-
-
How to install and use JetBrains IntelliJ Gateway as a Citrix published application
-
Use Citrix Secure Access and Citrix Secure Developer Spaces with VS Code
-
Configure AI Gateway routing in Citrix Secure Developer Spaces
-
Configure external MongoDB with X.509 authentication in Citrix Secure Developer Spaces
-
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Network connections for Citrix SecurSpaces™ Flex
This article describes how Citrix SecurSpaces™ Flex workspaces connect to customer-owned systems, the available connectivity options, and what each option enables.
Overview
Citrix SecurSpaces Flex workspaces run in a Citrix-managed Azure tenant. To enable developer workflows, workspaces typically need access to customer-owned systems — such as identity providers, Git repositories, CI/CD pipelines, artifact stores, and secrets managers.
Connectivity between the Citrix-managed execution plane and customer-owned systems is established through an integration layer. This layer uses standard Azure networking primitives. The customer is responsible for configuring their side of the connection.
Connectivity options
Citrix SecurSpaces Flex supports two connectivity options for connecting workspaces to customer-owned infrastructure.
Azure virtual network (vNET) peering
Azure vNET peering creates a private, low-latency network path between the Citrix-managed Azure virtual network and a virtual network in the customer’s Azure subscription.
Use this option when:
- Your customer-owned systems (IdP, Git, CI/CD, secrets manager) are hosted in Azure.
- You want private, high-performance connectivity without traffic routing over the public internet.
What the customer configures:
- A virtual network in the customer’s Azure subscription.
- A peering request from the customer vNET to the Citrix-managed vNET (Citrix provides the resource identifier during setup).
- Network security group (NSG) rules and routing to allow workspace traffic to reach the target systems.
VPN gateway
A VPN gateway connects the Citrix-managed Azure vNET to the customer network using an IPsec/IKE VPN tunnel.
Use this option when:
- Your customer-owned systems are on-premises or in a non-Azure environment.
- Azure vNET peering is not available or is not suitable for your network architecture.
What the customer configures:
- A VPN device or gateway at the customer network boundary.
- An IPsec/IKE tunnel configuration (Citrix provides the remote gateway endpoint during setup).
- Routing rules to direct workspace traffic to the appropriate on-premises systems.
What workspaces can reach
Once connectivity is established, workspaces can reach any system accessible within the connected network, subject to the routing and security group rules you configure. Common integration targets include:
| System type | Examples |
|---|---|
| Identity providers | Azure Active Directory, Okta, any SAML 2.0 or OpenID Connect provider |
| Source code repositories | GitHub Enterprise, GitLab self-managed, Bitbucket Server, Azure Repos |
| Artifact repositories | Artifactory, Nexus, Azure Artifacts |
| CI/CD systems | Jenkins, Azure DevOps, CircleCI |
| Secrets managers | HashiCorp Vault, Azure Key Vault |
| Internal data sources | Databases, data lakes, internal APIs |
No connectivity (default state)
By default, before any connectivity option is configured, workspaces have access to:
- The public internet (subject to egress policy rules you define in the Citrix SecurSpaces console).
- Citrix-managed platform services (required for workspace operation).
Workspaces do not have default access to customer-owned private networks. Connectivity must be explicitly configured using one of the options above.
Responsibility summary
| Task | Responsible party |
|---|---|
| Providing the Citrix-managed vNET resource identifier or VPN endpoint | Citrix |
| Configuring the customer-side peering or VPN tunnel | Customer |
| Configuring NSG rules and routing on the customer network | Customer |
| Managing access to customer-owned systems once connected | Customer |
| Enforcing egress policy within workspaces | Citrix (platform) + Customer (policy configuration) |
More information
- Technical security overview
- Workspace templates
- Azure vNET peering documentation — Microsoft Azure
- Azure VPN Gateway documentation — Microsoft Azure
Share
Share
This Preview product documentation is Citrix Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Citrix Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Citrix product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.