Penstock

Guide / Plans, privacy and help

Security and privacy

A complete list of what leaves your machine, when, and to whom. Nothing is sent by surprise, and nothing is sent to track you.

Free

The short version

Everything that talks to the network

WhatWhenWhere toWhat is sent
Deploy When you press Deploy, or run penstock deploy. The address in deployment.url. The file you deploy, and the credentials of the profile. Nothing else from the project. See Deployment.
OAuth token request With auth.type: oauth, just before a deploy or an engine call. The tokenUrl you configured. The client id and secret, and the audience if you set one.
Engine questions Only when you act: Check Workers, Monitor, Scenarios, or Open run. The engine of the profile in force. Requests to the engine's REST API, with the profile's credentials. The tool adds the credentials. The web page in the editor never sees them.
Connector templates When you open Templates…, or press Download on a missing template. Never when your tool starts. Never when you open a diagram. At most once a day. api.github.com (the release list of camunda/connectors) and codeload.github.com (the release archive). A plain HTTPS request. No credentials, no cookies, no project data. It uses the proxy settings of your tool. See Element templates.
Licence Once a day, in the background. When you buy or sign in. The licence service, Polar. The licence, and the machine it is for: a one-way hash of the machine's own id, and the host name as a label so you can recognise it. When you sign in: your e-mail address and the code. Never a diagram. Nobody copies a key: buying opens Polar's checkout and Penstock polls it, and signing in is an e-mail code. See Buying and signing in.
The command line download The first time a project needs a version of the penstock command that is not on the machine. That includes the commands a tool runs for you when the project has no penstockw. The npm registry, package @kern0x1b/penstock-cli. A normal npm install request.
Pull request comments When penstock bot or penstock report runs in your pipeline. Your own Git host. The comment, using the pipeline's own token. See Pipelines, reports and the bot.
The checkout Only when you press a Buy button on the Plans page, or buy from your tool. Polar, the merchant of record. The address is a Polar checkout link. Your browser asks Polar for its checkout page, so Polar sees your address and what your browser sends to any web page. What you type there, such as your e-mail and card, goes to Polar and not to Penstock. See Opening the checkout.
The education link When you press the link. Your browser. Nothing from Penstock.

That is the whole list. There is no update polling, no crash reporting and no usage statistics. Share as HTML and Import work entirely on your machine.

What a deployment sends

One request per deployment. It carries the file you deploy, as multipart form data, and the deployment settings from penstock.yaml (name, source, tenant). It does not carry other diagrams, element templates or the settings file. The request is made by your tool, not by the web page in the editor, so no CORS setup is needed on the engine. Timeouts are 10 seconds to connect and 30 seconds for the request.

Credentials

Scenario runs are safe by design

A scenario run deploys a test build of its own. Every process, decision, form and the calls between them in that build carries a penstock.<run>. prefix, so the engine never takes it for a version you deployed, and what is left on the engine afterwards is what you deployed. Every resource is marked with the run, so an interrupted one can be cleaned up by the next.

Trust

A terminal running penstock check in a project that is not trusted. A hook line says preCheck was not run because the project is not a trusted project, and tells you to run penstock trust or pass --trust-project. The next line says the Check stage was stopped by its pre hook. Then penstock trust --list says No project is trusted on this machine
A hook that does not run in a project nobody has trusted, and the list of trusted projects.

The shared HTML file

A file made with Share as HTML loads nothing and sends nothing. It makes no network request, uses no CDN, has no telemetry, and carries a content security policy that forbids all of it.

Opening the checkout

The Buy buttons on the Plans page are links to a Polar checkout page. Pressing one opens Polar's page, either in a new page or, where the site has switched it on, in a frame over this one. Either way it is Polar's page that loads. Polar sees the visit, and whatever you type there goes to Polar. Penstock never sees your card.

This website

The pages you are reading are plain HTML and one style sheet. They set no cookies and load no fonts, images or code from other sites. The font, JetBrains Mono, is served from this site. Nothing tracks visitors. GitHub, which hosts the site, keeps its own server logs. Apart from the checkout above, the only links that leave this site are ordinary links that you click.

Report a vulnerability

Do not open a public issue. Read SECURITY.md and report it privately.

What is specific to your tool

JetBrains

  • Secrets are kept in the IDE password safe, once for each profile.
  • The Run Penstock commands in the tool window, and the preDeploy and postDeploy hooks of an IDE deploy, run only in a trusted project. From IDE 2025.2 the IDE's own Trust Project decides, and Penstock never overrides it. On 2024.2 and 2025.1 Penstock asks itself, in a dialog that names the command, and keeps the answer in ~/.penstock/trusted-projects.json. Without a penstockw in the project, the IDE runs npx @kern0x1b/penstock-cli, which downloads the command from npm the first time.
  • A private certificate must be trusted by the Java runtime of the IDE. Penstock never skips the check.
  • The connector download uses the IDE proxy settings.

VS Code

  • Passwords and client secrets are kept in VS Code's secret storage, once for each workspace, profile and field.
  • The preDeploy and postDeploy hooks of penstock.yaml run only in a trusted workspace.
  • Files are read and written only inside the workspace folders, or where you chose in a dialog.
  • The connector catalogue is downloaded on demand into ~/.penstock/connectors, with a cap of 64 MB.

Command line

  • Secrets come from PENSTOCK_PASSWORD, PENSTOCK_CLIENT_SECRET and PENSTOCK_TOKEN. Set them in the environment of the command, never in a file.
  • A hooks: command from penstock.yaml runs for check, layout and deploy only in a project you have trusted with penstock trust, or for one run with --trust-project. Inside a pipeline, where CI is set, hooks run without a question. A hook sees only PENSTOCK_FILES, PENSTOCK_ROOT, PENSTOCK_STAGE and PENSTOCK_PROFILE, never the licence key, a password or a token.
  • The wrapper downloads the pinned version from npm once, into ~/.penstock/wrapper. After that it runs offline.
  • The connector download uses HTTPS_PROXY and HTTP_PROXY when they are set.

Common problems

My firewall shows a request to GitHub from my tool.
You opened the connector browser, or pressed Download on a missing template. That is the only GitHub request. It is at most once a day.
My firewall shows a request to npm.
A command line action needed a version of @kern0x1b/penstock-cli that was not on the machine. penstock init adds a wrapper that pins the version and keeps the download in ~/.penstock/wrapper.
I work offline.
Everything works offline except deploy, engine questions, the connector download and the licence check. An active licence works 30 days without a connection.