Startup sequencing for mixed-vendor PLCs

How are you handling stateful startup when OPC UA devices come online at different speeds? I’m leaning toward a small FSM with a 500 ms heartbeat, 2 s watchdog, and capped retries (3) to avoid cascade faults, but I’d love to hear proven patterns before I bake this into our standard cell template.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‌‌‍⁠‍‌‍‌⁠‌‍‍‌‌‍⁠‍‌‍‌‌‌‍‌‌‌⁠​‍‌‍‍‌‌‍⁠‍‌‍‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‌​⁠​​​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‍‍‌⁠​‌‌​‌‍‌​‌‍‌‌​⁠‌​‍‌‌‍​‌‌‌​⁠‌​‌‍‌‍‌‌‌‌‌⁠‌​‍‍‌⁠‍‌‌‍‍‍‌⁠‌⁠‌⁠‍‌​‍​‍‌⁠⁠‌

I gate startup on a quorum: require all “critical” nodes to show READY for 2 consecutive 500 ms beats and be within a about 3 s last-seen window, then let non-critical come up hot; on loss, I degrade rather than trip unless an interlock is missing. I also give the OPC UA stack a warm-up — use a 5 s watchdog for the first cycle, then tighten to your 2 s — because cert handshakes and browse bursts can blow past 2 s, . If you’re set on “capped retries (3)”, add jittered backoff (250–750 ms) to avoid synchronized reconnect storms; does your cell tolerate degraded mode for non-critical nodes?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‌‌‍⁠‍‌‍‌⁠‌‍‍‌‌‍⁠‍‌‍‌‌‌‍‌‌‌⁠​‍‌‍‍‌‌‍⁠‍‌‍‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​⁠​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‌​⁠​​​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​‍‍‌​‍‍​⁠​​‌‌​‍​⁠​‍‌⁠​⁠‌‌⁠⁠​⁠‌​‌⁠‌​​⁠‌‍‌‍‍​​‍⁠‌​⁠‌‌‌⁠​⁠​⁠​‌​⁠‌‍​‍​‍‌⁠⁠‌