Orleans.Lattice.Api.Auth.Grpc
10.0.0
dotnet add package Orleans.Lattice.Api.Auth.Grpc --version 10.0.0
NuGet\Install-Package Orleans.Lattice.Api.Auth.Grpc -Version 10.0.0
<PackageReference Include="Orleans.Lattice.Api.Auth.Grpc" Version="10.0.0" />
<PackageVersion Include="Orleans.Lattice.Api.Auth.Grpc" Version="10.0.0" />
<PackageReference Include="Orleans.Lattice.Api.Auth.Grpc" />
paket add Orleans.Lattice.Api.Auth.Grpc --version 10.0.0
#r "nuget: Orleans.Lattice.Api.Auth.Grpc, 10.0.0"
#:package Orleans.Lattice.Api.Auth.Grpc@10.0.0
#addin nuget:?package=Orleans.Lattice.Api.Auth.Grpc&version=10.0.0
#tool nuget:?package=Orleans.Lattice.Api.Auth.Grpc&version=10.0.0
Orleans.Lattice.Api.Auth.Grpc
Code-first gRPC transport binding for Orleans.Lattice.Api.Auth. Projects the membership and authorization-policy admin facade onto a flat set of unary gRPC RPCs so a remote admin tool, CLI, or dashboard can administer groups, membership, and rules - and search the identity directory and introspect verdicts - over the wire.
Administering authorization is the most sensitive surface in the cluster, so the
binding fails closed: with no authorizer registered, every admin call is
rejected with PermissionDenied.
RPCs
| RPC | Facade method |
|---|---|
UpsertGroup |
UpsertGroupAsync |
GetGroup |
GetGroupAsync |
RemoveGroup |
RemoveGroupAsync |
ListGroups |
ListGroupsAsync |
AddMember |
AddMemberAsync |
RemoveMember |
RemoveMemberAsync |
ListGroupMembers |
ListGroupMembersAsync |
ListSubjectGroups |
ListSubjectGroupsAsync |
PutRule |
PutRuleAsync |
GetRule |
GetRuleAsync |
RemoveRule |
RemoveRuleAsync |
ListRules |
ListRulesAsync |
ListRulesForTree |
ListRulesForTreeAsync |
Explain |
ExplainAsync |
EffectivePermissions |
EffectivePermissionsAsync |
SearchDirectory |
SearchDirectoryAsync |
ResolveDirectoryPrincipal |
ResolveDirectoryPrincipalAsync |
GetAccessModel |
GetAccessModelAsync |
Two-layer authorization
Every admin call passes through two independent gates, both fail-closed:
- Transport meta-authorizer. The
ILatticeAuthApiAuthorizercoarse gate runs at the edge in a gRPC interceptor. It defaults toDenyAllAuthApiAuthorizer; every call is rejected withPermissionDenieduntil the host registers a permissive authorizer (or the opt-inAllowAllAuthApiAuthorizer) or turnsRequireAuthorizationoff. - Facade administrator check. Once past the transport gate, the service
stamps the caller identity onto the ambient credential context (via a
header-based
ILatticeAuthApiCredentialBridge,Bearer-aware by default) and invokes the facade. The facade's own per-call administrator check then runs against the resolved caller's subject. An anonymous caller (no credential) is denied here even when the transport gate allowed the call.
A ListRules call with AuthPageRequest.ActiveTenantOnly set also lifts the
caller's asserted active tenant from the ActiveTenantHeaderName header
(default lattice-active-tenant; null or empty disables it). The facade
re-validates it against the caller's membership, and an assertion the caller
may not make fails the call with PermissionDenied. No other auth call reads
the header.
A denial from the facade check is mapped to PermissionDenied with response
trailers carrying only non-sensitive fields (lattice-denied-tree,
lattice-denied-operation, lattice-denied-subject, lattice-denied-reason) -
never a policy value.
Server wiring
builder.Services.AddLatticeAuthApiGrpc(o => o.RequireAuthorization = true);
builder.Services.AddSingleton<ILatticeAuthApiAuthorizer, MyTokenAuthorizer>();
// ... app build ...
app.MapLatticeAuthApiGrpc();
The host must register the admin facade in the same service provider - typically
by co-hosting Orleans with
AddLattice(...).AddLatticeMembership().AddLatticeAuth(...).AddLatticeAuthApi().
Client
var channel = GrpcChannel.ForAddress("https://admin.example:443");
var client = LatticeAuthApiGrpcClient.Create(channel.CreateCallInvoker(), serializerProvider);
await client.PutRuleAsync(new AuthPutRule { Rule = rule });
var explanation = await client.ExplainAsync(new AuthExplainQuery { SubjectId = "alice", Operation = LatticeOperation.Read, Scope = scope });
The serializerProvider must have Orleans serialization registered
(AddSerializer()) so the client and server wire marshallers match exactly.
Transport concerns (address, TLS, deadlines, retries, call credentials) are
configured on the channel the caller supplies.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Grpc.AspNetCore (>= 2.83.0)
- Grpc.Net.ClientFactory (>= 2.83.0)
- Orleans.Lattice.Api.Abstractions (>= 10.0.0)
NuGet packages (2)
Showing the top 2 NuGet packages that depend on Orleans.Lattice.Api.Auth.Grpc:
| Package | Downloads |
|---|---|
|
Orleans.Lattice.Api.Mcp
Model Context Protocol (MCP) server binding for Orleans.Lattice. Exposes the cluster's transport-agnostic API facades (state, data, backup, auth, replication, treeadmin, and tenantadmin) as MCP tools over the official ModelContextProtocol SDK, with permission-aware discovery, an authenticated fail-closed credential bridge, and default-deny authorization. Per-facade modules are opt-in via Add*Tools helpers, including AddTenantAdminTools, and out-of-silo hosting is available via AddLatticeMcpRemote(...). |
|
|
Orleans.Lattice.Explorer.Access
Access (membership and access-control) management area for the Orleans.Lattice Explorer: bridges the auth-admin control-API gRPC client to the explorer's navigation and capability model, and gates the Access area behind a capability probe. Companion to Orleans.Lattice.Explorer.Core. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 10.0.0 | 0 | 10/8/2026 |
| 9.9.0 | 101 | 10/2/2026 |
| 9.8.0 | 134 | 9/26/2026 |
| 9.7.0 | 124 | 9/21/2026 |
| 9.6.1 | 327 | 9/9/2026 |
| 9.6.0 | 145 | 9/5/2026 |
| 9.5.0 | 135 | 9/2/2026 |
| 9.4.0 | 456 | 8/29/2026 |
| 9.3.0 | 168 | 8/25/2026 |
| 9.2.0 | 174 | 8/23/2026 |
| 9.1.0 | 181 | 8/20/2026 |
| 9.0.0 | 202 | 8/14/2026 |
| 8.0.0 | 530 | 7/20/2026 |
| 7.9.1 | 116 | 7/16/2026 |
| 7.9.0 | 118 | 7/9/2026 |
| 7.8.0 | 133 | 7/4/2026 |