diff --git a/src/frontend/src/content/docs/dashboard/configuration.mdx b/src/frontend/src/content/docs/dashboard/configuration.mdx
index 129aeea7a..3be3553a3 100644
--- a/src/frontend/src/content/docs/dashboard/configuration.mdx
+++ b/src/frontend/src/content/docs/dashboard/configuration.mdx
@@ -283,12 +283,16 @@ The resource service client authentication is configured with `Dashboard:Resourc
| `Dashboard:ResourceServiceClient:AuthMode` Default: `null` | Can be set to `ApiKey`, `Certificate` or `Unsecured`. `Unsecured` should only be used during local development. It's not recommended when hosting the dashboard publicly or in other settings. This value is required if a resource service URL is specified. |
| `Dashboard:ResourceServiceClient:ApiKey` Default: `null` | The API to send to the resource service in the `x-resource-service-api-key` header. This value is required if auth mode is API key. |
| `Dashboard:ResourceServiceClient:ClientCertificate:Source` Default: `null` | Can be set to `File` or `KeyStore`. This value is required if auth mode is client certificate. |
-| `Dashboard:ResourceServiceClient:ClientCertificate:FilePath` Default: `null` | The certificate file path. This value is required if source is `File`. |
+| `Dashboard:ResourceServiceClient:ClientCertificate:FilePath` Default: `null` | The PKCS#12/PFX certificate file path. The file should contain the client certificate and its private key. This value is required if source is `File`. |
| `Dashboard:ResourceServiceClient:ClientCertificate:Password` Default: `null` | The password for the certificate file. This value is optional. |
| `Dashboard:ResourceServiceClient:ClientCertificate:Subject` Default: `null` | The certificate subject. This value is required if source is `KeyStore`. |
| `Dashboard:ResourceServiceClient:ClientCertificate:Store` Default: `My` | The certificate `X509Certificates.StoreName`. |
| `Dashboard:ResourceServiceClient:ClientCertificate:Location` Default: `CurrentUser` | The certificate `X509Certificates.StoreLocation`. |
+
+
### Telemetry limits
Telemetry is stored in SQLite. To bound the amount of retained telemetry, the dashboard applies limits to each database. Log, trace, and metric retention limits evict the oldest stored values when full; attribute and span-event limits truncate incoming data, and the resource limit rejects telemetry for new resources after the limit is reached.