Penstock

Guide / Every rule

Secret written in a form the engine no longer reads

The check compat/secrets, in the group Engine compatibility.

Advice

Why it matters

A secret referenced as {{secrets.NAME}} or in the old connector syntax is deprecated and is dropped in a later version.

How to fix it

Write the secret as a FEEL expression, camunda.secrets.NAME.

Where you see it

The Problems tab lists it under Engine, the editor marks the element on the canvas, and penstock check reports it as compat/secrets. It checks the diagram against the engine and the version it is written for: the version in the file's modeler:executionPlatformVersion, or the newest one when the file has none. Operaton and CIB seven are checked as Camunda 7. This check is free.

To turn it off, set camunda-compat/secrets or compat/secrets to off in your .bpmnlintrc. See Validation.

Rule details

Idcompat/secrets
GroupEngine compatibility
LevelAdvice: it works, and reads or runs better without it

Read more: Validation. All rules: Every rule.