Keep the answer, drop the series — pre-aggregation on arrival and bucket exemplars
Summing away the labels nobody queries as samples arrive cuts stored series by orders of magnitude, while deleting every distinguishing label makes counters collide and rates lie. One saved example request keeps the path to a customer without a series per customer.
Every defense stops the explosion by dropping, blinding or refusing something; we want the answers without the series.
Scene 15
Keep the answer, drop the series
- Watch
- Try it
- Predict
- Capture
How do you keep people's questions answerable while storing far fewer series? Start by looking at the gap. Checkout's dashboards only ever query by route and status — 50 series in total. Watch the labels the scrape actually carries pile up beside them, and watch the stored bar leave the queried bar behind.
Highlighted lines are the ones running in the diagram right now.
def drop_labels(samples, drop): # labeldropif not drop:return samples # stored as scrapedfor s in samples:for name in drop: # ["pod", "instance"]s.labels.pop(name)s.key = series_key(s.labels) # route, statusreturn samples # 50 pods -> one key
def append(key, t, value):last = series[key].last_sampleif last and t == last.t:return reject("duplicate sample")if last and t < last.t:return reject("out of order")series[key].push(t, value)
DROP = ["pod", "instance"] # stream aggregationdef on_sample(s):key = series_key(without(s.labels, DROP))src = (key, s.labels["pod"]) # one state per poddelta = max(0, s.value - last.get(src, s.value))last[src] = s.valuetotal[key] += deltadef flush(): # every intervalfor key, v in total.items():remote_write(key, v) # only the rollup
def observe(seconds, trace_id):for b in buckets: # 0.1, 0.5, 1, 5, +Infif seconds <= b.le:b.count += 1b.exemplar = Exemplar(trace_id, seconds)breakdef expose(b): # OpenMetrics textline = f"{b.count}"if b.exemplar: # one per bucketline += f' # {{trace_id="{b.exemplar.id}"}}'return line # labels <= 128 chars
Where this sits in Metrics / Monitoring System
Scene 15 of 18, in the Cardinality act — Churn, defenses, aggregation, then design it.. Summing away labels nobody queries as samples arrive cuts series by orders of magnitude, while deleting every distinguishing label makes counters collide — and an exemplar keeps one example customer.
Up next. Now that you can control what every series costs without losing the answers, the next question is which combination of all these choices a real workload actually needs.
All 18 scenes in Metrics / Monitoring System · Every curriculum