Orleans.Lattice.Api.Schema.Grpc
This page documents Orleans.Lattice.Api.Schema.Grpc 9.9.0, in the documentation for Orleans.Lattice 9.9.0 (release line 9.9), built 2026-10-04. It is also published as markdown, with every table and list, at README.md, and llms.txt lists every page.Code-first gRPC binding for Orleans.Lattice.Api.Schema - projects the schema-management control facade onto a gRPC service and a public typed client, using code-first Orleans-serialized request and response records that wrap or carry the facade DTOs, with no hand-written .proto.
What is it?
Orleans.Lattice.Api.Schema.Grpc is the remote transport for the cluster's schema control plane. A host references it when a dashboard, a CLI, or a future bridge needs to manage schema policy, inspect dead letters, drive versioning and remediation, scan compliance, or probe capabilities over the network rather than in-process.
It provides:
- A code-first gRPC service. One RPC for each facade operation, plus the unauthenticated
GetAuthSchemediscovery RPC - unary for policy, count, versioning, remediation, compliance, capability, and auth-scheme calls, and server-streaming for dead-letter draining - bound from C# definitions rather than a.proto. - A public typed client.
LatticeSchemaApiGrpcClientexposes one method per RPC over a caller-supplied gRPCCallInvoker. - Shared Orleans marshalling. The binding's request and response wrappers are
[GenerateSerializer]records serialized with the Orleans binary serializer. Shared DTOs streamed or returned directly use their existing Orleans serialization aliases, so client and server stay in lock-step by construction. - Two-layer authorization. A transport meta-authorizer gates every protected RPC at the edge;
GetAuthSchemeis exempt for unauthenticated discovery, and the facade's own scope authorization re-authorizes the resolved caller. The transport layer defaults to deny. The facade layer denies by default only whenOrleans.Lattice.Authis registered, whoseLatticeAuthOptions.DefaultEffectdefaults toDeny; without that add-on the core no-op access gate allows every call, so the transport layer is the only barrier.
Schema administration changes write-validation rules and can rewrite existing values, so the binding fails closed: with no authorizer registered, every protected call is rejected with PermissionDenied.
Core properties
- Public client, internal service. Callers consume
LatticeSchemaApiGrpcClient; the service, marshallers, method definitions, and interceptor are internal. - No transport policy in the client. Address, TLS, retries, deadlines, and credentials live on the caller's
GrpcChannel/CallInvoker. - Two load-bearing gates. The transport meta-authorizer decides whether a call may run at all; the credential the identity bridge resolves then feeds the schema engine's own fail-closed scope authorization. Neither replaces the other.
- Discoverable sign-in. An unauthenticated
GetAuthSchemeRPC lets a client discover how to authenticate before it holds a credential.
RPCs
The gRPC service name is orleans.lattice.api.schema.
| RPC | Kind | Facade operation |
|---|---|---|
SetPolicy |
unary | Set policy |
ClearPolicy |
unary | Clear policy |
GetPolicy |
unary | Get policy |
StreamDeadLetters |
server-streaming | List dead letters |
CountDeadLetters |
unary | Count dead letters |
SetVersionConfig |
unary | Set version config |
GetVersionConfig |
unary | Get version config |
AdvanceTargetVersion |
unary | Advance target version |
AdvanceAndMigrate |
unary | Advance and migrate |
MigrateToTargetVersion |
unary | Migrate to target version |
ClearVersionConfig |
unary | Clear version config |
Remediate |
unary | Remediate |
GetRemediationStatus |
unary | Get remediation status |
ScanCompliance |
unary | Scan compliance |
ProbeCapabilities |
unary | Probe capabilities |
GetAuthScheme |
unary (unauthenticated) | Advertise accepted auth schemes |
Quick Start
Register the binding on a silo that already has AddLatticeSchemaApi, then map its routes. The host must expose the control facade in the same service provider - typically by co-hosting Orleans with AddLattice(...).AddLatticeSchemaEnforcement(...).AddLatticeSchemaApi() on the same host. Register AddLatticeSchemaVersioning(...) when version RPCs should succeed.
Client
LatticeSchemaApiGrpcClient is created over a caller-supplied CallInvoker and an IServiceProvider with Orleans serialization registered (AddSerializer()). The typed client carries no address, TLS, retry, deadline, or credential policy of its own.
A call the server rejects arrives as a PermissionDenied RpcException (the client surfaces the server status unchanged). Other unmapped server faults are returned with a safe gRPC status rather than leaking implementation details. See Architecture for the mapping.
Reference
- API reference - the public client, options, authorization behaviour, and wire message records.
- Configuration - the public options properties, their types, and defaults.
- Architecture - the two-layer authorization model and the code-first binding.
See also
Orleans.Lattice.Api.Schema- the transport-agnostic facade this binding adapts.Orleans.Lattice.Schema- the schema enforcement and versioning engine underneath.Orleans.Lattice.Api.Abstractions- the shared control-surface contract package.Orleans.Lattice.Api.Backup- the sibling control facade this binding mirrors.