Task · OPN-0068

State pfTop retained-cardinality and address-label costs accurately

Description

The pfTop documentation and dashboard describe a 611-series hard ceiling, but the bounded inventories cap only one current scrape. After the five-minute expiry, a disjoint top set can replace every address and port label, so retained Prometheus storage can accumulate many more distinct series and endpoint-identifying values. The opt-in feature remains bounded in process, but the published capacity and privacy contract is incomplete.

Acceptance Criteria

Definition of Done

Implementation Plan

Correct the hand-written pfTop capacity/privacy prose and the dashboard panel text without changing the bounded-inventory behavior, regenerate dashboard artifacts once, and validate the source plus generated forms.

Final Summary

Fixed by afda1a4c, with the regenerated dashboard line landing in b360e86b. The docs and dashboard now distinguish simultaneous active series from retained identity churn and name the endpoint-identifying labels and retention implications without claiming a measured live volume. just dashboard reported coverage 1087/1087 and log streams 10/10; just docs-check and integrated just check passed. Tests and CodeRabbit were intentionally skipped for prose/declarative dashboard wording.

View the source file on GitHub