Orleans.Lattice.Api.Telemetry 9.9.0

dotnet add package Orleans.Lattice.Api.Telemetry --version 9.9.0
                    
NuGet\Install-Package Orleans.Lattice.Api.Telemetry -Version 9.9.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Orleans.Lattice.Api.Telemetry" Version="9.9.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Orleans.Lattice.Api.Telemetry" Version="9.9.0" />
                    
Directory.Packages.props
<PackageReference Include="Orleans.Lattice.Api.Telemetry" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Orleans.Lattice.Api.Telemetry --version 9.9.0
                    
#r "nuget: Orleans.Lattice.Api.Telemetry, 9.9.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Orleans.Lattice.Api.Telemetry@9.9.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Orleans.Lattice.Api.Telemetry&version=9.9.0
                    
Install as a Cake Addin
#tool nuget:?package=Orleans.Lattice.Api.Telemetry&version=9.9.0
                    
Install as a Cake Tool

Orleans.Lattice.Api.Telemetry

Transport-neutral telemetry proxy for Orleans.Lattice. It holds the machinery that turns a cluster's OpenTelemetry metrics into answerable queries - the read-only Prometheus / PromQL-compatible backend client, the credential boundary in front of it, the range guardrails, and the fail-closed metric-access allow-list - without depending on any transport.

Every telemetry binding adapts over this one package, so the security-critical PromQL code exists exactly once and is never forked per transport.

What it gives you

  • The curated telemetry facade - AddLatticeTelemetryApi() registers ILatticeTelemetry (implemented by LatticeTelemetry) over a server-authored named-query catalogue: a caller selects a query by id and never supplies PromQL, the facade derives the tenant scope from the authenticated caller and reports the scope it applied on every response, and discovery degrades to an empty catalogue rather than failing. It calls AddLatticeTelemetryBackend() itself.
  • A read-only backend client - IPrometheusQueryClient covers the four operations a telemetry surface needs: instant query, range query, metric-name listing, and metric metadata.
  • A dual-credential trust boundary - the proxy stamps the configured backend credential (bearer, basic, dynamic bearer, or mutual-TLS) on every backend request. It takes no dependency on any Lattice credential source, so a caller's Lattice credential can never be forwarded to the backend. ITelemetryBackendTokenProvider is the seam a cloud-identity add-on plugs a rotating token into.
  • Guardrails - a request timeout on every backend call, plus a maximum range and step for range queries that TelemetryRangeGuardrails applies so every binding rejects an over-budget request with the same message.
  • A capability gate - TelemetryAccessAuthorizer checks the cluster-wide Telemetry capability. The facade runs it before every query (discovery degrades to the empty catalogue instead), and a binding that evaluates caller-supplied PromQL - the MCP tool group - registers it and runs it before any backend call. AddLatticeTelemetryBackend() does not register it, and the allow-list below only narrows what an authorized caller may read.
  • A fail-closed metric-access allow-list - TelemetryMetricAccessPolicy is read-all by default or deny-all with an explicit list of exact names and * patterns, each matched against the whole name (anchored at both ends, never across a newline, and without backtracking). Under deny-all, TelemetryQueryAuthorizer gates a PromQL expression against it using PromQlMetricExtractor, a conservative scanner that denies a query carrying a __name__ regex or negative matcher, a malformed or unterminated __name__ matcher, an unconstrained (or unterminated) label-only selector, or no metric name it can extract at all, rather than admitting what it cannot prove safe. It skips # comments and quoted strings as Prometheus's own lexer does - including inside a grouping modifier's label list - so neither can hide a metric selector from the gate.

Register the backend once, after binding the options:

services.Configure<LatticeTelemetryOptions>(o =>
{
    o.BackendAddress = new Uri("https://prometheus.internal:9090/");
    o.AuthMode = LatticeTelemetryBackendAuthMode.Bearer;
    o.Credential = new LatticeTelemetryBackendCredential { BearerToken = "..." };
    o.MetricAccess = LatticeTelemetryMetricAccessMode.DenyAllExceptAllowed;
    o.AllowedMetrics.Add("orleans_lattice_*");
});

services.AddLatticeTelemetryBackend();

AddLatticeTelemetryBackend() is idempotent and defers to an IPrometheusQueryClient the host registered first, so a test or an alternative backend can be substituted without touching the policy wiring.

This package starts nothing and exposes no transport of its own. The gRPC binding for the curated facade ships in Orleans.Lattice.Api.Telemetry.Grpc, and the MCP tool group ships in Orleans.Lattice.Api.Mcp.Telemetry.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (2)

Showing the top 2 NuGet packages that depend on Orleans.Lattice.Api.Telemetry:

Package Downloads
Orleans.Lattice.Api.Mcp.Telemetry

Optional, opt-in telemetry add-on for Orleans.Lattice.Api.Mcp. Exposes cluster OpenTelemetry metrics as MCP tools by proxying a read-only Prometheus/PromQL-compatible backend, with a dual-credential trust boundary that stamps the configured backend credential and never forwards the caller's Lattice credential. Registered with AddTelemetryTools(...).

Orleans.Lattice.Api.Mcp.Telemetry.Azure

Azure managed-identity backend-token provider for the transport-neutral Orleans.Lattice.Api.Telemetry facade. Supplies a rotating Entra (Azure AD) access token to the telemetry proxy's DynamicBearer auth mode so any telemetry binding - the MCP cluster-telemetry tools, or a client head hosting the facade directly - can query an Azure Monitor managed-Prometheus endpoint, acquiring and caching the token from a caller-supplied Azure.Core TokenCredential and refreshing it before expiry with a single shared in-flight acquisition. Keeps the Azure identity dependency out of the core telemetry package and takes no dependency on the MCP server surface.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
9.9.0 56 10/2/2026
9.8.1 89 9/29/2026
9.8.0 107 9/26/2026
9.7.1 109 9/24/2026
9.7.0 104 9/21/2026
9.6.0 348 9/5/2026
9.5.0 137 9/2/2026