MR

Money Roll Engineering Package

Rev A · 2026-09-13 · Released for review

← Kiosk

Module 06

Manuals & Deployment Documentation

Assembly & deployment guide, field service manual (cassette swap, hopper refill, dye safe-arm), and operator configuration manual (OS hardening, network, hot wallet).

Module 6: Manuals & Deployment Documentation

Document IDRevisionDateOwnerStatus
MR-ENG-M6-001A2026-09-13Field Operations & DocumentationReleased for review

6.1 Scope

This document contains three parts: Part A Assembly & Deployment Guide, Part B Field Service Manual, and Part C Operator Configuration Manual, for the Money Roll micro-ATM.

Part A: Assembly & Deployment Guide

A.1 Exploded View and Parts Callout

              (1)
               |
        +------v------+
        |  Top cover   |
        +------+------+
               |
        +------v------+     (2) Bezel + Apex 7000 validator assembly
        |  Front panel |<----
        +------+------+     (3) Card dispenser bezel slot (CRT-591)
               |
        +------v------+
        |  Main chassis|---- (4) STM32F407 controller board
        |  frame       |---- (5) Raspberry Pi CM4 carrier
        +------+------+---- (6) LSM6DSO IMU mount point
               |
        +------v------+
        |  Cassette bay|---- (7) Steel cassette, Abloy Protec2 lock
        +------+------+---- (8) EE-SX671 beam-break emitter/receiver
               |
        +------v------+
        |  Base / anchor|--- (9) Anchor plate, 4x M10 holes
        |  plate         |--- (10) Grounding stud
        +---------------+
CalloutPartReference
1Top cover, powder-coated steelModule 3 drawing MR-M3-100
2Bezel + Pyramid Apex 7000 validator assemblyModule 1, Section 1.5.1
3Card dispenser bezel slot, Creator CRT-591Module 2, Section 2.2
4STM32F407 real-time controller boardModule 4 drawing MR-M4-030
5Raspberry Pi CM4 carrier boardModule 4 drawing MR-M4-031
6LSM6DSO IMU mount pointModule 1, Section 1.6.1
7Steel cassette assembly, Abloy Protec2 cam lockModule 1, Section 1.5.3
8EE-SX671 beam-break pairModule 1, Section 1.6.1
9Base anchor plate, 4x M10 clearance holesThis document, Section A.2
10Single-point PE grounding studThis document, Section A.4

A.2 Floor and Wall Anchoring

A.2.1 Floor Mount (Primary Method)

ParameterSpecification
Anchor type4 x M10 wedge anchors
SubstrateConcrete, minimum 20 MPa compressive strength
Embedment depth60 mm
Tightening torque45 N.m
Anchor patternRectangular, per base plate template MR-M3-101

WARNING: Do not anchor into concrete rated below 20 MPa or into slab thinner than 100 mm. Verify slab rating with facility documentation or a core sample test before drilling.

A.2.2 Wall-Mount Alternative

ParameterSpecification
SubstrateSteel studs, minimum 1.6 mm gauge, 400 mm on-center
Fasteners4 x M10 through-bolts with backing plate spanning at least 2 studs
Load rating requirementBracket and studs must support 3x static unit weight (unit weight approx. 95 kg fully loaded)

A.3 Thermal Dissipation

PathDescription
IntakeLower rear vent, filtered, draws ambient air across CM4 and STM32F407 boards
ExhaustUpper rear fan (12 V DC, PWM-controlled), exhausts warm air away from customer-facing bezel
Fan directionRear-intake, top-rear-exhaust, negative-pressure bias to reduce dust ingress at the bezel
Thermal interlockCM4 SoC temperature above 75 C ramps fan to 100 percent duty; above 85 C triggers a service-menu warning and throttles non-essential background tasks

A.4 Grounding

ParameterSpecification
Ground pointSingle-point PE (protective earth) stud on base plate
Bonding resistance<= 0.1 Ohm chassis to PE stud
Conductor4 mm squared green/yellow insulated copper
VerificationContinuity test with calibrated milliohm meter at commissioning

WARNING: All exposed metal enclosure sections must bond to the single PE stud before mains power is connected. Do not create secondary ground paths through building steel; this can defeat the dye-pack fire circuit's isolation assumptions (Module 1, Section 1.3, Module 4).

A.5 Mains Power

ParameterSpecification
InletIEC C14
Fuse6 A slow-blow (T6A), in-line at inlet
Input range100-240 V AC, 50/60 Hz, auto-sensing supply

A.6 Commissioning Checklist

  1. Confirm anchoring torque (45 N.m) on all 4 anchors with calibrated torque wrench.
  2. Confirm PE bonding resistance <= 0.1 Ohm.
  3. Power on, verify STM32F407 and CM4 boot, confirm boot log has no fault codes.
  4. Verify Apex 7000 validator STATUS response over ID-003 (Module 1, Section 1.3).
  5. Verify CRT-591 dispenser STATUS response and hopper count (Module 2, Section 2.5).
  6. Load empty test cassette, confirm micro-switch presence detect and RFID identity read.
  7. Run tamper self-test: open front door in DISARMED state, confirm log entry, no fire.
  8. Arm system, confirm state machine transitions to ARMED on service menu.
  9. Confirm network connectivity: Ethernet primary link up, LTE fallback registers to carrier.
  10. Confirm Horizon connectivity per /etc/moneyroll/stellar.toml (Part C, Section C.5).
  11. Run one end-to-end test transaction: insert test note, confirm ledger credit, dispense test card.
  12. Sign and file commissioning report with unit serial number, cassette RFID ID, and technician ID.

Part B: Field Service Manual

B.1 Cassette Swap Protocol

WARNING: Cassette swap requires dual control (two authorized technicians) and must only be performed with the system in DISARMED state.

  1. Both technicians authenticate at the service menu (PIN plus fleet 2FA token) to enter Service Mode.
  2. Confirm arming state indicator reads DISARMED (physical LED off). If ARMED, execute disarm procedure (Section B.1.1) before proceeding.
  3. Technician A opens the rear service door using the physical key.
  4. Technician B visually confirms the mechanical safety pin is inserted into the dye canister carriage (Module 1, Section 1.7.4).
  5. Release the cassette sliding rail latch, withdraw the loaded cassette along its rail.
  6. Confirm micro-switch reports cassette-removed and log entry is generated (expected, non-alarming while DISARMED).
  7. Insert replacement empty cassette, confirm rail latch engages and micro-switch reports cassette-seated.
  8. Confirm RFID reader reads and logs the new cassette identity.
  9. Remove the mechanical safety pin from the canister carriage only after the new cassette is confirmed seated.
  10. Close and lock the rear service door.
  11. Re-arm the system via the service menu; both technicians acknowledge the tamper log summary presented on screen before exiting Service Mode.
  12. Transport the removed cassette in a sealed, logged transit case to the cash processing facility.

B.1.1 Dye-Pack SAFE-ARM / DISARM Checklist

WARNING: Never bypass the mechanical safety pin. Capacitor-backed reserve power can fire the canister even with mains disconnected (Module 1, Section 1.7.4).

DISARM (before service):

  1. Enter Service Mode with valid 2FA.
  2. Confirm on-screen state reads ARMED before initiating disarm (sanity check).
  3. Issue disarm command; confirm physical arm-indicator LED turns off.
  4. Insert mechanical safety pin into canister carriage.
  5. Confirm log entry: DISARM event, technician ID, timestamp.

ARM (after service, before closing unit to customer traffic):

  1. Remove mechanical safety pin.
  2. Confirm rear and front doors closed and latched (micro-switch state clear).
  3. Confirm cassette seated (micro-switch and RFID both report present).
  4. Issue arm command from service menu; confirm arm-indicator LED illuminates.
  5. Confirm log entry: ARM event, technician ID, timestamp.
  6. Acknowledge tamper log summary before exiting Service Mode.

B.2 Card Hopper Refill

  1. Enter Service Mode.
  2. Open front service panel to access CRT-591 hopper.
  3. Load up to 200 CR80 card blanks, orientation per hopper label arrow.
  4. Close panel, issue STATUS command from service menu, confirm hopper count matches load.

B.3 Bill Validator Lens Cleaning

ParameterValue
IntervalQuarterly
MaterialsPyramid Apex 7000 manufacturer cleaning card, isopropyl alcohol (IPA) 99 percent, lint-free cloth
ProcedureInsert cleaning card per manufacturer instructions, cycle 5 times; wipe accessible bezel glass with IPA-dampened lint-free cloth; do not use abrasive materials

B.4 Roller and Belt Inspection

IntervalCheck
MonthlyVisual inspection of silicone transport rollers for glazing, cracking, or debris buildup
QuarterlyBelt tension check on stepper-driven transport, replace if deflection exceeds 3 mm under 500 g load
AnnuallyFull roller replacement regardless of visible wear

B.5 Dye Canister Inspection and Replacement

ParameterValue
Shelf life5 years from manufacture date printed on canister label
Inspection intervalAnnually, check for seal integrity, pressure indicator (if equipped), and corrosion
ReplacementRequired at 5-year shelf-life expiry or immediately after any FIRED event

B.6 Preventive Maintenance Schedule

TaskInterval
Bill validator lens cleaningQuarterly
Card hopper refillAs needed, approx. weekly
Cleaning card pass through CRT-591Monthly
Roller/belt visual inspectionMonthly
Belt tension checkQuarterly
Dye canister inspectionAnnually
Dye canister replacement5 years or after FIRED event
Cassette swap and cash pickupPer fleet cash-management schedule, typically weekly
Tamper sensor functional testQuarterly
Firmware/OS patch reviewMonthly (Part C, Section C.1)
Full preventive maintenance visitSemi-annually

B.7 Troubleshooting Table

SymptomLikely CauseAction
Validator rejects all notesDirty optical/IR lensPerform lens cleaning (Section B.3)
Validator not responding to pollID-003 UART cable disconnected or optoisolator faultCheck J4 connector seating, test optoisolator continuity
Note jams repeatedly at bezelBezel misalignment beyond toleranceRe-fixture bezel per Module 1, Section 1.5.1, verify with alignment gauge
Cassette will not seatRail obstruction or bent guideInspect rail, clear debris, replace bent guide
Cassette RFID not readTag damaged or reader antenna misalignedReplace RFID tag, re-seat cassette, check reader wiring
False tamper alerts on doorMicro-switch debounce fault or worn switchReplace Omron D2F-01L switch, verify debounce firmware config
False tamper alerts on tiltIMU mounting loose or miscalibrated zero referenceRe-torque IMU mount, recalibrate zero-tilt reference in service menu
Dye pack fires unexpectedlyFault in tamper relay board or bypassed safety pin during serviceImmediately DISARM, inspect Module 4 relay board, review tamper log, escalate to engineering
Card dispenser reports E01 hopper emptyHopper depletedRefill hopper (Section B.2)
Card dispenser reports E02 jamDebris or misfed card in transport pathOpen service panel, clear jam, run cleaning card
Card dispenser reports E03/E04 encode failureChip/antenna contact fault or corrupted personalization dataRetry, if persistent replace encode station or escalate to Module 2 vendor support
Reader fails authentication repeatedlyCard cloned/damaged, or fleet key mismatch after rotationCheck card status server-side, verify fleet key version, reissue card if legitimate
Network offline, LTE fallback also downSIM/APN misconfiguration or carrier outageCheck ModemManager status, verify SIM, escalate to carrier if outage confirmed
Unit fails to bootCorrupted overlayfs upper layer or TPM unlock failureBoot to recovery partition, restore known-good overlay image, verify TPM state
Fan not spinning, thermal warning shownFan connector disconnected or fan failureInspect connector, replace fan (12 V DC PWM)
Ink stain visible on cassette exterior with no FIRED log entryCanister seal leak, not a genuine trigger eventTreat as hazard, wear gloves, replace canister and cassette, inspect for external damage

B.8 Spare Parts List

PartVendor/Part NumberTypical Stock Qty per Depot
Bill validatorPyramid Apex 70002
Card dispenserCreator CRT-5912
Micro-switchOmron D2F-01L10
Beam-break sensor pairOmron EE-SX6714
IMU moduleSTMicroelectronics LSM6DSO breakout4
Stepper motorNEMA 17, 17HS44014
Stepper driverTMC22094
Cassette lock cylinderAbloy Protec2 cam lock4
Dye canister assembly60 ml solenoid-actuated ink cartridge6
RFID tagNXP NTAG21320
NFC/EMV hybrid readerCreator CRT-3102
Fan assembly12 V DC PWM, 80 mm4
Fuse, mains inlet6 A slow-blow (T6A)20

Part C: Operator Configuration Manual

C.1 Debian 12 Hardening

ControlImplementation
Root filesystemRead-only via overlayfs, with tmpfs upper layer discarded on reboot for non-persistent state
Data partitionLUKS2-encrypted, key sealed to TPM 2.0 PCRs (boot chain measurement), auto-unlocked via clevis and tpm2-tools at boot
Unused servicesDisabled: bluetooth, cups, avahi-daemon, rpcbind
SSHKey-only authentication, password auth disabled, reachable only via out-of-band WireGuard management VPN, not exposed on customer-facing network interfaces
Unattended upgradesEnabled, pinned to security-only repository, staged rollout via fleet canary group before full deployment
Auditauditd enabled, rules watching /etc/moneyroll/, key management operations, and sudo usage
Mandatory access controlAppArmor profiles enforced for moneyroll-reader.service, moneyroll-firmware-bridge.service, and the kiosk UI process

C.1.1 Example nftables Ruleset

table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;
    iif "lo" accept
    ct state established,related accept
    iif "wg0" tcp dport 22 accept
    ip protocol icmp accept
    counter drop
  }
  chain forward {
    type filter hook forward priority 0; policy drop;
  }
  chain output {
    type filter hook output priority 0; policy accept;
  }
}

C.2 Network Configuration

InterfaceRolePriority/Metric
eth0Primary Ethernet uplinkMetric 100 (NetworkManager)
wwan0 (LTE modem, managed by ModemManager)Fallback WANMetric 600, activated by NetworkManager connectivity check on eth0 failure
wg0WireGuard tunnel to fleet management VPNAlways up, routes management/telemetry traffic only
NTPTime syncchrony or systemd-timesyncd against fleet-internal NTP pool with public pool fallback

C.3 Hot-Wallet Key Management

AspectPolicy
Key storageTPM-sealed distributor account signing key, never leaves TPM in plaintext
Funding policyDistributor account maintained above a minimum float threshold (configurable, default 500 USDC equivalent); automated top-up alert below threshold
Sweep procedureScheduled sweep of accumulated customer-credit obligations from distributor account to cold treasury account at end of business day, logged and reconciled against ledger
Key rotationRotated every 180 days or immediately upon suspected compromise, via TPM re-seal procedure requiring dual-control authorization
Emergency freezeFleet backend can issue an immediate freeze command halting all outbound Stellar payment operations terminal-wide, pending investigation

C.4 Horizon Endpoint Configuration

/etc/moneyroll/stellar.toml:

[horizon]
primary_url = "https://horizon.stellar.org"
fallback_url = "https://horizon-backup.moneyroll-fleet.internal"
network_passphrase = "Public Global Stellar Network ; September 2015"
connect_timeout_ms = 3000
request_timeout_ms = 8000

[fee_bump]
enabled = true
max_base_fee_stroops = 10000
policy = "escalate_on_timeout"

C.5 Fee Configuration

/etc/moneyroll/fees.toml:

[fees]
service_fee_usd = 1.00
card_fee_usd = 10.00
bridge_spread = 0.005

C.6 On-Screen Service Menu Reference

AccessHold logo for 5 seconds, then enter service PIN
ScreenContents
Validator statusLive ID-003 event log, last accept/reject decisions, denomination counts
Cassette levelCurrent note count estimate, capacity remaining, RFID identity
Tamper arm/disarmCurrent state machine status, arm/disarm controls with 2FA prompt, tamper log
Dispenser hopper/testsHopper count, capture bin count, manual dispense/encode test
Reader testManual card read test, APDU/RF passthrough diagnostics
NetworkInterface status (Ethernet, LTE, WireGuard), signal strength, connectivity test
Power rails12 V, 5 V, 3.3 V rail voltage and current readouts from Module 4 monitoring
Logs exportExport local SQLite journal and auditd logs to USB or push to fleet backend

C.7 Remote Fleet Telemetry

MQTT over TLS is used for fleet telemetry and command channels.

TopicDirectionPayload
moneyroll/{unit_id}/status/heartbeatPublishUptime, firmware version, network health, timestamp
moneyroll/{unit_id}/status/tamperPublishState machine transitions, sensor triggers
moneyroll/{unit_id}/status/cassettePublishCassette fill level, RFID identity, swap events
moneyroll/{unit_id}/status/dispenserPublishHopper level, capture bin count, error codes
moneyroll/{unit_id}/status/powerPublishRail voltages/currents, fan duty cycle, thermal state
moneyroll/{unit_id}/cmd/freezeSubscribeEmergency freeze command from fleet backend
moneyroll/{unit_id}/cmd/armSubscribeRemote arm/disarm authorization token
moneyroll/{unit_id}/cmd/config-updateSubscribeSigned config bundle push (fees.toml, stellar.toml updates)