KORTHEXDocumentation

Docs / INTEGRATIONS

INTEGRATIONS

Mesh-Relay

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Mesh-Relay is the optional outbound channel that lets multiple Korthex installations coordinate through a central server when peer-to-peer mesh networking isn't an option (restricted networks, hub-and-spoke deployments, NAT-locked environments). Mesh-Relay is an Enterprise-tier feature and is disabled by default. Activating it requires explicit configuration plus a valid relay-server URL and bearer token issued by your Korthex administrator.

What It Does

Each Korthex installation that opts in becomes a node . Nodes report scan events, finding observations, and migration progress to the relay server. The relay forwards them to other authorized nodes belonging to the same organization - useful for fleet visibility, cross-team coordination, and pushing scan triggers to remote build agents. Event forwarding - scan started / finding observed / scan complete events propagate to peers. Fleet visibility - a single Korthex Dashboard can show the status of all paired nodes. Cross-installation diffs - compare scans run on developer machines vs. the CI pipeline vs. a security scan box.

Security Model

Mesh-Relay is engineered fail-closed: missing or invalid configuration means the relay client refuses to start. The relay server can route events between nodes but cannot read the contents - payloads are signed per-event and any tampering invalidates them.

ControlBehavior
TLS pinningRequired. Connection fails closed if no SPKI pin file is provided.
Per-event signingEach event is signed with a per-installation key. Replay window enforced; replays are dropped and counted.
AuthBearer token issued per node. Rotated on the relay-admin side without redeploying clients.
No code or findings on the wireOnly structured metadata events. No source code, no scan-finding payloads.
Local audit streamEvery send/receive logged locally; failures (signature reject, replay reject) surfaced as metrics.

Files & Configuration

Two small JSON files live under %APPDATA%/korthex/mesh/ (Windows) or ~/.korthex/mesh/ (macOS / Linux): The relay_config.json file is plain JSON and can be hand-edited for quick configuration changes. Restart Korthex after any edit. The node identity file must not be edited or copied to another machine - it would break the cryptographic association between this installation and the relay.

FilePurposeUser-editable
node_identity.jsonPer-installation node ID + signing key seed. Generated on first activation.No
relay_config.jsonRelay server URL, bearer token, SPKI pin reference, queue limits.Yes (with care)