- Custom handlers - Write code against the Cortex API that sends data to Cortex on a set interval, on a cron schedule, or after processing a webhook. For more information, see the Cortex Axon README.
- Internally-hosted integrations - Axon Relay creates a virtual connection between your network and Cortex, so Cortex can reach integrations you host internally. Axon Relay supports Bitbucket, GitHub, GitLab, Google Cloud Platform, Harness, Jira, Prometheus, and SonarQube. You can also use it to call internal service endpoints from a Workflow.
How Axon Relay works

- In Cortex, you register the integration with an alias you choose.
- You start the Cortex Axon Docker container with your Cortex API key, the integration type, and the alias.
- The Axon agent connects to Cortex, authenticates, and registers itself with the integration type and alias.
- The agent starts a Snyk Broker client process. The client uses the configuration details returned by that registration (the
/registercall) to connect to the Snyk Broker server that runs on the Cortex backend. - Once the connection is established, Cortex relays API calls to your internal network, and the responses come back to Cortex through the same tunnel.
Using Axon Relay
Cortex Axon is composed of an agent which runs in a Docker container (cortex-axon-agent) and integrates with Kubernetes, creating a secure tunnel between the broker and Cortex.
Prerequisites
- Create an API key in Cortex.
- Create authentication credentials for the integration you’re configuring. Refer to the third-party’s documentation for more information.
Step 1: Setting up the Cortex Axon agent
Step 1.1: Configuring the Axon Relay in Cortex
Axon Relay supports Bitbucket, GitHub, GitLab, Google Cloud Platform, Harness, Jira, Prometheus, and SonarQube. You can also use Axon Relay to call internal service endpoints via a Workflow .
- From the main sidebar, expand Integrations, then select Configurations.
- Search for the integration you want to set up, then click +Install.

- In the side panel, select Relay as the configuration type.
- From Configuration details, do the following:
- Optionally, select a new category from the Category dropdown. Cortex provides a default category, you can change it if you need to. Needs at least one category.
- Configuration alias - Enter the alias that ties the service registration to this configuration (required).
- Depending on the integration, there may be additional options to configure.
Step 1.2: Creating a .env file and a docker-compose.yml file
-
Locally on your machine, create a file called
.env. Inside the file, add contents for the integration you are configuring:
Docker Compose
See the variables for your integration in the README. For example, for GitLab you would add:Kubernetes
To run the agent in Kubernetes, you’ll need to create a Deployment that runs the agent with similar configuration as described above. There is a Helm chart available that can be used as a starting point. Its critical variables are:If you have a proxy setup you can add values such as:
For Google Cloud Platform (GCP), your
.env file only needs CORTEX_API_TOKEN. The agent gets its Google credential from Application Default Credentials (ADC), so you don’t need to add a Google token or password to .env. If you use a service account key, mount in docker-compose.yml instead. You enter your Google Workspace customer ID in Cortex when you configure the relay.-
Locally on your machine, create a file called
docker-compose.yml. Inside the file, add contents for the integration you are configuring:
Bitbucket
Bitbucket Cloud:Bitbucket Hosted:GitHub
GitHub:Additional environment variables include:GITHUB_API=https://api.github.com,GITHUB_TOKENGitHub Hosted:Additional environment variables include:GITHUB=https://github.mycompany.com,GITHUB_TOKENGitHub App:Additional environment variables include: Arg-s app,GITHUB=https://github.com,GITHUB_APP_CLIENT_ID,GITHUB_APP_CLIENT_PEM(either path to PEM or PEM contents),GITHUB_INSTALLATION_IDGitLab
Google Cloud Platform (GCP)
The Google Cloud agent doesn’t use a token or password in.env. It gets short-lived credentials from Application Default Credentials (ADC) in your environment. The alias must begcp. Service account key: Mount the key file into the container and pointGOOGLE_APPLICATION_CREDENTIALSto it.GKE Workload Identity: You don’t need to mount anything. The container reaches the GKE metadata server over pod networking.Harness
Jira
Jira:Jira Bearer/Cloud:Additional variables include: Arg-s bearerPrometheus
SonarQube
Step 2: Running the agent
You can run Axon Relay in one of two ways:- In a production environment
- Use the Helm chart provided by Cortex.
- In a sandbox environment
- In your CLI, run the command
docker compose up.
The agent starts and connects to Cortex. - Verify that your agent is working:
- From the main sidebar in Cortex, expand Integrations, then select Configurations.
- Locate the integration, then click Settings.
-
On the integration’s Settings page, click Test all at the top right.
- If watching the logging output in your CLI, you’ll see the agent receive the request and forward it to your internal service.
- Check the message in the bottom-right corner of the screen to see whether the test succeeded.
- In your CLI, run the command