Orleans.Lattice.Api.Auth
9.9.0
dotnet add package Orleans.Lattice.Api.Auth --version 9.9.0
NuGet\Install-Package Orleans.Lattice.Api.Auth -Version 9.9.0
<PackageReference Include="Orleans.Lattice.Api.Auth" Version="9.9.0" />
<PackageVersion Include="Orleans.Lattice.Api.Auth" Version="9.9.0" />
<PackageReference Include="Orleans.Lattice.Api.Auth" />
paket add Orleans.Lattice.Api.Auth --version 9.9.0
#r "nuget: Orleans.Lattice.Api.Auth, 9.9.0"
#:package Orleans.Lattice.Api.Auth@9.9.0
#addin nuget:?package=Orleans.Lattice.Api.Auth&version=9.9.0
#tool nuget:?package=Orleans.Lattice.Api.Auth&version=9.9.0
Orleans.Lattice.Api.Auth
Optional, opt-in configuration and control facade add-on for Orleans.Lattice authorization. Exposes a single transport-agnostic admin surface that administers the membership directory and the authorization policy store from one place. A sibling package projects this facade onto a code-first gRPC surface.
Design
The facade mirrors the read-only Orleans.Lattice.Api.State and the read-write
Orleans.Lattice.Api.Data facades: the facade is the contract, transports bind
over it, and it costs nothing until it is registered.
One combined admin surface carries:
- Membership admin. CRUD groups, add / remove membership edges, and list them (there is no user CRUD: users are not records this facade manages).
- Policy admin. CRUD authorization rules and list / enumerate them.
ExplainAsync. Returns the authorization verdict for a subject, operation, and scope, plus the rules that apply, for debugging policy. The verdict is produced by the same access gate the data plane consults, evaluated for the subject as the membership directory resolves it (the id plus its directory group closure; token-asserted groups are not included).EffectivePermissionsAsync. Returns every authored rule that names a subject directly or through one of its groups, for dashboards and UX - a listing, not a resolved verdict. It reads the live policy store, so it reflects a policy change as soon as the change commits.- Identity directory and access model.
SearchDirectoryAsyncandResolveDirectoryPrincipalAsyncsearch and resolve principals in the configured identity directory (an explicit unavailable result, not an error, when none is configured), andGetAccessModelAsyncreports the cluster's best-effort access-model posture.
Security
This is an administrative control plane, so every operation is itself authorized as an administrator. The facade routes each call through the same enforcement primitive the in-cluster data path uses: it resolves the caller identity from the ambient credential context and requires an administrator verdict before performing any membership or policy operation. A non-admin (or anonymous) caller is refused fail-closed. The facade adds no bespoke, un-authorized write path to the membership or policy trees.
- Opt-in and absent by default. Nothing is registered unless the host calls
AddLatticeAuthApi(). - Must be registered after
AddLatticeAuth(...). The call fails fast with an actionable message otherwise. - Zero background work. Registration wires a lazy singleton only: no hosted service, timer, or reminder. Nothing runs until a facade method is called.
- Tenant-narrowed listing.
AuthPageRequest.ActiveTenantOnlynarrowsListRulesAsyncto the rules governing the caller's active tenant's own trees, and the page names that tenant inAuthRulePage.Tenant. The tenant is the caller's validated active-tenant assertion, never one the request names; an assertion the caller may not make is refused, never defaulted.
Usage
siloBuilder
.AddLattice(/* ... */)
.AddLatticeMembership()
.AddLatticeAuth(options => options.BootstrapAdministrators.Add("root-admin"))
.AddLatticeAuthApi();
Bind a transport over the facade to administer membership and policy remotely:
the sibling Orleans.Lattice.Api.Auth.Grpc package projects it onto a
code-first gRPC surface.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Orleans.Sdk (>= 10.2.2)
- Orleans.Lattice (>= 9.9.0)
- Orleans.Lattice.Api.Abstractions (>= 9.9.0)
- Orleans.Lattice.Auth (>= 9.9.0)
- Orleans.Lattice.Membership (>= 9.9.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 9.9.0 | 39 | 10/2/2026 |
| 9.8.0 | 94 | 9/26/2026 |
| 9.7.0 | 93 | 9/21/2026 |
| 9.6.0 | 333 | 9/5/2026 |
| 9.5.0 | 102 | 9/2/2026 |
| 9.4.0 | 120 | 8/29/2026 |
| 9.3.0 | 108 | 8/25/2026 |
| 9.2.0 | 120 | 8/23/2026 |
| 9.1.0 | 102 | 8/20/2026 |
| 9.0.0 | 123 | 8/14/2026 |
| 8.0.1 | 120 | 7/24/2026 |
| 8.0.0 | 169 | 7/20/2026 |
| 7.9.1 | 124 | 7/16/2026 |
| 7.9.0 | 119 | 7/9/2026 |
| 7.8.0 | 127 | 7/4/2026 |