Skip to main content
Cortex Axon is a framework for building jobs that run in your environment and securely send data to Cortex. You can use Axon for two things:

How Axon Relay works

Network diagram showing how Cortex Axon works.
Cortex Axon is built on Snyk Broker, an open-source project published by Snyk. Snyk Broker uses WebSockets to create a secure tunnel between your internal network and cloud-hosted Cortex. HTTP requests from Cortex travel through this tunnel to the Axon agent. Because the tunnel is opened from inside your network, you don’t need to open any inbound firewall ports. When you deploy Axon, you store your API tokens or credentials as secrets on infrastructure you own, inside your network. Axon uses these credentials to proxy requests to third-party integrations. Your sensitive information stays inside your virtual private cloud (VPC) and is never exposed to Cortex cloud services. The process works like this:
  1. In Cortex, you register the integration with an alias you choose.
  2. You start the Cortex Axon Docker container with your Cortex API key, the integration type, and the alias.
  3. The Axon agent connects to Cortex, authenticates, and registers itself with the integration type and alias.
  4. The agent starts a Snyk Broker client process. The client uses the configuration details returned by that registration (the /register call) to connect to the Snyk Broker server that runs on the Cortex backend.
  5. Once the connection is established, Cortex relays API calls to your internal network, and the responses come back to Cortex through the same tunnel.

Using Axon Relay

Cortex Axon is composed of an agent which runs in a Docker container (cortex-axon-agent) and integrates with Kubernetes, creating a secure tunnel between the broker and Cortex.

Prerequisites

  1. Create an API key in Cortex.
  2. Create authentication credentials for the integration you’re configuring. Refer to the third-party’s documentation for more information.

Step 1: Setting up the Cortex Axon agent

Step 1.1: Configuring the Axon Relay in Cortex

  1. From the main sidebar, expand Integrations, then select Configurations.
  2. Search for the integration you want to set up, then click +Install.
    The Install button, located to the right of the integration's name.
  3. In the side panel, select Relay as the configuration type.
  4. From Configuration details, do the following:
    1. Optionally, select a new category from the Category dropdown. Cortex provides a default category, you can change it if you need to. Needs at least one category.
    2. Configuration alias - Enter the alias that ties the service registration to this configuration (required).
    3. Depending on the integration, there may be additional options to configure.

Step 1.2: Creating a .env file and a docker-compose.yml file

  1. Locally on your machine, create a file called .env. Inside the file, add contents for the integration you are configuring:
    See the variables for your integration in the README. For example, for GitLab you would add:
    To run the agent in Kubernetes, you’ll need to create a Deployment that runs the agent with similar configuration as described above. There is a Helm chart available that can be used as a starting point. Its critical variables are:
    If you have a proxy setup you can add values such as:
For Google Cloud Platform (GCP), your .env file only needs CORTEX_API_TOKEN. The agent gets its Google credential from Application Default Credentials (ADC), so you don’t need to add a Google token or password to .env. If you use a service account key, mount in docker-compose.yml instead. You enter your Google Workspace customer ID in Cortex when you configure the relay.
  1. Locally on your machine, create a file called docker-compose.yml. Inside the file, add contents for the integration you are configuring:
    Bitbucket Cloud:
    Bitbucket Hosted:
    GitHub:
    Additional environment variables include: GITHUB_API=https://api.github.com, GITHUB_TOKEN GitHub Hosted:
    Additional environment variables include: GITHUB=https://github.mycompany.com, GITHUB_TOKEN GitHub App:
    Additional environment variables include: Arg -s app, GITHUB=https://github.com, GITHUB_APP_CLIENT_ID, GITHUB_APP_CLIENT_PEM (either path to PEM or PEM contents), GITHUB_INSTALLATION_ID
    The Google Cloud agent doesn’t use a token or password in .env. It gets short-lived credentials from Application Default Credentials (ADC) in your environment. The alias must be gcp. Service account key: Mount the key file into the container and point GOOGLE_APPLICATION_CREDENTIALS to it.
    GKE Workload Identity: You don’t need to mount anything. The container reaches the GKE metadata server over pod networking.
    Jira:
    Jira Bearer/Cloud:
    Additional variables include: Arg -s bearer

Step 2: Running the agent

You can run Axon Relay in one of two ways:
  • In a production environment
    • Use the Helm chart provided by Cortex.
  • In a sandbox environment
    1. In your CLI, run the command docker compose up.
      The agent starts and connects to Cortex.
    2. Verify that your agent is working:
      1. From the main sidebar in Cortex, expand Integrations, then select Configurations.
      2. Locate the integration, then click Settings.
      3. On the integration’s Settings page, click Test all at the top right.
        • If watching the logging output in your CLI, you’ll see the agent receive the request and forward it to your internal service.
        • Check the message in the bottom-right corner of the screen to see whether the test succeeded.

Examples

See examples of using Axon Relay with unsupported tools in the Cortex Axon repository.
Last modified on September 25, 2026