Docs / INTEGRATIONS
INTEGRATIONS
Mesh-Relay
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Mesh-Relay is the optional outbound channel that lets multiple Korthex installations coordinate through a central server when peer-to-peer mesh networking isn't an option (restricted networks, hub-and-spoke deployments, NAT-locked environments). Mesh-Relay is an Enterprise-tier feature and is disabled by default. Activating it requires explicit configuration plus a valid relay-server URL and bearer token issued by your Korthex administrator.
What It Does
Each Korthex installation that opts in becomes a node . Nodes report scan events, finding observations, and migration progress to the relay server. The relay forwards them to other authorized nodes belonging to the same organization - useful for fleet visibility, cross-team coordination, and pushing scan triggers to remote build agents. Event forwarding - scan started / finding observed / scan complete events propagate to peers. Fleet visibility - a single Korthex Dashboard can show the status of all paired nodes. Cross-installation diffs - compare scans run on developer machines vs. the CI pipeline vs. a security scan box.
Security Model
Mesh-Relay is engineered fail-closed: missing or invalid configuration means the relay client refuses to start. The relay server can route events between nodes but cannot read the contents - payloads are signed per-event and any tampering invalidates them.
| Control | Behavior |
|---|---|
| TLS pinning | Required. Connection fails closed if no SPKI pin file is provided. |
| Per-event signing | Each event is signed with a per-installation key. Replay window enforced; replays are dropped and counted. |
| Auth | Bearer token issued per node. Rotated on the relay-admin side without redeploying clients. |
| No code or findings on the wire | Only structured metadata events. No source code, no scan-finding payloads. |
| Local audit stream | Every send/receive logged locally; failures (signature reject, replay reject) surfaced as metrics. |
Files & Configuration
Two small JSON files live under %APPDATA%/korthex/mesh/ (Windows) or ~/.korthex/mesh/ (macOS / Linux): The relay_config.json file is plain JSON and can be hand-edited for quick configuration changes. Restart Korthex after any edit. The node identity file must not be edited or copied to another machine - it would break the cryptographic association between this installation and the relay.
| File | Purpose | User-editable |
|---|---|---|
| node_identity.json | Per-installation node ID + signing key seed. Generated on first activation. | No |
| relay_config.json | Relay server URL, bearer token, SPKI pin reference, queue limits. | Yes (with care) |