Public and private data policy
Public measurements include CPU core/mode counters, aggregate memory and physical-disk statistics, root capacity without path labels, network sums by Ethernet/Wi-Fi category, uptime, firmware power conditions, and collection status.
IP and MAC addresses, SSIDs, usernames, commands, environment variables, arbitrary paths, detailed service/container names, logs and unrelated server metrics are private. Standard kernel source filenames in the catalog describe how a measurement is obtained; they are not collected user paths.
The collector aggregates interfaces by category before labeling them. CPU core values and all other dimensions use finite catalog enumerations. The gateway checks exact metric names and exact dimension sets. Unknown metric names are dropped; additional or invalid labels reject the request. Duplicate resulting series are rejected, preventing silent collisions. Samples must be finite, ordered and within the accepted time window. Incoming metadata, exemplars and histograms are never forwarded.
The API accepts catalog identifiers and five fixed ranges only. It never accepts arbitrary PromQL, offers database proxying, or exposes a log route. Browser assets contain no Grafana credentials. The database is exclusively for sanitized Pi data.
Selected journal streams are sent to the private account with best-effort common-secret redaction. Redaction cannot guarantee that every sensitive string is removed. Access and retention are governed by the private Grafana account. Do not alter account-wide settings to deploy this project.