NetworkManager connectivity check on eth0 failure |
| wg0 | WireGuard tunnel to fleet management VPN | Always up, routes management/telemetry traffic only |
| NTP | Time sync | chrony or systemd-timesyncd against fleet-internal NTP pool with public pool fallback |
C.3 Hot-Wallet Key Management
| Aspect | Policy |
|---|---|
| Key storage | TPM-sealed distributor account signing key, never leaves TPM in plaintext |
| Funding policy | Distributor account maintained above a minimum float threshold (configurable, default 500 USDC equivalent); automated top-up alert below threshold |
| Sweep procedure | Scheduled sweep of accumulated customer-credit obligations from distributor account to cold treasury account at end of business day, logged and reconciled against ledger |
| Key rotation | Rotated every 180 days or immediately upon suspected compromise, via TPM re-seal procedure requiring dual-control authorization |
| Emergency freeze | Fleet backend can issue an immediate freeze command halting all outbound Stellar payment operations terminal-wide, pending investigation |
C.4 Horizon Endpoint Configuration
/etc/moneyroll/stellar.toml:
[horizon]
primary_url = "https://horizon.stellar.org"
fallback_url = "https://horizon-backup.moneyroll-fleet.internal"
network_passphrase = "Public Global Stellar Network ; September 2015"
connect_timeout_ms = 3000
request_timeout_ms = 8000
[fee_bump]
enabled = true
max_base_fee_stroops = 10000
policy = "escalate_on_timeout"
C.5 Fee Configuration
/etc/moneyroll/fees.toml:
[fees]
service_fee_usd = 1.00
card_fee_usd = 10.00
bridge_spread = 0.005
C.6 On-Screen Service Menu Reference
| Access | Hold logo for 5 seconds, then enter service PIN |
|---|
| Screen | Contents |
|---|---|
| Validator status | Live ID-003 event log, last accept/reject decisions, denomination counts |
| Cassette level | Current note count estimate, capacity remaining, RFID identity |
| Tamper arm/disarm | Current state machine status, arm/disarm controls with 2FA prompt, tamper log |
| Dispenser hopper/tests | Hopper count, capture bin count, manual dispense/encode test |
| Reader test | Manual card read test, APDU/RF passthrough diagnostics |
| Network | Interface status (Ethernet, LTE, WireGuard), signal strength, connectivity test |
| Power rails | 12 V, 5 V, 3.3 V rail voltage and current readouts from Module 4 monitoring |
| Logs export | Export local SQLite journal and auditd logs to USB or push to fleet backend |
C.7 Remote Fleet Telemetry
MQTT over TLS is used for fleet telemetry and command channels.
| Topic | Direction | Payload |
|---|---|---|
moneyroll/{unit_id}/status/heartbeat | Publish | Uptime, firmware version, network health, timestamp |
moneyroll/{unit_id}/status/tamper | Publish | State machine transitions, sensor triggers |
moneyroll/{unit_id}/status/cassette | Publish | Cassette fill level, RFID identity, swap events |
moneyroll/{unit_id}/status/dispenser | Publish | Hopper level, capture bin count, error codes |
moneyroll/{unit_id}/status/power | Publish | Rail voltages/currents, fan duty cycle, thermal state |
moneyroll/{unit_id}/cmd/freeze | Subscribe | Emergency freeze command from fleet backend |
moneyroll/{unit_id}/cmd/arm | Subscribe | Remote arm/disarm authorization token |
moneyroll/{unit_id}/cmd/config-update | Subscribe | Signed config bundle push (fees.toml, stellar.toml updates) |