Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion src/frontend/src/content/docs/dashboard/configuration.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -283,12 +283,16 @@ The resource service client authentication is configured with `Dashboard:Resourc
| `Dashboard:ResourceServiceClient:AuthMode`<br/>Default: `null` | Can be set to `ApiKey`, `Certificate` or `Unsecured`. `Unsecured` should only be used during local development. It's not recommended when hosting the dashboard publicly or in other settings. This value is required if a resource service URL is specified. |
| `Dashboard:ResourceServiceClient:ApiKey`<br/>Default: `null` | The API to send to the resource service in the `x-resource-service-api-key` header. This value is required if auth mode is API key. |
| `Dashboard:ResourceServiceClient:ClientCertificate:Source`<br/>Default: `null` | Can be set to `File` or `KeyStore`. This value is required if auth mode is client certificate. |
| `Dashboard:ResourceServiceClient:ClientCertificate:FilePath`<br/>Default: `null` | The certificate file path. This value is required if source is `File`. |
| `Dashboard:ResourceServiceClient:ClientCertificate:FilePath`<br/>Default: `null` | The PKCS#12/PFX certificate file path. The file should contain the client certificate and its private key. This value is required if source is `File`. |
| `Dashboard:ResourceServiceClient:ClientCertificate:Password`<br/>Default: `null` | The password for the certificate file. This value is optional. |
| `Dashboard:ResourceServiceClient:ClientCertificate:Subject`<br/>Default: `null` | The certificate subject. This value is required if source is `KeyStore`. |
| `Dashboard:ResourceServiceClient:ClientCertificate:Store`<br/>Default: `My` | The certificate `X509Certificates.StoreName`. |
| `Dashboard:ResourceServiceClient:ClientCertificate:Location`<br/>Default: `CurrentUser` | The certificate `X509Certificates.StoreLocation`. |

<Aside type="caution" title="File-based client certificates must be PKCS#12/PFX">
File-based client certificate loading accepts only PKCS#12/PFX files, with or without a password. It doesn't accept standalone DER/PEM certificates, PKCS#7 containers, Windows serialized certificates, or Authenticode-signed files. To migrate, export the client certificate and its private key as PKCS#12/PFX, or use `KeyStore` to select an installed certificate with an associated private key.
</Aside>

### Telemetry limits

Telemetry is stored in SQLite. To bound the amount of retained telemetry, the dashboard applies limits to each database. Log, trace, and metric retention limits evict the oldest stored values when full; attribute and span-event limits truncate incoming data, and the resource limit rejects telemetry for new resources after the limit is reached.
Expand Down
Loading