Samples
This page is part of the documentation for Orleans.Lattice 9.9.0 (release line 9.9), built 2026-10-04. It is also published as markdown, with every table and list, at index.md, and llms.txt lists every page.Runnable projects exercising the platform, grouped by concern as in the capability catalogue. Each sample's own README explains what it demonstrates and how to run it; its Source page lists the code.
Core Storage and Durability
- AtomicAction ():
IAtomicActionGrainis a generic, all-or-nothing saga / TCC coordinator. - AtomicWrites ():
ILattice.SetManyAtomicAsynccommits a batch of key-value pairs all-or-nothing: either every key in the batch becomes visible together, or - on failure or a failed guard - nothing is committed and every key keeps its pre-batch value. - BulkLoading (): Bulk loading seeds an empty tree far more cheaply than a loop of
SetAsynccalls: it packs each leaf to capacity and builds the tree without splitting nodes as it grows - the one-shot form computes the finished shape up front and commits each shard once, and the streaming form grafts each chunk onto the right edge of the tree. - ConflictFreeMerges (): Plain writes on a tree -
SetAsync,SetManyAsync,SetManyAtomicAsync, and friends - are last-writer-wins (theLatticeMergeMode.LwwRegistermerge mode): when two writers touch the same key concurrently, the later timestamp silently overwrites the earlier one and the losing update is discarded. - DistributedLock ():
ILatticeLockGrainis a single-cluster, FIFO-fair distributed lock / lease keyed by name. - DurableCursors (): A durable cursor is a server-checkpointed iterator.
OpenEntryCursorAsyncreturns an opaque cursor ID whose paging position is persisted to Orleans storage after every page. - OnlineReshard (): Lattice can grow the number of physical shards a tree's key space is spread across while the tree stays online - no downtime, no data loss.
- PredicateOperations (): Server-side predicate push-down: a typed read or scan can carry an ordinary C#
Expression<Func<T, bool>>that is compiled to a small serializable IR on the client and evaluated on the leaf grain that owns each key. Only the keys (or values) that match travel back across the wire; non-matching values are dropped at the source. - Resize ():
ILattice.ResizeAsyncchanges a tree's structural sizing (MaxLeafKeys/MaxInternalChildren) on a tree that already holds data. - RetryPolicy (): Storage faults are sometimes transient (a throttle, a brief network blip).
- SnapshotCursors (): A snapshot cursor gives strict snapshot isolation.
OpenSnapshotEntryCursorAsyncfreezes the tree state at open time; every page the cursor returns reflects that captured instant, and no concurrent change - foregroundSetAsync/DeleteAsync, atomic saga, range delete, replication apply, or a topology change such as a shard split - is ever visible to the cursor for the rest of its lifetime. - Snapshots ():
SnapshotAsynccopies a tree into a new destination tree - an offline snapshot as a point-in-time copy - which is useful for backups, read-only analytics forks, or cloning a dataset for experimentation. - SoftDeleteRecovery ():
DeleteTreeAsyncis a soft delete: the tree is immediately made inaccessible (reads and writes throwInvalidOperationException) but its data is retained for a configurable grace window. - StronglyConsistentScans (): Lattice's scan primitives -
CountAsync,ScanKeysAsync, andScanEntriesAsync- are strongly consistent: no key is missed or double-counted because a shard split or rebalanced underneath the call, and a concurrentSetManyAtomicAsyncis observed all-or-nothing. - TreeRegistry (): Every tree you touch is tracked in a registry.
- Ttl (): Per-entry time-to-live: a key written with a
TimeSpanTTL is visible to every read until its absolute expiry instant (resolved server-side asUtcNow + ttl), after which every read path treats it as absent.
Replication and Distribution
- CrossClusterReplication (): Active-active cross-cluster replication.
- RuntimeReplicationConfig (): This sample drives cross-cluster replication enablement at runtime through the replication control API, instead of declaring replicated trees statically in the
LatticeReplicationOptions.ReplicatedTreesoptions map at boot.
Governance
- InstallableApps (): A single-silo tour of the installable App concept: an embedded manifest, a version-pinned operator consent, generated app-owned authorization rules, and activation / teardown through the Apps API facade.
- MultiTenancy (): An opt-in, single-silo tour of Orleans.Lattice multi-tenancy: the tenant registry, the isolation naming seam, and the operator control-plane facade - all turned on by adding a few packages, with no change to the core tree.
- SchemaEnforcement (): The companion
Orleans.Lattice.Schemapackage adds two opt-in, composable capabilities on top of the opaque-byte[]core:.
Identity and Security
- Authorization (): The Orleans.Lattice authorization layer on one in-process Orleans silo, with a focus on group and nested-group membership: identity (users, groups, and a group nested inside another group), a default-deny policy, and per-tree / per-key / per-prefix rules enforced on every operation.
- CrossClusterAuthorization (): The Orleans.Lattice authorization layer end to end: membership (users and groups), a default-deny policy, and per-tree / per-key / per-prefix rules enforced on every operation.
- EntraAuthorization (): The Orleans.Lattice authorization layer on one in-process Orleans silo, gated by a genuine Entra identity where the signed-in user is the tree's owner. Where the Authorization sample fakes a token, this sample acquires a real Entra access token for the user who is currently signed in to the Azure CLI, makes that user's Entra object id (
oid) the sole bootstrap administrator, and then reads and writes a value to a tree as that Entra identity - while an anonymous request is denied. - Explorer (): A one-command, self-contained demo of the opt-in
Orleans.Lattice.Explorer.Webhosting library. - PasswordProtection (): Two operator accounts protecting one in-process Orleans silo that exposes the read-only State API over gRPC:.
Administration and Operations
- BackupAndRestore (): Demonstrates the
Orleans.Lattice.Backupsurface end to end against a single in-process silo using the default in-cluster backup sink. - ClusterScaling (): A deployable, end-to-end sample that runs a real multi-silo Orleans.Lattice cluster on Azure Container Apps (ACA) and proves the
Orleans.Lattice.Scalingautoscaling signal drives KEDA replica scale-out on the compute axis. A bundled .NET load driver generates compute-axis pressure, and the deploy tooling wires an ACA KEDAmetrics-apiscale rule to the/lattice/scalesignal so ACA adds replicas under load and removes them afterwards. - Diagnostics ():
ILattice.DiagnoseAsyncreturns a point-in-time health snapshot of a tree without touching application data paths. - Events (): Orleans.Lattice publishes metadata-only event notifications on a per-tree Orleans stream, so caches, projections, audit pipelines, and dashboards can react to mutations without polling.
- Metrics (): Orleans.Lattice publishes rich
System.Diagnostics.Metricsinstruments (counters, histograms, and observable gauges) on a single meter namedorleans.lattice. - StateExplorer (): A console tree-explorer for the optional
Orleans.Lattice.Api.Stateadd-on.
AI and MCP
- AgentBacklog: A runnable walkthrough of the claim and lease surface that makes an agent-operated backlog safe for several agents to drain at once.
- McpServer (): A single-process demonstration of the optional
Orleans.Lattice.Api.Mcpadd-on. - McpTelemetry (): A single-process demonstration of the optional
Orleans.Lattice.Api.Mcp.Telemetryadd-on. - RepoContextContainer (): This sample runs the RepoContext MCP server as a single, restart-durable container alongside its embedding companion, and demonstrates the core durability guarantee end to end:.
Indexing, Search and Views
- ChangeHistory (): Every write to a lattice key becomes a revision in that key's timeline.
- GrainIndex (): A grain index tracks a grain's typed state in a lattice tree, so you can ask *"which
Usergrains are 18 or over?"* without hand-maintaining a secondary index and without activating every grain to find out. - HistoryViews (): An opt-in durable per-key history view: an append-only materialised view that records every revision of every key in a source tree, surviving source WAL garbage collection.
- MaterialisedViews (): A materialised view is an asynchronous, eventually-consistent projection of a source tree, maintained by tailing that tree's write-ahead log.
- TagIndexes (): A tag index lets you attach arbitrary string tags to keys and then query the keys back by tag.
- VectorSearch (): Approximate nearest-neighbour search with
Orleans.Lattice.Vector: sub-linear query cost, honest per-query reporting, first-class deletes, and accuracy that is measured rather than asserted.
Reliability and Formal Verification
- VerifiedAtomicCommit (): The all-or-nothing visibility of
SetManyAtomicAsyncis not just asserted by integration tests - it is driven by verified protocol cores that are model-checked with Coyote and specified in TLA+. This sample makes that verified property observable at runtime: a concurrent snapshot reader (GetManyAsync, the N-key reader-stability path) races a saga that repeatedly flips a whole key set between a PRE and a POST value, and every snapshot resolves the saga all-or-nothing - never a torn, half-committed view. - VerifiedWalDurability (): The write-ahead log's garbage collector may only trim log entries that every consumer has acked - unless the optional
LatticeOptions.WalRetentionceiling (off by default) ages old entries out regardless of cursor position - and it learns each live consumer's progress from the WAL cursor registry (the leaf materialisers' durable checkpoint offsets add a floor of their own, so a restart that empties the in-memory registry cannot let it trim WAL a leaf has not yet checkpointed).
Other samples
- HelloWorld
- MultiSiteManufacturing (): A working thin slice of a regulated process-engineering traceability system (turbine-blade lifecycle: forge → heat-treat → machining → NDT → MRB → FAI) that uses
Orleans.Latticeas the fact store and convergent state layer for an inventory system running across two independent Orleans clusters. - VehicleFleetSimulator (): A simulated vehicle fleet that streams structured telemetry events over gRPC. Imported into this repo to drive the WAL benchmarks for
Orleans.LatticeandOrleans.Lattice.Replication(see benchmark, whose silo reuses the simulator's projects unmodified), and as the foundation for a future sample that bridges the simulator's event stream into a Lattice tree.