Orleans.Lattice.Tenancy
9.9.0
dotnet add package Orleans.Lattice.Tenancy --version 9.9.0
NuGet\Install-Package Orleans.Lattice.Tenancy -Version 9.9.0
<PackageReference Include="Orleans.Lattice.Tenancy" Version="9.9.0" />
<PackageVersion Include="Orleans.Lattice.Tenancy" Version="9.9.0" />
<PackageReference Include="Orleans.Lattice.Tenancy" />
paket add Orleans.Lattice.Tenancy --version 9.9.0
#r "nuget: Orleans.Lattice.Tenancy, 9.9.0"
#:package Orleans.Lattice.Tenancy@9.9.0
#addin nuget:?package=Orleans.Lattice.Tenancy&version=9.9.0
#tool nuget:?package=Orleans.Lattice.Tenancy&version=9.9.0
Orleans.Lattice.Tenancy
Optional, opt-in multi-tenancy add-on for
Orleans.Lattice. Partitions a
deployment into keyspace-isolated tenants, each with its own trees, quotas, and
optional region residency, across a single cluster or many - byte-for-byte
identical to the pre-tenancy behaviour, and zero runtime cost, when
AddLatticeTenancy is not registered.
Design
AddLatticeTenancy() supplies the durable, conflict-free-mergeable definition of
every tenant: status, resource quotas and burst allowance, placement binding,
tenant-admin subjects, cross-tenant grants, and its allowed regions and per-region
residency status. The ITenantRegistry dogfoods
the reserved sys-tenant-* Lattice trees under system-origin, converging
concurrent edits with last-writer-wins register semantics, and those registry
trees are read-isolated on the control plane so no data-plane grant can scan
them. Registration seeds the reserved default tenant with an unbounded quota,
so an existing cluster adopts the add-on non-destructively.
Isolation is achieved by filling in seams that core declares as inert no-ops:
ITenantContextResolverscopes a caller-supplied, tenant-local tree name into the tenant's own namespace (t/{tenant}/{name}), so two tenants using the same unqualified name reach different trees. The assertion is re-validated against the caller's own membership, and an unresolvable or unauthorized one fails closed with aLatticeTenantAccessDeniedExceptionrather than falling back to a shared tree.ITenantEnumerationFilterprunes a tree-id enumeration made under an active tenant to the trees that tenant owns (platform-owned system ids stay in, governed separately); a caller asserting no tenant is confined instead by the per-entry authorization check, so a catalog read can never disclose another tenant's tree names - or the tenant roster itself.ITenantRegionVisibilityResolverreports the regions a tenant is authorized into or resident in, so region discovery never hands a tenant caller the cluster's whole routing topology (in the shipped registrations discovery cannot validate a tenant assertion, so a tenant-asserting caller is shown only the serving region).
Each seam keeps its no-op default until the add-on replaces it, which is what
makes a host that never calls AddLatticeTenancy() unchanged.
Quotas, metering, and rate limiting
Usage metering samples each tenant's live keys, bytes, memory, and tree count
into a durable per-tenant usage store, and quota admission refuses a write once
the tenant's metered usage is beyond its quota and burst allowance, with a
LatticeQuotaExceededException (surfaced over the data gRPC binding as
ResourceExhausted carrying the breached dimension). A cluster-wide operations-per-second budget is
apportioned across live silos and enforced silo-locally by a token bucket, so
rate limiting needs no per-request cross-silo hop. Usage above a steady-state cap
is accrued as billable overage on every metering tick.
Region residency and observability
An optional per-tenant residency policy confines a tenant's data to a residency
set within an operator-authorized set of regions, refusing the tenant's requests and
its replicated writes in any region where the tenant is not Online. With the tenant-admin control API
registered, a region dropped from residency completes its drain on its own, but no
shipped component advances an added region past Provisioning, so read the
region-residency guide before configuring one. A separate placement binding on the
tenant record can pin its
trees to a dedicated WAL provider. Every
tenant is observable through the orleans.lattice.tenancy OpenTelemetry meter,
which publishes per-tenant usage, quota, and overage gauges tagged by tenant.
Registration
siloBuilder
.AddLattice((silo, name) => silo.AddMemoryGrainStorage(name))
.AddLatticeMembership()
.AddLatticeAuth()
.AddLatticeTenancy(options => options.SeedDefaultTenant = true);
Must be registered after AddLattice(), AddLatticeMembership(), and
AddLatticeAuth(): membership resolves the tenant-admin subjects the registry
names, and auth is the enforcement seam that acts on tenant status, quotas, and
grants. Calling it out of order fails fast with an actionable message.
This package carries no operator control surface of its own. Add
Orleans.Lattice.Api.TenantAdmin (and its gRPC or MCP binding) to administer the
tenant lifecycle.
See the Multi-tenancy documentation for the full guide.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Orleans.Sdk (>= 10.2.2)
- Orleans.Lattice (>= 9.9.0)
- Orleans.Lattice.Auth (>= 9.9.0)
- Orleans.Lattice.Backup (>= 9.9.0)
- Orleans.Lattice.Membership (>= 9.9.0)
- Orleans.Lattice.Replication (>= 9.9.0)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Orleans.Lattice.Tenancy:
| Package | Downloads |
|---|---|
|
Orleans.Lattice.Api.TenantAdmin
Optional transport-agnostic control facade add-on for Orleans.Lattice multi-tenant clusters. Presents fail-closed tenant lifecycle, admin-subject, cross-tenant grant, quota and usage, region authorization, residency, and tenant self-service operations over the tenancy add-on. Registered separately; transport packages adapt over this facade. |
GitHub repositories
This package is not used by any popular GitHub repositories.