Orleans.Lattice.Api.TenantAdmin.Grpc
9.9.0
dotnet add package Orleans.Lattice.Api.TenantAdmin.Grpc --version 9.9.0
NuGet\Install-Package Orleans.Lattice.Api.TenantAdmin.Grpc -Version 9.9.0
<PackageReference Include="Orleans.Lattice.Api.TenantAdmin.Grpc" Version="9.9.0" />
<PackageVersion Include="Orleans.Lattice.Api.TenantAdmin.Grpc" Version="9.9.0" />
<PackageReference Include="Orleans.Lattice.Api.TenantAdmin.Grpc" />
paket add Orleans.Lattice.Api.TenantAdmin.Grpc --version 9.9.0
#r "nuget: Orleans.Lattice.Api.TenantAdmin.Grpc, 9.9.0"
#:package Orleans.Lattice.Api.TenantAdmin.Grpc@9.9.0
#addin nuget:?package=Orleans.Lattice.Api.TenantAdmin.Grpc&version=9.9.0
#tool nuget:?package=Orleans.Lattice.Api.TenantAdmin.Grpc&version=9.9.0
Orleans.Lattice.Api.TenantAdmin.Grpc
Optional, opt-in gRPC transport binding for Orleans.Lattice.Api.TenantAdmin - the transport-agnostic tenant-administration control facade.
It exposes the facade as a code-first, Orleans-serialized gRPC service and ships
strongly-typed clients. LatticeTenantAdminApiGrpcClient binds the
administrative surface: the tenant lifecycle operations - create,
suspend, resume, and delete (which cascades the tenant's trees) -
plus set quotas and the quota-usage read, the per-tenant region-residency
operations (authorize allowed regions, set residency, and get region
status), the tenant-admin subject operations (list, add, and remove),
and the cross-tenant grant operations (list, offer, approve,
reject, and revoke), alongside the unauthenticated auth-scheme discovery RPC. A read-only
LatticeTenantSelfServiceApiGrpcClient binds the co-hosted self-service reads -
current tenant, list accessible tenants, and get tenant - which any
caller, including an anonymous one, may invoke and which the facade scopes
fail-closed to that caller. Every wire message rides the Orleans serializer, so the contract stays
versioned and additive-only.
Wiring on the co-hosting silo:
builder.Services.AddLatticeTenantAdminApiGrpc(o => o.RequireAuthorization = true);
app.MapLatticeTenantAdminApiGrpc();
The binding is default-deny: until the host registers a permissive
ILatticeTenantAdminApiAuthorizer (or turns enforcement off behind an outer
authentication boundary), every administrative call is rejected. The
unauthenticated GetAuthScheme discovery RPC is exempt, so a client can learn how
to sign in before it holds a credential, and so are the three read-only
self-service RPCs, which the facade scopes fail-closed to the caller instead. The facade itself re-derives and
authorizes the caller server-side, so the surface fails closed for an
unauthenticated caller even when the transport gate is disabled.
The binding establishes the caller's asserted active tenant from the
lattice-active-tenant header, so tenant scoping holds on a split-head
deployment, and a tenant denial is reported as PermissionDenied rather than an
opaque Internal fault.
See the tenant-administration gRPC documentation for the full guide.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Grpc.AspNetCore (>= 2.83.0)
- Grpc.Net.ClientFactory (>= 2.83.0)
- Orleans.Lattice.Api.Abstractions (>= 9.9.0)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Orleans.Lattice.Api.TenantAdmin.Grpc:
| Package | Downloads |
|---|---|
|
Orleans.Lattice.Api.Mcp
Model Context Protocol (MCP) server binding for Orleans.Lattice. Exposes the cluster's transport-agnostic API facades (state, data, backup, auth, replication, treeadmin, and tenantadmin) as MCP tools over the official ModelContextProtocol SDK, with permission-aware discovery, an authenticated fail-closed credential bridge, and default-deny authorization. Per-facade modules are opt-in via Add*Tools helpers, including AddTenantAdminTools, and out-of-silo hosting is available via AddLatticeMcpRemote(...). |
GitHub repositories
This package is not used by any popular GitHub repositories.