Table of Contents

Orleans.Lattice.Api.Backup.Grpc configuration

This page documents Orleans.Lattice.Api.Backup.Grpc 9.9.0, in the documentation for Orleans.Lattice 9.9.0 (release line 9.9), built 2026-10-04. It is also published as markdown, with every table and list, at configuration.md, and llms.txt lists every page.

The package has one public server-side options type, LatticeBackupApiGrpcOptions, bound through AddLatticeBackupApiGrpc(configure). The client (LatticeBackupApiGrpcClient) carries no options of its own - transport concerns live on the CallInvoker / GrpcChannel the caller supplies.

LatticeBackupApiGrpcOptions

Property Type Default Meaning
RequireAuthorization bool true Whether the authorization interceptor enforces ILatticeBackupApiAuthorizer on protected inbound calls. The unauthenticated GetAuthScheme discovery RPC is exempt. Default-deny: the binding fails closed unless a host registers a permissive authorizer or turns enforcement off. Set to false only when an outer authentication boundary already guards the endpoint.
CredentialHeaderName string authorization The inbound request-header (gRPC metadata) name carrying the caller's credential token, bridged into the ambient Lattice credential so the backup access gate can resolve the caller's subject. The default bridge reads it on every call, but it only has an effect when auth-backed backup control is active (the Orleans.Lattice.Auth add-on is registered); the core no-op gate ignores the bridged credential.
CredentialScheme string Bearer The authentication scheme stamped on the bridged credential, matched by a registered credential authenticator to resolve the caller's subject. A case-insensitive scheme prefix on the header value (for example "Bearer ") is stripped before the remaining token is used.
ActiveTenantHeaderName string lattice-active-tenant The inbound request-header (gRPC metadata) name carrying the tenant the caller is acting as, lifted onto the ambient active-tenant scope for the duration of the call so a tenant-scoped caller captures and restores only within its own namespace, and a ListBackups call that sets BackupCatalogRequest.ActiveTenantOnly is narrowed to that tenant's own trees. Defaults to LatticeActiveTenantAssertion.DefaultHeaderName. Set to null or an empty string to disable header-based tenant selection. The asserted tenant is only a claim, re-validated by the tenancy add-on; without that add-on it resolves the reserved default tenant and changes nothing.
AdvertisedAuthSchemes IList<AuthSchemeDescriptor> empty The auth schemes the endpoint advertises from its unauthenticated GetAuthScheme RPC, in preference order. Empty by default (the endpoint advertises nothing, so a client falls back to manual or Basic selection). Each descriptor must carry only public configuration - never a secret.

AdvertisedAuthSchemes is a read-only list property: populate it in the configure delegate (for example o.AdvertisedAuthSchemes.Add(descriptor)).

Fail-closed defaults

Out of the box the binding registers DenyAllBackupApiAuthorizer and leaves RequireAuthorization at true, so every protected call is rejected with PermissionDenied until the host opts in - either by registering a permissive authorizer (or the built-in AllowAllBackupApiAuthorizer) or by setting RequireAuthorization = false behind a trusted boundary. GetAuthScheme remains reachable without a credential so clients can discover how to sign in. See Architecture for how the transport gate and the facade's own scope authorization combine.

Client transport

The typed client is configured entirely through the CallInvoker the caller passes to LatticeBackupApiGrpcClient.Create:

  • Address, TLS, retries, deadlines - set on the GrpcChannel / CallInvoker.
  • Call credentials - attach on the channel or per call; the header name and scheme the server reads are CredentialHeaderName / CredentialScheme above.
  • Serialization - the IServiceProvider passed to Create must have Orleans serialization registered (AddSerializer()) so the client and server marshallers match.