---
title: "Samples"
url: "https://nsta1.github.io/Orleans.Lattice/samples/index.html"
source: "https://github.com/NSTA1/Orleans.Lattice/blob/release/9.9/FEATURES.md"
documents: "Orleans.Lattice 9.9.0 (release line 9.9)"
built: "2026-10-04"
all-pages: "https://nsta1.github.io/Orleans.Lattice/llms.txt"
---
# Samples

Part of the [Orleans.Lattice documentation](../index.md).

Runnable projects exercising the platform, grouped by concern as in the
[capability catalogue](../FEATURES.md). Each sample's own README explains what
it demonstrates and how to run it; its Source page lists the code.

## Core Storage and Durability

- [AtomicAction](AtomicAction/README.md) ([Source](AtomicAction/source.md)): `IAtomicActionGrain` is a generic, all-or-nothing saga / TCC coordinator.
- [AtomicWrites](AtomicWrites/README.md) ([Source](AtomicWrites/source.md)): `ILattice.SetManyAtomicAsync` commits a batch of key-value pairs all-or-nothing: either every key in the batch becomes visible together, or - on failure or a failed guard - nothing is committed and every key keeps its pre-batch value.
- [BulkLoading](BulkLoading/README.md) ([Source](BulkLoading/source.md)): Bulk loading seeds an **empty** tree far more cheaply than a loop of `SetAsync` calls: it packs each leaf to capacity and builds the tree without splitting nodes as it grows - the one-shot form computes the finished shape up front and commits each shard once, and the streaming form grafts each chunk onto the right edge of the tree.
- [ConflictFreeMerges](ConflictFreeMerges/README.md) ([Source](ConflictFreeMerges/source.md)): Plain writes on a tree - `SetAsync`, `SetManyAsync`, `SetManyAtomicAsync`, and friends - are **last-writer-wins** (the `LatticeMergeMode.LwwRegister` merge mode): when two writers touch the same key concurrently, the later timestamp silently overwrites the earlier one and the losing update is discarded.
- [DistributedLock](DistributedLock/README.md) ([Source](DistributedLock/source.md)): `ILatticeLockGrain` is a single-cluster, FIFO-fair distributed lock / lease keyed by name.
- [DurableCursors](DurableCursors/README.md) ([Source](DurableCursors/source.md)): A durable cursor is a **server-checkpointed iterator**. `OpenEntryCursorAsync` returns an opaque cursor ID whose paging position is persisted to Orleans storage after every page.
- [OnlineReshard](OnlineReshard/README.md) ([Source](OnlineReshard/source.md)): Lattice can grow the number of physical shards a tree's key space is spread across **while the tree stays online** - no downtime, no data loss.
- [PredicateOperations](PredicateOperations/README.md) ([Source](PredicateOperations/source.md)): Server-side **predicate push-down**: a typed read or scan can carry an ordinary C# `Expression<Func<T, bool>>` that is compiled to a small serializable IR on the client and evaluated **on the leaf grain that owns each key**. Only the keys (or values) that match travel back across the wire; non-matching values are dropped at the source.
- [Resize](Resize/README.md) ([Source](Resize/source.md)): `ILattice.ResizeAsync` changes a tree's structural sizing (`MaxLeafKeys` / `MaxInternalChildren`) on a tree that already holds data.
- [RetryPolicy](RetryPolicy/README.md) ([Source](RetryPolicy/source.md)): Storage faults are sometimes transient (a throttle, a brief network blip).
- [SnapshotCursors](SnapshotCursors/README.md) ([Source](SnapshotCursors/source.md)): A snapshot cursor gives **strict snapshot isolation**. `OpenSnapshotEntryCursorAsync` freezes the tree state at open time; every page the cursor returns reflects that captured instant, and no concurrent change - foreground `SetAsync` / `DeleteAsync`, atomic saga, range delete, replication apply, or a topology change such as a shard split - is ever visible to the cursor for the rest of its lifetime.
- [Snapshots](Snapshots/README.md) ([Source](Snapshots/source.md)): `SnapshotAsync` **copies a tree** into a new destination tree - an offline snapshot as a point-in-time copy - which is useful for backups, read-only analytics forks, or cloning a dataset for experimentation.
- [SoftDeleteRecovery](SoftDeleteRecovery/README.md) ([Source](SoftDeleteRecovery/source.md)): `DeleteTreeAsync` is a **soft delete**: the tree is immediately made inaccessible (reads and writes throw `InvalidOperationException`) but its data is retained for a configurable grace window.
- [StronglyConsistentScans](StronglyConsistentScans/README.md) ([Source](StronglyConsistentScans/source.md)): Lattice's scan primitives - `CountAsync`, `ScanKeysAsync`, and `ScanEntriesAsync` - are **strongly consistent**: no key is missed or double-counted because a shard split or rebalanced underneath the call, and a concurrent `SetManyAtomicAsync` is observed all-or-nothing.
- [TreeRegistry](TreeRegistry/README.md) ([Source](TreeRegistry/source.md)): Every tree you touch is tracked in a registry.
- [Ttl](Ttl/README.md) ([Source](Ttl/source.md)): Per-entry **time-to-live**: a key written with a `TimeSpan` TTL is visible to every read until its absolute expiry instant (resolved server-side as `UtcNow + ttl`), after which every read path treats it as absent.

## Replication and Distribution

- [CrossClusterReplication](CrossClusterReplication/README.md) ([Source](CrossClusterReplication/source.md)): Active-active cross-cluster replication.
- [RuntimeReplicationConfig](RuntimeReplicationConfig/README.md) ([Source](RuntimeReplicationConfig/source.md)): This sample drives cross-cluster replication enablement at **runtime** through the replication control API, instead of declaring replicated trees statically in the `LatticeReplicationOptions.ReplicatedTrees` options map at boot.

## Governance

- [InstallableApps](InstallableApps/README.md) ([Source](InstallableApps/source.md)): A single-silo tour of the installable App concept: an embedded manifest, a version-pinned operator consent, generated app-owned authorization rules, and activation / teardown through the Apps API facade.
- [MultiTenancy](MultiTenancy/README.md) ([Source](MultiTenancy/source.md)): An opt-in, single-silo tour of Orleans.Lattice multi-tenancy: the tenant registry, the isolation naming seam, and the operator control-plane facade - all turned on by adding a few packages, with **no change to the core tree**.
- [SchemaEnforcement](SchemaEnforcement/README.md) ([Source](SchemaEnforcement/source.md)): The companion **`Orleans.Lattice.Schema`** package adds two opt-in, composable capabilities on top of the opaque-`byte[]` core:.

## Identity and Security

- [Authorization](Authorization/README.md) ([Source](Authorization/source.md)): The Orleans.Lattice authorization layer on **one in-process Orleans silo**, with a focus on **group and nested-group membership**: identity (users, groups, and a group nested inside another group), a default-deny policy, and per-tree / per-key / per-prefix rules enforced on every operation.
- [CrossClusterAuthorization](CrossClusterAuthorization/README.md) ([Source](CrossClusterAuthorization/source.md)): The Orleans.Lattice authorization layer end to end: membership (users and groups), a default-deny policy, and per-tree / per-key / per-prefix rules enforced on every operation.
- [EntraAuthorization](EntraAuthorization/README.md) ([Source](EntraAuthorization/source.md)): The Orleans.Lattice authorization layer on **one in-process Orleans silo**, gated by a genuine Entra identity where **the signed-in user is the tree's owner**. Where the Authorization sample fakes a token, this sample acquires a real Entra access token for the user who is currently signed in to the Azure CLI, makes that user's Entra object id (`oid`) the sole bootstrap administrator, and then reads and writes a value to a tree **as that Entra identity** - while an anonymous request is denied.
- [Explorer](Explorer/README.md) ([Source](Explorer/source.md)): A one-command, self-contained demo of the opt-in `Orleans.Lattice.Explorer.Web` hosting library.
- [PasswordProtection](PasswordProtection/README.md) ([Source](PasswordProtection/source.md)): Two operator accounts protecting one in-process Orleans silo that exposes the read-only State API over gRPC:.

## Administration and Operations

- [BackupAndRestore](BackupAndRestore/README.md) ([Source](BackupAndRestore/source.md)): Demonstrates the `Orleans.Lattice.Backup` surface end to end against a single in-process silo using the default in-cluster backup sink.
- [ClusterScaling](ClusterScaling/README.md) ([Source](ClusterScaling/source.md)): A deployable, end-to-end sample that runs a real multi-silo Orleans.Lattice cluster on **Azure Container Apps (ACA)** and proves the `Orleans.Lattice.Scaling` autoscaling signal drives **KEDA replica scale-out on the compute axis**. A bundled .NET load driver generates compute-axis pressure, and the deploy tooling wires an ACA KEDA `metrics-api` scale rule to the `/lattice/scale` signal so ACA adds replicas under load and removes them afterwards.
- [Diagnostics](Diagnostics/README.md) ([Source](Diagnostics/source.md)): `ILattice.DiagnoseAsync` returns a point-in-time health snapshot of a tree without touching application data paths.
- [Events](Events/README.md) ([Source](Events/source.md)): Orleans.Lattice publishes **metadata-only event notifications** on a per-tree Orleans stream, so caches, projections, audit pipelines, and dashboards can react to mutations without polling.
- [Metrics](Metrics/README.md) ([Source](Metrics/source.md)): Orleans.Lattice publishes rich `System.Diagnostics.Metrics` instruments (counters, histograms, and observable gauges) on a single meter named `orleans.lattice`.
- [StateExplorer](StateExplorer/README.md) ([Source](StateExplorer/source.md)): A console tree-explorer for the optional `Orleans.Lattice.Api.State` add-on.

## AI and MCP

- [AgentBacklog](AgentBacklog/README.md): A runnable walkthrough of the claim and lease surface that makes an **agent-operated backlog** safe for several agents to drain at once.
- [McpServer](McpServer/README.md) ([Source](McpServer/source.md)): A single-process demonstration of the optional `Orleans.Lattice.Api.Mcp` add-on.
- [McpTelemetry](McpTelemetry/README.md) ([Source](McpTelemetry/source.md)): A single-process demonstration of the optional `Orleans.Lattice.Api.Mcp.Telemetry` add-on.
- [RepoContextContainer](RepoContextContainer/README.md) ([Source](RepoContextContainer/source.md)): This sample runs the RepoContext MCP server as a single, restart-durable container alongside its embedding companion, and demonstrates the core durability guarantee end to end:.

## Indexing, Search and Views

- [ChangeHistory](ChangeHistory/README.md) ([Source](ChangeHistory/source.md)): Every write to a lattice key becomes a revision in that key's timeline.
- [GrainIndex](GrainIndex/README.md) ([Source](GrainIndex/source.md)): A **grain index** tracks a grain's typed state in a lattice tree, so you can ask *"which `User` grains are 18 or over?"* without hand-maintaining a secondary index and without activating every grain to find out.
- [HistoryViews](HistoryViews/README.md) ([Source](HistoryViews/source.md)): An opt-in **durable per-key history view**: an append-only materialised view that records every revision of every key in a source tree, surviving source WAL garbage collection.
- [MaterialisedViews](MaterialisedViews/README.md) ([Source](MaterialisedViews/source.md)): A **materialised view** is an asynchronous, eventually-consistent projection of a source tree, maintained by tailing that tree's write-ahead log.
- [TagIndexes](TagIndexes/README.md) ([Source](TagIndexes/source.md)): A tag index lets you attach arbitrary string tags to keys and then query the keys back by tag.
- [VectorSearch](VectorSearch/README.md) ([Source](VectorSearch/source.md)): Approximate nearest-neighbour search with `Orleans.Lattice.Vector`: sub-linear query cost, honest per-query reporting, first-class deletes, and accuracy that is measured rather than asserted.

## Reliability and Formal Verification

- [VerifiedAtomicCommit](VerifiedAtomicCommit/README.md) ([Source](VerifiedAtomicCommit/source.md)): The all-or-nothing visibility of `SetManyAtomicAsync` is not just asserted by integration tests - it is driven by verified protocol cores that are model-checked with Coyote and specified in TLA+. This sample makes that verified property observable at runtime: a concurrent snapshot reader (`GetManyAsync`, the N-key reader-stability path) races a saga that repeatedly flips a whole key set between a PRE and a POST value, and every snapshot resolves the saga all-or-nothing - never a torn, half-committed view.
- [VerifiedWalDurability](VerifiedWalDurability/README.md) ([Source](VerifiedWalDurability/source.md)): The write-ahead log's garbage collector may only trim log entries that every consumer has acked - unless the optional `LatticeOptions.WalRetention` ceiling (off by default) ages old entries out regardless of cursor position - and it learns each live consumer's progress from the WAL cursor registry (the leaf materialisers' durable checkpoint offsets add a floor of their own, so a restart that empties the in-memory registry cannot let it trim WAL a leaf has not yet checkpointed).

## Other samples

- [HelloWorld](HelloWorld/source.md)
- [MultiSiteManufacturing](MultiSiteManufacturing/README.md) ([Source](MultiSiteManufacturing/source.md)): A working thin slice of a regulated process-engineering traceability system (turbine-blade lifecycle: forge → heat-treat → machining → NDT → MRB → FAI) that uses **`Orleans.Lattice`** as the fact store and convergent state layer for an inventory system running across two independent Orleans clusters.
- [VehicleFleetSimulator](VehicleFleetSimulator/README.md) ([Source](VehicleFleetSimulator/source.md)): A simulated vehicle fleet that streams structured telemetry events over gRPC. Imported into this repo to drive the WAL benchmarks for `Orleans.Lattice` and `Orleans.Lattice.Replication` (see benchmark, whose silo reuses the simulator's projects unmodified), and as the foundation for a future sample that bridges the simulator's event stream into a Lattice tree.
