Guide / Every rule
Secret used in a way the engine cannot resolve
The check compat/unresolvable-secret-reference, in the group Engine compatibility.
Why it matters
A secret can only be read as an expression; written as a plain string, in a list or in a branch of an if it is never replaced.
How to fix it
Use =camunda.secrets.NAME directly as the value of the property.
Where you see it
The Problems tab lists it under Engine, the editor marks the element on the canvas, and penstock check reports it as compat/unresolvable-secret-reference. It checks the diagram against the engine and the version it is written for: the version in the file's modeler:executionPlatformVersion, or the newest one when the file has none. Operaton and CIB seven are checked as Camunda 7. This check is free.
To turn it off, set camunda-compat/unresolvable-secret-reference or compat/unresolvable-secret-reference to off in your .bpmnlintrc. See Validation.
Rule details
| Id | compat/unresolvable-secret-reference |
| Group | Engine compatibility |
| Level | Error: the diagram or the process is wrong |
Read more: Validation. All rules: Every rule.