From 710e437dae87937d8a4d7c2051e1508a9f1eb06d Mon Sep 17 00:00:00 2001 From: Sami Alajrami Date: Thu, 3 Sep 2026 10:20:17 +0200 Subject: [PATCH 1/4] docs: note 1MB payload limit for custom attestations Ref: kosli-dev/server#5388 Co-Authored-By: Claude Sonnet 5 --- tutorials/attest_large_documents.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/tutorials/attest_large_documents.md b/tutorials/attest_large_documents.md index e445fa2..bf35e0d 100644 --- a/tutorials/attest_large_documents.md +++ b/tutorials/attest_large_documents.md @@ -8,6 +8,10 @@ By the end, you will have a Kosli attestation that captures the key facts from y This two-part approach keeps attestation payloads focused on what compliance rules need to evaluate, while ensuring the raw evidence remains available. + +The `--attestation-data` payload sent with `kosli attest custom` is limited to 1MB. Large reports must be distilled into a summary (as described in this tutorial) and, if you need the full document preserved, uploaded separately via `--attachments` to the Evidence Vault. + + ## Prerequisites * [Install Kosli CLI](/getting_started/install). From 285f86517e23c28c0cd7c2d16993e79ca4f16887 Mon Sep 17 00:00:00 2001 From: Sami Alajrami Date: Thu, 3 Sep 2026 10:24:55 +0200 Subject: [PATCH 2/4] docs: tighten payload limit note per review Co-Authored-By: Claude Sonnet 5 --- getting_started/attestations.md | 4 ++++ tutorials/attest_large_documents.md | 2 +- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/getting_started/attestations.md b/getting_started/attestations.md index 34ef73a..eb44fe1 100644 --- a/getting_started/attestations.md +++ b/getting_started/attestations.md @@ -203,6 +203,10 @@ Use **`--attestation-data`** on `kosli attest custom` to provide the JSON data t attestation type's jq expression evaluates. This is what determines the compliance status of the attestation. See the [Custom](#custom) attestation type below for details. +The `--attestation-data` payload is limited to 1 MB. For larger reports, distill the data you need +into a summary and attach the full document separately — see +[Attesting large documents](/tutorials/attest_large_documents). + ```shell kosli attest custom \ --type coverage-metrics \ diff --git a/tutorials/attest_large_documents.md b/tutorials/attest_large_documents.md index bf35e0d..25f678c 100644 --- a/tutorials/attest_large_documents.md +++ b/tutorials/attest_large_documents.md @@ -9,7 +9,7 @@ By the end, you will have a Kosli attestation that captures the key facts from y This two-part approach keeps attestation payloads focused on what compliance rules need to evaluate, while ensuring the raw evidence remains available. -The `--attestation-data` payload sent with `kosli attest custom` is limited to 1MB. Large reports must be distilled into a summary (as described in this tutorial) and, if you need the full document preserved, uploaded separately via `--attachments` to the Evidence Vault. +The `--attestation-data` JSON payload sent by `kosli attest custom` is limited to 1 MB. Distill larger reports into a summary and attach the full document with `--attachments`, as described below. ## Prerequisites From 89b59f12e8b72035db0f5d3b3dfad0e8d0829234 Mon Sep 17 00:00:00 2001 From: Sami Alajrami Date: Thu, 3 Sep 2026 10:27:26 +0200 Subject: [PATCH 3/4] docs: mention 400 error for oversized attestation-data Co-Authored-By: Claude Sonnet 5 --- getting_started/attestations.md | 4 ++-- tutorials/attest_large_documents.md | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/getting_started/attestations.md b/getting_started/attestations.md index eb44fe1..77b5258 100644 --- a/getting_started/attestations.md +++ b/getting_started/attestations.md @@ -203,8 +203,8 @@ Use **`--attestation-data`** on `kosli attest custom` to provide the JSON data t attestation type's jq expression evaluates. This is what determines the compliance status of the attestation. See the [Custom](#custom) attestation type below for details. -The `--attestation-data` payload is limited to 1 MB. For larger reports, distill the data you need -into a summary and attach the full document separately — see +The `--attestation-data` payload is limited to 1 MB — exceeding it returns a 400 error. For larger +reports, distill the data you need into a summary and attach the full document separately — see [Attesting large documents](/tutorials/attest_large_documents). ```shell diff --git a/tutorials/attest_large_documents.md b/tutorials/attest_large_documents.md index 25f678c..513837f 100644 --- a/tutorials/attest_large_documents.md +++ b/tutorials/attest_large_documents.md @@ -9,7 +9,7 @@ By the end, you will have a Kosli attestation that captures the key facts from y This two-part approach keeps attestation payloads focused on what compliance rules need to evaluate, while ensuring the raw evidence remains available. -The `--attestation-data` JSON payload sent by `kosli attest custom` is limited to 1 MB. Distill larger reports into a summary and attach the full document with `--attachments`, as described below. +The `--attestation-data` JSON payload sent by `kosli attest custom` is limited to 1 MB — exceeding it returns a 400 error. Distill larger reports into a summary and attach the full document with `--attachments`, as described below. ## Prerequisites From 3e7ab8008809012f5f53f8f1a33abb761824aadb Mon Sep 17 00:00:00 2001 From: Sami Alajrami Date: Thu, 3 Sep 2026 10:40:16 +0200 Subject: [PATCH 4/4] Update getting_started/attestations.md Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> --- getting_started/attestations.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/getting_started/attestations.md b/getting_started/attestations.md index 77b5258..ac49075 100644 --- a/getting_started/attestations.md +++ b/getting_started/attestations.md @@ -203,9 +203,9 @@ Use **`--attestation-data`** on `kosli attest custom` to provide the JSON data t attestation type's jq expression evaluates. This is what determines the compliance status of the attestation. See the [Custom](#custom) attestation type below for details. -The `--attestation-data` payload is limited to 1 MB — exceeding it returns a 400 error. For larger -reports, distill the data you need into a summary and attach the full document separately — see -[Attesting large documents](/tutorials/attest_large_documents). +The `--attestation-data` JSON payload sent to Kosli is limited to 1 MB; larger payloads fail with a +400 error. For larger reports, distill the data you need into a summary and attach the full document +separately — see [Attesting large documents](/tutorials/attest_large_documents). ```shell kosli attest custom \