Table of Contents

Documentation map

This page is part of the documentation for Orleans.Lattice 9.9.0 (release line 9.9), built 2026-10-04. It is also published as markdown, with every table and list, at index.md, and llms.txt lists every page.

Every package's documentation, grouped by the seam it fills. A filled node is published on NuGet; a hollow node is unreleased or in progress and builds from source. For installation see the package inventory; for what each capability does, see the capability catalogue.

Core

The core package, plus the companions that extend the data model itself.

  • Orleans.Lattice: Orleans.Lattice · 51 documents. The core platform: the sharded, CRDT-backed B+ tree, the write-ahead log that is its durability boundary, the grain catalogue, and the seams every companion package plugs into.
  • GrainIndex: Orleans.Lattice.GrainIndex · 7 documents. Typed grain indexing: track an Orleans grain's typed state in a lattice tree and query it with the server-side predicate surface, without hand-maintaining a secondary index.
  • Vector (unreleased): Orleans.Lattice.Vector · 5 documents. Allocation-lean approximate nearest-neighbour vector index over Lattice-held vectors: an inverted-file core whose query cost is sub-linear in the corpus, persisted on a Lattice tree in bounded chunks with lazy partial load and incremental insert, delete and re-embed maintenance, so a restart reloads the index instead of rebuilding it; an interrupted build resumes from its last durable checkpoint, and a corrupt or version-incompatible index fails its verified load and is rebuilt rather than served.

APIs

The transport-agnostic facade family and its gRPC bindings. A facade is the in-process contract; the matching .Grpc package is its wire binding and typed client, for a head that runs outside the cluster.

  • Api.Abstractions: Orleans.Lattice.Api.Abstractions · 2 documents. The shared, transport-agnostic API contract: the facade service interfaces - state, data, auth, backup, schema, replication, telemetry, tree administration, tenant administration, and installable-app control - the region-discovery contract, and their request/response DTOs, referenced by the facade implementations, the gRPC bindings, and the MCP server without cross-package internal-visibility grants.
  • Api.Apps (unreleased): Orleans.Lattice.Api.Apps · 1 document. Transport-agnostic control facade for installable apps: install, enable, disable, uninstall, list and describe apps, manage each install's version-pinned consent and re-bind its roles, one generic contract dispatching by app slug, beside a catalogue of the configured app sources.
  • Api.Apps.Grpc (unreleased): Orleans.Lattice.Api.Apps.Grpc · 1 document. The code-first gRPC binding and public client for the app control facade, and for the catalogue, workspace and bridge services, all behind one default-deny interceptor with server-classified operations.
  • Api.Auth: Orleans.Lattice.Api.Auth · 2 documents. Transport-agnostic control facade for administering membership and policy and explaining authorization decisions.
  • Api.Auth.Grpc: Orleans.Lattice.Api.Auth.Grpc · 1 document. The code-first gRPC binding and public client for the authorization control facade.
  • Api.Backup: Orleans.Lattice.Api.Backup · 5 documents. Transport-agnostic control facade for driving backup capture (full, incremental, and backup sets), recurring schedules and per-scope status, restore and revert, cold restore, catalog rebuild from the sink and catalog scrub against it, catalog listing and inventory, chain describe, artifact export, deletion, and backup health monitoring.
  • Api.Backup.Grpc: Orleans.Lattice.Api.Backup.Grpc · 4 documents. The code-first gRPC binding and public client for the backup control facade.
  • Api.Data: Orleans.Lattice.Api.Data · 2 documents. Write-capable external data-plane facade for non-.NET clients: point set/delete, non-atomic bulk upsert, point and bounded-range reads, bounded range deletes, single- and cross-tree atomic batches, and the typed CRDT write and read verbs (counters, sets, flags, registers, maps, sequences, and version vectors), each authorized through the core gate.
  • Api.Data.Grpc: Orleans.Lattice.Api.Data.Grpc · 1 document. The code-first gRPC binding and public client for the read-write data-plane API.
  • Api.Replication: Orleans.Lattice.Api.Replication · 4 documents. Transport-agnostic control facade for runtime per-tree replication configuration: an authorized operator can enable replication for a tree (fixing its wire merge mode), disable it, and inspect the replicated-tree set, authorized fail-closed through the shared access gate.
  • Api.Replication.Grpc: Orleans.Lattice.Api.Replication.Grpc · 4 documents. The code-first gRPC binding and public client for the runtime replication control facade, and for the read-only peer-status facade (AddLatticeReplicationStatusApiGrpc / MapLatticeReplicationStatusApiGrpc, LatticeReplicationStatusGrpcClient), which sits behind the control binding's default-deny authorizer.
  • Api.Schema: Orleans.Lattice.Api.Schema · 5 documents. Transport-agnostic control facade for managing schema policy, dead letters, versioning, remediation, and compliance audits.
  • Api.Schema.Grpc: Orleans.Lattice.Api.Schema.Grpc · 4 documents. The code-first gRPC binding and public client for the schema control facade.
  • Api.State: Orleans.Lattice.Api.State · 8 documents. Read-only cluster state-API facade: query, observe, and subscribe to trees, structure, entries, change feeds, and metrics.
  • Api.State.Grpc: Orleans.Lattice.Api.State.Grpc · 1 document. The code-first gRPC binding and public client for the read-only state API.
  • Api.Telemetry: Orleans.Lattice.Api.Telemetry · 1 document. Backend-neutral telemetry facade: answers a curated set of named queries over a Prometheus-compatible backend, derives each answer's tenant scope on the server, and, when a metric allow-list is configured, enforces it fail-closed on the metric names a query will actually evaluate.
  • Api.Telemetry.Grpc: Orleans.Lattice.Api.Telemetry.Grpc · 1 document. gRPC binding for the telemetry facade, for a remote head that cannot enforce tenant scoping locally.
  • Api.TenantAdmin: Orleans.Lattice.Api.TenantAdmin · 1 document. Transport-agnostic operator control facade for tenant administration: create, suspend, resume, and delete tenants (delete cascading the tenant's trees), author per-tenant quotas and read usage against them, administer admin subjects, cross-tenant grants, and per-tenant region residency, plus a fail-closed self-service read surface and an optional tenant-scoped tree-administration surface - all authorized through the shared access gate.
  • Api.TenantAdmin.Grpc: Orleans.Lattice.Api.TenantAdmin.Grpc · 1 document. The code-first gRPC binding and public client for the tenant-administration control facade.
  • Api.TreeAdmin: Orleans.Lattice.Api.TreeAdmin · 2 documents. Transport-agnostic control facade for whole-tree administration, composing the existing single-responsibility facades (it wraps the schema control facade by delegation).
  • Api.TreeAdmin.Grpc: Orleans.Lattice.Api.TreeAdmin.Grpc · 1 document. The code-first gRPC binding and public client for the tree-administration control facade.

MCP

Model Context Protocol bindings that expose the API facades to AI agents, fail-closed and scoped to the caller's grants.

  • Api.Mcp: Orleans.Lattice.Api.Mcp · 5 documents. Model Context Protocol (MCP) server binding: exposes the transport-agnostic API facades as opt-in, permission-aware MCP tools over an authenticated, fail-closed, default-deny credential bridge, registered with AddLatticeMcp(...) and mapped with MapLatticeMcp().
  • Api.Mcp.Apps (unreleased): Orleans.Lattice.Api.Mcp.Apps · 1 document. Opt-in MCP surface for installable apps: every enabled app's tools on the single MCP endpoint, namespaced {slug}_{tool}, paired exactly with the app's manifest and gated per caller by the app's role bindings - a caller sees a tool when a group it belongs to is bound to the tool's role, unless a deny takes the role away - without changing the facade groups or lattice_capabilities.
  • Api.Mcp.Telemetry: Orleans.Lattice.Api.Mcp.Telemetry · 4 documents. Opt-in telemetry add-on for the MCP server: exposes cluster OpenTelemetry metrics as MCP tools by proxying a read-only Prometheus/PromQL backend, with a dual-credential trust boundary that stamps the backend credential and never forwards the caller's Lattice credential.
  • Api.Mcp.Telemetry.Azure: Orleans.Lattice.Api.Mcp.Telemetry.Azure · 1 document. Azure managed-identity backend-token provider for the telemetry facade's Prometheus proxy: supplies a rotating Entra (Azure AD) access token so any telemetry binding - the MCP telemetry tools, or a client head hosting the facade - can query an Azure Monitor managed-Prometheus endpoint, keeping the Azure identity dependency out of the core telemetry package and taking no dependency on the MCP server.

AI / RepoContext

RepoContext, an AI codebase-memory system built entirely on the platform. It is an example application, not part of the platform definition; see the README.

  • Api.Mcp.RepoContext (unreleased): Orleans.Lattice.Api.Mcp.RepoContext · 12 documents. Opt-in MCP tools that give an AI agent durable, conflict-free context and memory about a codebase - repository bootstrap, structural and symbol recall, free-form memories with optional TTL, and semantic search (approximate nearest-neighbour by default, or an exact scan when configured) - stored in the CRDT B+ tree and served fail-closed, with a container host for local use.
  • Api.Mcp.RepoContext.Replication (unreleased): Orleans.Lattice.Api.Mcp.RepoContext.Replication · 1 document. Opt-in multi-cluster add-on for the repository-context store: EnableRepoContextMultiCluster(...) turns on cross-cluster replication for every repository-context tree with the correct per-tree merge mode - the vector-membership presence tree pinned to the add-wins OrFlag CRDT so active-active convergence can never silently drop an embedding, the agent-memory tree pinned to MvRegister so concurrent cross-cluster memory writes both survive and fold, other trees defaulting to last-writer-wins.

Explorer

Status: in progress. The Explorer is under active development. The packages build, are documented and are usable, but the surface area and navigation are still moving, so treat this group as work in flight rather than a stable contract.

  • Explorer (in progress): Orleans.Lattice.Explorer · 17 documents. Opt-in, auth-aware web console for a running cluster, embeddable via AddLatticeExplorerWeb / MapLatticeExplorer or run standalone.
  • Explorer.Entra (in progress): Orleans.Lattice.Explorer.Entra · 1 document. Optional Microsoft Entra ID (Azure AD) interactive login provider for the Explorer: an OIDC auth-code + PKCE (or device-code) sign-in that acquires and silently refreshes a bearer token for an auth-enabled State API, keeping the MSAL dependency out of the core explorer.
  • Explorer.Entra.Web (in progress): Orleans.Lattice.Explorer.Entra.Web · 4 documents. Hosted-web Microsoft Entra ID (OpenID Connect) sign-in for the Blazor Server Explorer: wires the ASP.NET auth-code + PKCE cookie flow through Microsoft.Identity.Web and exchanges the browser session for a State API bearer token, without any public API change to the released Explorer.

Identity and Security

Who the caller is, and what they are allowed to do.

  • Auth: Orleans.Lattice.Auth · 4 documents. Authorization and enforcement: durable policy store, decision engine, and the fail-closed access gate the data path consults.
  • Membership: Orleans.Lattice.Membership · 4 documents. Identity directory and credential-to-subject resolution: groups, transitive membership edges, and pluggable authenticators.
  • Membership.Entra: Orleans.Lattice.Membership.Entra · 3 documents. Microsoft Entra ID (Azure AD) credential authenticator for the membership layer.
  • Membership.Entra.Graph: Orleans.Lattice.Membership.Entra.Graph · 2 documents. Microsoft Graph-backed group-overflow resolver for the Entra authenticator (for subjects whose group claims exceed the token) and the Graph-backed identity directory that the Explorer Access area searches and validates against.
  • Membership.Oidc: Orleans.Lattice.Membership.Oidc · 2 documents. Generic, discovery-document-driven OpenID Connect credential authenticator for the membership layer (Okta, Auth0, Keycloak, Ping, Google).

Governance

Policy over the shape of stored data, over the boundaries between tenants, and over what an installed app may do.

  • Apps (unreleased): Orleans.Lattice.Apps · 1 document. Opt-in installable apps: an embedded manifest declares an app's trees, roles, replication intent, change-feed subscriptions and MCP tools, and optionally how the app presents and a UI bundle the Explorer runs in a sandboxed frame; install records group role bindings and a version-pinned capability ceiling, and activation compiles the roles into ordinary authorization rules and provisions a/{app}/{tree} trees, per tenant when tenancy is on.
  • Schema: Orleans.Lattice.Schema · 6 documents. Opt-in schema enforcement and versioning companion over the opaque-byte[] core: per-tree validation of the values a tree's own write operations carry, which rejects a non-compliant local write and, under opt-in strict ingest, dead-letters a non-compliant replicated typed-CRDT or atomic-batch entry (a plain last-writer-wins replication apply, a backup restore and a tree merge are not validated), and self-describing value versioning with read-time upcasting.
  • Tenancy: Orleans.Lattice.Tenancy · 1 document. Opt-in multi-tenancy across a single-cluster or multi-cluster deployment: keyspace-partitioned tenants under a t/{tenant}/ prefix, a tenant registry with a create / suspend / resume / delete lifecycle, per-tenant quotas admitted against a cluster-converged or per-cluster usage aggregate, usage metering (folded across clusters), rate limiting enforced per cluster, and optional per-tenant region residency - layered on the core through null seams so a host without it is byte-for-byte unchanged.

Replication

Cross-cluster active-active replication and its transport.

  • Replication: Orleans.Lattice.Replication · 29 documents. Cross-cluster active-active replication: producer, WAL, shipper, apply, bootstrap, and anti-entropy.
  • Replication.Grpc: Orleans.Lattice.Replication.Grpc · 5 documents. The canonical gRPC transport binding for replication: the live push transport, the anti-entropy digest-probe transport, the bootstrap snapshot transport, and the cross-cluster saga control channel, over one peer map with shared-secret authentication.

Storage

Durability backends behind the storage seams. The core ships an in-memory write-ahead log, which the two write-ahead-log backends replace for production; the other two back the backup sink and a distributed cache.

  • Backup.AzureBlob: Orleans.Lattice.Backup.AzureBlob · 4 documents. The durable Azure Blob Storage sink backend for backup artifacts and manifests.
  • Caching.AzureBlob: Orleans.Lattice.Caching.AzureBlob · 4 documents. A durable Azure Blob Storage IDistributedCache for the family, backing the hosted-web Explorer's distributed token cache on a multi-replica host.
  • Storage.AzureTable: Orleans.Lattice.Storage.AzureTable · 5 documents. The durable Azure Table Storage write-ahead-log backend.
  • Storage.File: Orleans.Lattice.Storage.File · 3 documents. A durable local-disk write-ahead-log backend: an append-and-fsync log per shard with crash-safe reconciliation and background compaction that rewrites the log to reclaim trimmed space, using the same per-entry record payload encoding as the Azure Table backend.

Operations

Backup, autoscaling, and dashboards.

  • Backup: Orleans.Lattice.Backup · 6 documents. Causally consistent backup and restore: full and incremental capture, scheduling and chain retention, an optional cross-tree causal fence, and a fail-closed permission model over a pluggable sink.
  • Dashboards: Orleans.Lattice.Dashboards · 5 documents. Bundled Grafana dashboards and provisioning templates for the orleans.lattice, orleans.lattice.replication, orleans.lattice.replication.grpc, orleans.lattice.auth, orleans.lattice.membership, orleans.lattice.backup, orleans.lattice.scaling, and orleans.lattice.tenancy meters; the Overview dashboard also charts the exact-KNN gather instruments of the repository-context Orleans.Lattice.Api.Mcp.RepoContext meter.
  • Scaling: Orleans.Lattice.Scaling · 8 documents. Cluster-aggregate autoscaling signal: a compute-axis replica-demand scalar for KEDA plus an advisory, signal-only storage-axis WAL rebalance recommendation, served over an HTTP endpoint and an ASP.NET Core health check.

Concepts

Documentation-only topics that explain ideas the packages share.

  • CRDTs: 14 documents. A beginner-friendly tour of the conflict-free replicated data types (CRDTs) that ship with Orleans.Lattice, and how to drive each one through the typed ILattice accessor extensions.