Citrix SecurSpaces™

SecurSpaces at a glance

A summary of what Citrix SecurSpaces™ runs on, what it integrates with, and where its limits are, for anyone deciding whether it fits their environment.

Every figure here is owned by another page, which is linked from its row. Follow the link when you need the detail or the caveats.

Where it runs

   
Deployment model Self-hosted on your own Kubernetes cluster, in your cloud, on-premises, or fully air-gapped
Managed alternative SecurSpaces Flex, a Citrix-operated service billed through Platform Flex credits
Kubernetes 1.34 or later, on a cluster dedicated to SecurSpaces
Node architecture amd64 only. arm64, including AWS Graviton, is not supported
Certified platforms Amazon EKS, Azure AKS, Google GKE, Red Hat OpenShift, VMware Tanzu Kubernetes Grid, Nutanix Kubernetes Platform

See System requirements.

What it needs from your infrastructure

   
Ingress NetScaler CPX recommended and deployable by the chart; NGINX, HAProxy, and the Kubernetes Gateway API also supported
Database MongoDB, either managed such as Atlas, or deployed in-cluster
Registry Any OCI-compatible registry, for example Amazon ECR, Azure Container Registry, Google Artifact Registry, or JFrog Artifactory
DNS and TLS Two domains with valid certificates, one of them a wildcard for workspace proxying

See Ingress and System requirements.

What it integrates with

   
Identity providers SAML 2.0, OpenID Connect, Google OAuth, Microsoft Entra ID
User provisioning SCIM
Code repositories GitHub, GitLab, Bitbucket, Azure DevOps, each self-hosted or managed
Secrets Built-in secret storage, or HashiCorp Vault
Artifacts JFrog Artifactory
Developer portal Backstage plugin
Virtual apps and desktops Citrix DaaS
AI traffic Routed through an AI Gateway with per-user attribution

See Identity and access and Integrations.

How developers reach a workspace

   
In the browser Cloud IDE based on VS Code
From a local IDE Over SSH, from VS Code Desktop, JetBrains Gateway, Cursor, Windsurf, or Kiro
Graphical desktop Available through a GUI-enabled workspace image
Published application Through Citrix DaaS

See Develop in a workspace.

Automation

The platform can be operated as code as well as through the console, which matters if you manage environments with a platform team rather than by hand.

   
REST API Covers what the console covers — workspaces, projects, organizations, resources, users, and reporting. Authenticated with an API key. Enabled by a platform feature flag
Terraform provider Manages users, organizations, projects, groups, and workspace templates. Distributed through your deployment rather than the public registry
Deployment Helm values and the Strong Installer CLI, so cluster configuration lives in version control

See API, Terraform provider, and Install with the Strong Installer CLI.

Limits

   
CPU per workspace 1000 cores
Memory per workspace 10,000 GiB
Disk per workspace 10,000 GiB
GPUs per workspace 1000
Users and workspaces No user limit. SecurSpaces is included in the Citrix Platform License, with no new SKU

These are product ceilings, not recommendations. What you can request is bounded by the hardware in your cluster. See Sizing.

Note:

Workspaces are Linux containers, so toolchains that require macOS or Apple hardware — iOS, iPadOS, macOS, watchOS, and tvOS development — cannot run in SecurSpaces. This is a property of the platform rather than a gap in it.

Indicative scale

Deployment Service nodes Workspace nodes Database
50 developers, proof of concept One 8 vCPU / 32 GiB 8 vCPU / 32 GiB, autoscaling 20 GiB
500 developers Two 8 vCPU / 32 GiB 16 vCPU / 64 GiB, autoscaling 100 GiB

Workspace nodes scale with how many workspaces run at once, not how many exist, so idle detection is the largest single lever on cost. See Sizing.

Security and governance

   
Source code Stays in the workspace; never lands on the endpoint
Tooling Developers do not assemble their own environments. A workspace is created from a platform-owned, version-controlled template that fixes the image, toolchains, package sources, and extensions, so every workspace from it is identical
Network control Per-workspace egress policies, enforced at the proxy
Data protection Clipboard, download, and upload controls
Audit Every action recorded, exportable to a SIEM, retained in-platform for 360 days
Controls 31 identified controls across 8 domains, in the control catalogue
With the wider Citrix platform DaaS, Secure Private Access, and Chrome Enterprise Premium add controls on the access path in front of a workspace. See Layered controls

See Security and compliance.

Try it

   
Fastest evaluation The 1-Click VM runs the whole platform on a single virtual machine, no cluster needed
Production trial Deploy to a cluster and follow the standard installation

See Deploy for evaluation with the 1-Click VM and Kubernetes platforms.

SecurSpaces at a glance