Orleans.Lattice.Auth
9.9.0
dotnet add package Orleans.Lattice.Auth --version 9.9.0
NuGet\Install-Package Orleans.Lattice.Auth -Version 9.9.0
<PackageReference Include="Orleans.Lattice.Auth" Version="9.9.0" />
<PackageVersion Include="Orleans.Lattice.Auth" Version="9.9.0" />
<PackageReference Include="Orleans.Lattice.Auth" />
paket add Orleans.Lattice.Auth --version 9.9.0
#r "nuget: Orleans.Lattice.Auth, 9.9.0"
#:package Orleans.Lattice.Auth@9.9.0
#addin nuget:?package=Orleans.Lattice.Auth&version=9.9.0
#tool nuget:?package=Orleans.Lattice.Auth&version=9.9.0
Orleans.Lattice.Auth
Optional, opt-in authorization and fail-closed enforcement add-on for
Orleans.Lattice. Turns the resolved
LatticeSubject from Orleans.Lattice.Membership into an enforced access
decision at the data-plane boundary - byte-for-byte identical to the pre-gate
behaviour, and zero runtime cost, when AddLatticeAuth is not registered.
Design
AddLatticeAuth() supplies the real access gate. It stores rules in a dogfooded
sys-auth-policy tree through an ILatticeAuthorizationPolicyStore: a
LatticeAuthorizationRule binds a subject selector (user / group), a scope
(whole-tree / key / prefix), an operation set, and an Allow / Deny effect,
and every edit is durably auditable through the store's history. Rule ids under
the app: prefix (LatticeAppRuleIds) belong to installable apps and are
written only by the app compiler under system origin; a direct write or delete of
one throws LatticeAppOwnedRuleException. A background
maintainer compiles the rule set into an immutable, monotonically-versioned
in-memory snapshot, rebuilding on every policy change observed through the
change feed, and an ILatticeDecisionEngine evaluates a request against that
snapshot with most-specific-scope-wins precedence (exact key, then longest
prefix, then whole tree) and deny-overrides within a scope tier (a user rule
outranks a group rule at equal scope by default).
Enforcement wires the gate into every user-originated mutation and read:
- Writes / deletes / CRDT-apply / bulk-load / lifecycle admin throw
LatticeAuthorizationDeniedExceptionon a denial (carrying only tree id, operation, subject id, and reason - never a value). - A point read of a denied key reports absent (no existence oracle); range and multi-key reads prune to the authorized subset.
- A range delete is hard-denied all-or-nothing (a partial-coverage allow refuses rather than narrows), and atomic / cross-tree batches authorize every leg before any leg is applied, so a single denied key aborts wholesale.
The path is fail-closed: an unauthenticated caller resolves to Anonymous
and default-denies. A configurable set of bootstrap administrators is the
break-glass root-of-trust bypass. Internal machinery (replication-apply, saga
legs, view maintenance) runs system-origin and never self-filters.
Consistency and observability
Cross-cluster policy convergence ships in two modes (per the epic's design):
eventual last-writer-wins by default, plus an opt-in strict epoch fence
(LatticeAuthOptions.StrictConsistencyTrees) that closes the cross-cluster
revoke window at the cost of availability - off by default and zero-cost when
off. Every decision is observable through the orleans.lattice.auth OpenTelemetry
meter and an optional value-free ILatticeAuthAuditSink, both emitted strictly
after the decision is computed so they can never change it (a sink's synchronous
work runs inline on the request path, so a sink must return promptly).
Registration
siloBuilder
.AddLattice((silo, name) => silo.AddMemoryGrainStorage(name))
.AddLatticeMembership()
.AddLatticeAuth(options =>
{
options.DefaultEffect = LatticeEffect.Deny;
options.BootstrapAdministrators.Add("root-admin");
});
Must be registered after AddLattice(...) and AddLatticeMembership().
See the Auth documentation and the security posture for the full guide.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Orleans.Sdk (>= 10.2.2)
- Orleans.Lattice (>= 9.9.0)
- Orleans.Lattice.Membership (>= 9.9.0)
NuGet packages (4)
Showing the top 4 NuGet packages that depend on Orleans.Lattice.Auth:
| Package | Downloads |
|---|---|
|
Orleans.Lattice.Api.Abstractions
Shared contract package for the Orleans.Lattice API facades. Holds the transport-agnostic service interfaces and request/response models for the state, data, auth, backup, schema, tree-administration, tenancy, replication, telemetry, installable-app control, and region-discovery surfaces, so binding packages depend on a public, versioned contract instead of another package's internals. Contains no implementation and starts nothing; the facade packages implement these contracts and are registered separately. |
|
|
Orleans.Lattice.Api.Auth
Optional configuration and control facade add-on for Orleans.Lattice authorization. Exposes a single transport-agnostic admin surface (and, via a sibling binding, a gRPC surface) for administering the membership directory and the authorization policy store: CRUD groups, memberships, and rules, plus ExplainAsync (why a subject is or is not authorized) and EffectivePermissionsAsync (the rules in effect for a subject). Every operation is authorized as an administrator through the same enforcement the in-cluster path uses, so an admin API can never rewrite policy for an unauthorized caller. Opt-in and absent by default; registered with a single AddLatticeAuthApi(...) call. |
|
|
Orleans.Lattice.Api.Replication
Optional transport-agnostic facade add-on for Orleans.Lattice runtime per-tree replication configuration and peer status. Implements ILatticeReplicationControl over the replication engine's config-authoring seam, so an authorized operator can enable replication for a tree (fixing its wire merge mode), disable it, and inspect the runtime replicated-tree set. Also implements ILatticeReplicationStatus over the peer-status read path. Authoring and status reads are authorized fail-closed through the shared Lattice access gate (default-deny anonymous); the gRPC and MCP transports adapt over these surfaces. |
|
|
Orleans.Lattice.Tenancy
Multi-tenancy add-on for Orleans.Lattice, built on a durable, CRDT-backed tenant registry. Persists tenant definitions (status, quotas, burst, placement binding, tenant-admin subjects, and cross-tenant grants) in reserved sys-tenant-* Lattice trees under system-origin, converging concurrent updates with last-writer-wins semantics, and enforces them: each tenant's trees live in its own t/{tenant}/ keyspace, reads and writes are held to a per-tenant request-rate limit, writes and tree creation are admitted against the tenant's quotas, usage and overage are metered, and optional per-tenant region residency refuses operations in a region where the tenant is not online; it fails fast at registration when the auth and membership add-ons it depends on have not been added first. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 9.9.0 | 95 | 10/2/2026 |
| 9.8.1 | 71 | 9/30/2026 |
| 9.8.0 | 362 | 9/26/2026 |
| 9.7.0 | 314 | 9/21/2026 |
| 9.6.1 | 347 | 9/7/2026 |
| 9.6.0 | 658 | 9/5/2026 |
| 9.5.1 | 106 | 9/7/2026 |
| 9.5.0 | 330 | 9/2/2026 |
| 9.4.0 | 697 | 8/29/2026 |
| 9.3.0 | 362 | 8/25/2026 |
| 9.2.0 | 414 | 8/23/2026 |
| 9.1.0 | 439 | 8/20/2026 |
| 9.0.0 | 372 | 8/14/2026 |
| 8.0.0 | 966 | 7/20/2026 |
| 7.9.1 | 153 | 7/14/2026 |
| 7.9.0 | 150 | 7/9/2026 |
| 7.8.0 | 146 | 7/4/2026 |