Orleans.Lattice.Membership
9.9.0
dotnet add package Orleans.Lattice.Membership --version 9.9.0
NuGet\Install-Package Orleans.Lattice.Membership -Version 9.9.0
<PackageReference Include="Orleans.Lattice.Membership" Version="9.9.0" />
<PackageVersion Include="Orleans.Lattice.Membership" Version="9.9.0" />
<PackageReference Include="Orleans.Lattice.Membership" />
paket add Orleans.Lattice.Membership --version 9.9.0
#r "nuget: Orleans.Lattice.Membership, 9.9.0"
#:package Orleans.Lattice.Membership@9.9.0
#addin nuget:?package=Orleans.Lattice.Membership&version=9.9.0
#tool nuget:?package=Orleans.Lattice.Membership&version=9.9.0
Orleans.Lattice.Membership
Optional, opt-in caller-identity resolution add-on for
Orleans.Lattice. Resolves who is
calling into a LatticeSubject - a stable subject id, the fully
transitively-expanded set of group ids, and an optional flat claim bag - so the
authorization layer (Orleans.Lattice.Auth) can make an access decision.
Design
AddLatticeMembership() contributes the real credential-resolving context. It
selects the first registered ILatticeCredentialAuthenticator that recognizes
the ambient LatticeCredential, maps the resulting principal against an
introspectable ILatticeMembershipDirectory, and expands group membership to
its full transitive closure with cycle detection, so downstream policy always
evaluates a flat, uniform group set. Nested (group-in-group) membership is
supported, and under the default Union merge mode token-asserted groups are
themselves expanded through the directory closure (TokenOnly bypasses the
directory, and DirectoryOnly ignores token-asserted groups).
The directory dogfoods reserved sys-membership-* ILattice trees (a groups
tree, and an edges tree that stores each membership edge in both directions for
forward/reverse scans - there is no separate user record), so every
record is readable through the ordinary scan / change-feed surface and every
mutation is durably auditable through an auto-enabled per-key history view.
Resolution is served from a per-silo cache bounded by the minimum of the
configured lifetime and the inbound token's own expiry, and flushed on any
sys-membership-* mutation the silo commits, so a membership change is reflected
without a process restart (another silo keeps its pre-change entry until that
entry expires).
- Opt-in and zero-cost when absent. Core ships only an allow-nothing
default membership context that always resolves
Anonymous; nothing runs untilAddLatticeMembership()is called. - Extensible authenticators. A built-in
JwtCredentialAuthenticator(issuer / audience / signing-key / lifetime validation plus claim-to-subject and claim-to-groups mapping, registered per trusted issuer viaAddLatticeJwtAuthenticator) is the base for provider-specific authenticators such asOrleans.Lattice.Membership.Entra;AnonymousCredentialAuthenticatoris the fallback default.
Registration
siloBuilder
.AddLattice((silo, name) => silo.AddMemoryGrainStorage(name))
.AddLatticeMembership()
.AddLatticeJwtAuthenticator(options => { /* issuer, audience, signing key */ });
Group-merge policy (Union / TokenOnly / DirectoryOnly), the resolution-cache
lifetime, history retention, and an optional claim-to-group projection are
configured through LatticeMembershipOptions.
See the Membership documentation for the full guide.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.IdentityModel.JsonWebTokens (>= 8.22.0)
- Microsoft.IdentityModel.Tokens (>= 8.22.0)
- Microsoft.Orleans.Sdk (>= 10.2.2)
- Orleans.Lattice (>= 9.9.0)
NuGet packages (7)
Showing the top 5 NuGet packages that depend on Orleans.Lattice.Membership:
| Package | Downloads |
|---|---|
|
Orleans.Lattice.Auth
Authorization add-on for Orleans.Lattice. Ships the authorization rule model, durable policy store, decision engine, credential context, and read/write enforcement seams that gate lattice operations through a fail-closed access policy backed by reserved lattice trees with per-key history. |
|
|
Orleans.Lattice.Api.Abstractions
Shared contract package for the Orleans.Lattice API facades. Holds the transport-agnostic service interfaces and request/response models for the state, data, auth, backup, schema, tree-administration, tenancy, replication, telemetry, installable-app control, and region-discovery surfaces, so binding packages depend on a public, versioned contract instead of another package's internals. Contains no implementation and starts nothing; the facade packages implement these contracts and are registered separately. |
|
|
Orleans.Lattice.Api.Auth
Optional configuration and control facade add-on for Orleans.Lattice authorization. Exposes a single transport-agnostic admin surface (and, via a sibling binding, a gRPC surface) for administering the membership directory and the authorization policy store: CRUD groups, memberships, and rules, plus ExplainAsync (why a subject is or is not authorized) and EffectivePermissionsAsync (the rules in effect for a subject). Every operation is authorized as an administrator through the same enforcement the in-cluster path uses, so an admin API can never rewrite policy for an unauthorized caller. Opt-in and absent by default; registered with a single AddLatticeAuthApi(...) call. |
|
|
Orleans.Lattice.Membership.Entra
Microsoft Entra ID (Azure AD) credential authenticator for Orleans.Lattice.Membership. Specializes the built-in JWT authenticator with tenant-aware OIDC/JWKS discovery and signing-key rotation, Entra v2.0 claim conventions (oid subject, tid tenant, groups, app roles), single- and multi-tenant issuer allow-listing, and pluggable groups-overage resolution. Keeps the Entra dependency stack out of the core membership package. |
|
|
Orleans.Lattice.Api.Replication
Optional transport-agnostic facade add-on for Orleans.Lattice runtime per-tree replication configuration and peer status. Implements ILatticeReplicationControl over the replication engine's config-authoring seam, so an authorized operator can enable replication for a tree (fixing its wire merge mode), disable it, and inspect the runtime replicated-tree set. Also implements ILatticeReplicationStatus over the peer-status read path. Authoring and status reads are authorized fail-closed through the shared Lattice access gate (default-deny anonymous); the gRPC and MCP transports adapt over these surfaces. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 9.9.0 | 265 | 10/2/2026 |
| 9.8.0 | 429 | 9/26/2026 |
| 9.7.0 | 344 | 9/21/2026 |
| 9.6.2 | 353 | 9/9/2026 |
| 9.6.1 | 126 | 9/7/2026 |
| 9.6.0 | 700 | 9/5/2026 |
| 9.5.1 | 111 | 9/7/2026 |
| 9.5.0 | 378 | 9/2/2026 |
| 9.4.0 | 713 | 8/29/2026 |
| 9.3.0 | 398 | 8/25/2026 |
| 9.2.0 | 452 | 8/23/2026 |
| 9.1.0 | 473 | 8/20/2026 |
| 9.0.0 | 399 | 8/14/2026 |
| 8.0.0 | 999 | 7/20/2026 |
| 7.9.1 | 166 | 7/14/2026 |
| 7.9.0 | 170 | 7/9/2026 |
| 7.8.0 | 175 | 7/4/2026 |