Orleans.Lattice.Tenancy 9.9.0

dotnet add package Orleans.Lattice.Tenancy --version 9.9.0
                    
NuGet\Install-Package Orleans.Lattice.Tenancy -Version 9.9.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Orleans.Lattice.Tenancy" Version="9.9.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Orleans.Lattice.Tenancy" Version="9.9.0" />
                    
Directory.Packages.props
<PackageReference Include="Orleans.Lattice.Tenancy" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Orleans.Lattice.Tenancy --version 9.9.0
                    
#r "nuget: Orleans.Lattice.Tenancy, 9.9.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Orleans.Lattice.Tenancy@9.9.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Orleans.Lattice.Tenancy&version=9.9.0
                    
Install as a Cake Addin
#tool nuget:?package=Orleans.Lattice.Tenancy&version=9.9.0
                    
Install as a Cake Tool

Orleans.Lattice.Tenancy

Optional, opt-in multi-tenancy add-on for Orleans.Lattice. Partitions a deployment into keyspace-isolated tenants, each with its own trees, quotas, and optional region residency, across a single cluster or many - byte-for-byte identical to the pre-tenancy behaviour, and zero runtime cost, when AddLatticeTenancy is not registered.

Design

AddLatticeTenancy() supplies the durable, conflict-free-mergeable definition of every tenant: status, resource quotas and burst allowance, placement binding, tenant-admin subjects, cross-tenant grants, and its allowed regions and per-region residency status. The ITenantRegistry dogfoods the reserved sys-tenant-* Lattice trees under system-origin, converging concurrent edits with last-writer-wins register semantics, and those registry trees are read-isolated on the control plane so no data-plane grant can scan them. Registration seeds the reserved default tenant with an unbounded quota, so an existing cluster adopts the add-on non-destructively.

Isolation is achieved by filling in seams that core declares as inert no-ops:

  • ITenantContextResolver scopes a caller-supplied, tenant-local tree name into the tenant's own namespace (t/{tenant}/{name}), so two tenants using the same unqualified name reach different trees. The assertion is re-validated against the caller's own membership, and an unresolvable or unauthorized one fails closed with a LatticeTenantAccessDeniedException rather than falling back to a shared tree.
  • ITenantEnumerationFilter prunes a tree-id enumeration made under an active tenant to the trees that tenant owns (platform-owned system ids stay in, governed separately); a caller asserting no tenant is confined instead by the per-entry authorization check, so a catalog read can never disclose another tenant's tree names - or the tenant roster itself.
  • ITenantRegionVisibilityResolver reports the regions a tenant is authorized into or resident in, so region discovery never hands a tenant caller the cluster's whole routing topology (in the shipped registrations discovery cannot validate a tenant assertion, so a tenant-asserting caller is shown only the serving region).

Each seam keeps its no-op default until the add-on replaces it, which is what makes a host that never calls AddLatticeTenancy() unchanged.

Quotas, metering, and rate limiting

Usage metering samples each tenant's live keys, bytes, memory, and tree count into a durable per-tenant usage store, and quota admission refuses a write once the tenant's metered usage is beyond its quota and burst allowance, with a LatticeQuotaExceededException (surfaced over the data gRPC binding as ResourceExhausted carrying the breached dimension). A cluster-wide operations-per-second budget is apportioned across live silos and enforced silo-locally by a token bucket, so rate limiting needs no per-request cross-silo hop. Usage above a steady-state cap is accrued as billable overage on every metering tick.

Region residency and observability

An optional per-tenant residency policy confines a tenant's data to a residency set within an operator-authorized set of regions, refusing the tenant's requests and its replicated writes in any region where the tenant is not Online. With the tenant-admin control API registered, a region dropped from residency completes its drain on its own, but no shipped component advances an added region past Provisioning, so read the region-residency guide before configuring one. A separate placement binding on the tenant record can pin its trees to a dedicated WAL provider. Every tenant is observable through the orleans.lattice.tenancy OpenTelemetry meter, which publishes per-tenant usage, quota, and overage gauges tagged by tenant.

Registration

siloBuilder
    .AddLattice((silo, name) => silo.AddMemoryGrainStorage(name))
    .AddLatticeMembership()
    .AddLatticeAuth()
    .AddLatticeTenancy(options => options.SeedDefaultTenant = true);

Must be registered after AddLattice(), AddLatticeMembership(), and AddLatticeAuth(): membership resolves the tenant-admin subjects the registry names, and auth is the enforcement seam that acts on tenant status, quotas, and grants. Calling it out of order fails fast with an actionable message.

This package carries no operator control surface of its own. Add Orleans.Lattice.Api.TenantAdmin (and its gRPC or MCP binding) to administer the tenant lifecycle.

See the Multi-tenancy documentation for the full guide.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on Orleans.Lattice.Tenancy:

Package Downloads
Orleans.Lattice.Api.TenantAdmin

Optional transport-agnostic control facade add-on for Orleans.Lattice multi-tenant clusters. Presents fail-closed tenant lifecycle, admin-subject, cross-tenant grant, quota and usage, region authorization, residency, and tenant self-service operations over the tenancy add-on. Registered separately; transport packages adapt over this facade.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
9.9.0 43 10/2/2026
9.8.1 62 9/30/2026
9.8.0 93 9/26/2026
9.7.0 95 9/21/2026
9.6.1 115 9/9/2026
9.6.0 102 9/5/2026
9.5.0 110 9/2/2026
9.4.1 114 8/31/2026
9.4.0 113 8/29/2026