Citrix SecurSpaces™

What's new

Updates continuously enhance your Citrix SecurSpaces™ experience. Each release introduces new features, improvements, and fixes to ensure you always have access to the latest innovations and performance enhancements. This article highlights the new and updated capabilities available in this release, as well as resolved issues.

For compatibility and performance details, see Technical Requirements.

SecurSpaces 2026.9

Product name updated to Citrix SecurSpaces

Citrix SecurSpaces is the new product name for Citrix Secure Developer Spaces. The updated name now appears throughout the product interface, browser title, package metadata, email templates, and generated API documentation.

This change helps align the product experience with the current Citrix naming while preserving existing workflows and deployment paths.

Documentation URLs have moved from /en-us/secure-developer-spaces/ to /en-us/securspaces/. Every previous address redirects to the matching page, so existing links and bookmarks continue to work, but the new form is the one to use going forward.

For more information, see Overview.

Desired state configuration for workspace templates

Workspace templates now keep an active relationship with the workspaces created from them. Each workspace records the template version it was created from, so project owners can see which workspaces have drifted away from the current standard and bring them back up to date.

Previously, a template was applied once at creation time and the workspace kept no connection to it. Project owners had no way to tell which workspaces were still aligned with the current configuration, and any change to a repository, secret, extension, or policy had to be coordinated manually with each developer.

Key capabilities include:

  • See how many workspaces are in testing, outdated, or unversioned directly on the Templates page.
  • Open the Associated Workspaces window to review workspaces grouped by template version, and export the list to CSV.
  • Set a default template version to signal the desired configuration for a project.
  • Let workspace owners apply the update from an update window that previews the configuration changes, without losing their persistent data.
  • Require an outdated workspace to be updated before its configuration can be edited.
  • Prevent deletion of a template or template version while workspaces still use it.

For more information, see Templates.

AI observability for developer AI usage

AI traffic that SecurSpaces routes through an AI Gateway is now tagged with the user, project, and workspace that produced it. Platform teams can report on AI request volume, model usage, and token consumption across the organization, and attribute that usage to the teams and developers responsible for it.

Enterprise adoption of AI-assisted development has made token spend difficult to account for. Provider dashboards are specific to a single vendor and cannot show usage across the tools and models a development organization actually uses. This release gives customers a single, provider-independent view.

Key capabilities include:

  • Add user, project, and workspace metadata to AI requests forwarded to the AI Gateway.
  • Report on AI usage independently of the LLM provider serving each request.
  • Break down token consumption and request volume by project, by user, and by model to support chargeback.
  • Health check the AI Gateway, and choose whether AI traffic bypasses it or fails when it is unavailable.
  • Import a sample Grafana dashboard covering token totals, usage rates, response times, and per-project, per-user, and per-model views.

SecurSpaces documents a validated reference stack of Envoy AI Gateway, Prometheus, and Grafana. Because the gateway exports standard metrics, you can also send this data to your existing monitoring infrastructure.

For more information, see Configure AI Gateway routing.

Dot files for workspace personalization

Developers can now connect a personal dot files repository from Profile > Configuration > Dot Files. SecurSpaces clones the repository into each selected workspace and runs a supported install script so shell, editor, and tooling preferences can be applied automatically.

Dot files are configured per user and use that user’s connected Git integration. Developers can apply the configuration to all workspaces or only selected workspaces, choose the install-script timeout, and review Dot files output in workspace startup logs.

Key capabilities include:

  • Use private GitHub, GitLab, Bitbucket, or Azure DevOps repositories for dot files.
  • Apply dot files when a workspace starts or resumes with new repository commits.
  • Run Personalize Environment to reapply dot files to an existing workspace.
  • Keep workspace startup non-blocking if a dot files script fails or times out.

For more information, see Configuration.

Setup Checklist for guided project onboarding

The project console now includes a Setup Checklist that guides project owners and developers through common first steps. The checklist appears as a collapsible side panel on project pages and keeps progress across navigation so users can return to their next setup task.

Project owners see steps for reviewing images, adding repositories and secrets, creating templates, and adding users. Developers see steps for reviewing their profile, configuring integrations, customizing their environment, adding credentials, and creating a workspace. Returning developers see a shorter checklist focused on project-specific readiness.

Platform administrators can enable or disable the project-owner and developer checklists from onboarding settings.

For more information, see General Settings.

AWS Mount Points for shared workspace storage

Mount Points now support Amazon Web Services storage in addition to Azure file storage. Project owners can create or attach shared storage backed by Amazon Elastic File System (EFS) or Amazon S3 Files, then make it available to workspaces through the existing Resource Access flow.

Use AWS Mount Points when teams need live shared files for build artifacts, large datasets, or collaborative project data without copying that data into each workspace. Administrators enable the available storage types first, and project owners choose whether to create new storage or attach storage that an infrastructure team already prepared.

Key capabilities include:

  • Create new AWS-backed Mount Points from eligible storage classes.
  • Attach existing Amazon EFS or Amazon S3 Files storage to a project.
  • Use read-only or read/write access when attaching Mount Points to workspaces.
  • See clearer validation and delete guidance when a Mount Point is still used by live or deleted workspaces.

For more information, see Mount Points.

Amazon EFS and Amazon S3 Files require AWS resources that SecurSpaces does not create, including the file system, per-Availability-Zone mount targets, IAM roles, and Kubernetes storage classes. For the administrator setup steps, see Prepare AWS storage for Mount Points.

Redesigned IDE extension for VS Code and compatible IDEs

The SecurSpaces extension for VS Code, Cursor, Windsurf, and Kiro has been redesigned around a sidebar that acts as the SecurSpaces entry point inside the IDE. Developers who start their day from a local IDE, a Progressive Web App, or a Quickstart link no longer have to return to the console for routine actions.

Previously the extension listed workspaces and offered little beyond start, pause, and connect. Developers who worked mainly from their IDE had no way to see what a workspace contained or to reach the console actions they needed, which meant constant context switching.

Key capabilities include:

  • Browse workspaces grouped by project, with the connected workspace highlighted and sorted to the top.
  • Start, pause, connect in the current or a new window, and switch between workspaces.
  • Expand a workspace to open its cloned repositories, attached mount points, and running workspace apps.
  • Open a folder in a terminal, or copy a workspace app URL, from the right-click menu.
  • See connection quality in the status bar, with round-trip time and estimated bandwidth.
  • Jump to the console to create, edit, or delete a workspace, or to reach profile and troubleshooting pages.

The extension now runs on your local machine, and a small companion extension runs inside the workspace to report activity and answer connection measurements. Your access token stays on your local machine.

Actions that depend on newer platform features are hidden when the extension is connected to an older SecurSpaces platform, and the sidebar explains why.

For more information, see Connect to a workspace via SSH.

Recover your own workspaces before they are deleted

Workspaces removed by an inactivity custom action are now visible to their owner before they are gone for good. Profile > Overview > Workspaces separates Active workspaces from Workspaces pending deletion, and the pending list shows the permanent deletion deadline in UTC with actions to restore or permanently delete.

SecurSpaces also emails the workspace owner when a workspace is moved to the recycling bin, and again 24 hours before it is permanently deleted. Previously a workspace could disappear with no warning and no self-service way to get it back, which was a common source of support requests.

For more information, see Profile Overview.

Starting a workspace counts as use

A workspace that is started regularly is no longer treated as unused. Starting a workspace from the console, the REST API, or the IDE extension now counts towards the Inactive Workspace condition, so a workspace someone relies on is not deleted by an inactivity policy simply because they never opened a session inside it.

Starting a workspace still does not postpone the idle timeout that pauses it, so the cost savings from idle pausing are unchanged.

For more information, see Custom Actions.

Guided workspace creation, and a way to require templates

Creating a workspace now starts with a dialog that asks how you want to create it: from a template, from scratch, or by copying an existing workspace. Create from Template is marked as recommended. This replaces the split button, where the template and copy routes were hidden in a drop-down and easy to miss.

Platform administrators can also now require templates. A new Require templates for workspace creation permission on a role restricts everyone holding that role to creating workspaces from a template; the custom and copy options are shown but disabled, with a tooltip explaining why. Use it where every workspace in a project has to be reproducible and consistent.

For more information, see Create a workspace and Roles and permissions.

Archive workspace templates

Workspace templates can now be archived and restored. Archive a template to stop it from being used for new workspaces while keeping the existing workspaces that were created from it.

An archived template cannot be selected in the create-workspace flow or through a Quickstart link, and is hidden from the Templates list unless you choose to show archived templates. Because a template cannot be deleted while workspaces still use it, archiving is the supported way to retire a template that is still in use.

For more information, see Templates.

Deleted workspace recovery

Deleted workspaces now move to a recoverable Deleted Workspaces area before permanent deletion. This gives users a safety window to restore a workspace that was deleted accidentally and helps administrators manage the retention period.

Project owners can restore or permanently delete workspaces from the project settings view. Platform administrators can review deleted workspaces across projects and adjust how many days deleted workspaces remain recoverable before they are removed permanently.

For more information, see Profile Overview.

Installation and ingress configuration improvements

Administrators have more deployment options in this release. Helm values now support license configuration during deploy or upgrade, HAProxy ingress annotations, and an option to skip rendering cert-manager Certificate resources for clusters that do not use cert-manager.

These options reduce manual post-installation work and help fit SecurSpaces into a wider range of Kubernetes environments.

For more information, see Technical Requirements.

SecurSpaces 2026.4

SCIM user and group responses include membership details

SCIM responses now include more complete group membership information for identity providers that validate membership through the SecurSpaces SCIM API. The /Users endpoint returns the direct groups a user belongs to, and the /Groups list endpoint returns each group’s members without requiring a separate filtered group lookup.

This improvement helps administrators connect SecurSpaces to SCIM providers that expect user and group membership data to be available during synchronization checks. Users without group memberships still omit the groups attribute, so empty group data is not added to their SCIM user response.

For more information, see SCIM.

Platform teams can now manage workspace template Quickstart links through the REST API. This helps teams automate Quickstart links for developer portals, repository README files, and other onboarding workflows without manually copying links from the SecurSpaces console.

The API can enable, retrieve, and revoke a template’s Quickstart link. Responses include the URL and ready-to-use Markdown and HTML embed snippets, so automation can keep portal content synchronized with the current template link.

Key capabilities include:

  • Enable, retrieve, and revoke Quickstart links for workspace templates
  • Retrieve the raw URL, Markdown snippet, and HTML snippet for a Quickstart link
  • Use light or dark embed button styles for generated snippets
  • Create workspaces from Quickstart links through the same flow as UI-generated links

For more information, see REST API and Templates.

Custom Access Items in the REST API

Custom Access Items are now available through the REST API for workspaces and workspace templates. This gives platform teams API parity with the SecurSpaces console for adding one-click access entries to internal tools or services that run inside a workspace.

API callers can include Custom Access Items when creating workspaces and templates, update the full set of items on an existing workspace, and read configured items from workspace and template responses. Each item can define a display name, port, command, optional icon, and optional health probe.

Key capabilities include:

  • Add Custom Access Items when creating a workspace or workspace template
  • Update or remove Custom Access Items on an existing workspace
  • Read Custom Access Item status and URLs from workspace API responses
  • Receive machine-readable validation errors for invalid ports, duplicate names, missing commands, or unsupported icons

For more information, see REST API and Create a Workspace.

Self-hosted release documentation

SecurSpaces product documentation is now bundled with each release and served from the control plane. This helps air-gapped and restricted-network deployments keep documentation available without relying on external internet access.

Users can open the bundled documentation from the SecurSpaces environment at /docs/. The release also includes an llms.txt format so AI tools can read the same release-matched documentation when your organization permits that access.

Key capabilities include:

  • Access release-matched product documentation from the deployed SecurSpaces environment
  • Keep documentation available in environments without direct internet access
  • Provide AI-readable documentation through llms.txt

For more information, see Give your AI assistant access to SecurSpaces documentation.

Workspace API updates for IDE extensions

The workspace APIs now include more information and operations for IDE extension integrations. These updates help IDE extensions show richer workspace details and manage personal workspaces without requiring users to switch back to the SecurSpaces console.

The new API support includes workspace details for attached repositories, mount points, and data buckets. IDE extensions can also use capability flags from /version.json to enable features only when the deployed SecurSpaces version supports them.

Key capabilities include:

  • Retrieve personal workspace details from GET /v1/personal_workspaces/{workspace_id}
  • Delete a personal workspace with DELETE /v1/personal_workspaces/{workspace_id}
  • Use /version.json capability flags for extension feature gating
  • Read VSCode version fields in workspace API responses

For more information, see REST API and VSCode versions.

AI Gateway routing from Helm values

Platform administrators can now configure AI Gateway routing directly in the SecurSpaces Helm values. This update lets deployments intercept selected AI service domains and route that traffic through an internal AI Gateway service.

Use this configuration when your organization wants centralized control for AI provider access from workspaces. The Helm values support both platform-wide settings and region-specific overrides for external regions.

Key capabilities include:

  • Configure the internal AI Gateway service address with platform.aiGateway.address
  • List AI provider DNS endpoints to intercept with platform.aiGateway.dnsEndpoints
  • Override the platform-wide values per region with region.aiGateway

For more information, see Configure AI Gateway routing.

X.509 authentication for external MongoDB

SecurSpaces can now connect to an external MongoDB deployment by using X.509 certificate authentication. This gives organizations an alternative to username and password authentication for external MongoDB services such as MongoDB Atlas.

Administrators can select the MONGODB-X509 authentication mechanism in Helm values and provide the client certificate, private key, and optional certificate authority bundle either as base64-encoded values or from an existing Kubernetes Secret.

For more information, see External MongoDB X.509.

Guidance for blocked outbound SSH connections

When a workspace tries to start an outbound SSH connection and no SSH method is configured for the target host, SecurSpaces now shows an actionable terminal message before closing the connection. Previously, the user saw only that the SSH connection closed.

The message explains that an administrator must enable either Personal SSH Identity or a Connected SSH Service before the workspace can connect to external hosts over SSH.

For more information, see Connect to external servers and services via SSH.

Smarter workspace idle detection

SecurSpaces now uses a hybrid approach to determine whether a workspace is truly idle before pausing it. Previously, an open SSH connection was enough to keep a workspace running indefinitely, even when no one was actively working. This led to unnecessary infrastructure costs, for example, when developers left their IDE open overnight or over the weekend.

The new idle detection engine introduces three layers of intelligence:

  • IDE activity signals take priority. When the SecurSpaces IDE extension is active, the system uses granular input signals such as keyboard and mouse activity to determine whether a user is present. An open but unused SSH connection alone no longer prevents a workspace from pausing.
  • SSH fallback for unsupported IDEs. For developers using IDEs that do not support the SecurSpaces extension, the system falls back to the previous SSH-based logic, so active work is not interrupted.
  • Manual override. security officers can deactivate idle detection for select workspaces to support long-running services, such as shared development tooling or components. When activated, the workspace continues to run even without direct user input.

For more information, see Workspace idle detection for SSH connected workspaces

Shared storage mount points

Teams that work with large, shared datasets, such as ML training data, model artifacts, or experiment results, can now mount external storage directly into their workspaces. This new capability, called Mount Points, removes the need to copy data into the cluster before it becomes accessible.

Previously, SecurSpaces only offered Data Buckets, which function as point-in-time snapshots. While useful for versioning, snapshots duplicate data onto the cluster, require significant disk space, take a long time to replicate for large datasets, and prevent real-time collaboration because updates require a manual publish cycle.

With mount points:

  • Platform admins enable the feature globally under Settings > Integrations.
  • Project owners configure mount points by specifying the storage details, including server address, share name, default mount path, and access permissions (read-only or read-write).
  • Developers attach available mount points when creating a workspace or workspace template. The mount path can be customized per workspace, and the system prevents path conflicts.

This initial release supports only Azure file-based storage.

For more information, see Sharing Data Between Users - Mount Points.

Unified access with Citrix DaaS (Technical Preview)

SecurSpaces now integrates with Citrix DaaS and Citrix Workspace to provide a unified access experience across Linux, Windows, and macOS development environments. Until now, SecurSpaces supported only Linux-based Kubernetes workspaces, excluding teams that depend on Windows or macOS tooling, such as Xcode, full Visual Studio, or platform-specific simulation tools.

With this integration, developers can access both traditional SecurSpaces workspaces and Citrix-based virtual desktops and applications from a single console. Users only need to sign in once in the SecurSpaces console, and all SecurSpaces- and Citrix-based resources can be accessed seamlessly without further authentication.

This feature provides:

  • Unified access to Kubernetes-based and Citrix-based apps and workspaces from the SecurSpaces console
  • Integrated authentication with single sign-on
  • Access to virtual apps and desktops with the native Citrix Workspace app

This feature allows organizations to bring more developer teams onto one secure platform while leveraging their existing Citrix infrastructure and licensing.

For more information, see Citrix DaaS Integration.

Independent VS Code version management

VS Code updates are no longer tied to SecurSpaces platform releases. Previously, customers had to wait for a full SecurSpaces upgrade to get a newer VS Code version, which could delay access to new editor features and plugin compatibility.

With this release, VS Code is delivered and updated independently from the SecurSpaces platform. Key capabilities include:

  • Controlled updates and rollback. Administrators can adopt new VS Code versions when ready and roll back to a previous version if issues arise.
  • Offline and air-gapped support. Organizations that restrict internet access from the control plane or workspaces can host VS Code update files on an internal distribution point such as an artifact repository or network share.
  • Built-in notifications. SecurSpaces admins and security officers receive notifications through the built-in notification system when a new VS Code version becomes available.
  • User-controlled upgrades. Developers can control when the VS Code update is applied to each of their workspaces, similar to the existing workspace upgrade flow.

For more information, see VSCode Versions.

Native support for Kiro IDE

Kiro is now supported as an IDE for SSH-based workspace connections, joining VS Code Desktop, JetBrains Gateway, Cursor, and Windsurf. Previously, Kiro users had to manually configure SSH connections and extension installations to access their SecurSpaces workspaces.

With this update, the Connect via SSH modal in the SecurSpaces console includes Kiro as a launch option. Selecting it opens Kiro on the developer’s local machine, automatically installs or activates the SecurSpaces extension, and establishes the remote SSH connection to the target workspace.

For more information, see Connect to a workspace via SSH

Improved user onboarding flow

The Add User flow for projects has been redesigned to reduce errors and speed up onboarding. Project owners can now add users in bulk by pasting a list of email addresses, with inline validation and clear error feedback. Single-user search is limited to platform users not yet in the project, avoiding confusion. When adding external users, the flow guides the admin through the required additional details before completing the operation.

For more information, see Add and remove users and groups - Bulk add users

Automatic SecurSpaces extension installation for SSH connections

When connecting to a workspace via SSH from VS Code Desktop, SecurSpaces now automatically installs the required SecurSpaces extension on the remote workspace. This removes a previously manual step and reduces connection setup failures.

Configurable ghost workspace resources via Helm

Ghost workspace resource specifications can now be configured through the Helm chart, giving administrators more control over resource allocation for pre-provisioned workspaces.

Kubernetes PriorityClass support for workspace pods

Administrators can now assign a Kubernetes PriorityClass to workspace pods through a new optional Helm configuration field. When set, all newly created workspace pods are assigned the specified priority class, allowing Kubernetes schedulers and tools like Karpenter to make better scaling and scheduling decisions. When the setting is omitted, existing behavior is unchanged.

Debian desktop image with browser access

A new preconfigured Debian-based container image with NoVNC is now available, providing a full desktop environment directly accessible in the browser. This option is useful for teams that need GUI-based tooling or testing environments within their SecurSpaces workspaces.

VS Code updated to 1.114

SecurSpaces now ships with VS Code 1.114, bringing the latest editor features and plugin compatibility improvements.

Improved downloads for large analytics exports

Workspace measurement exports can now reliably handle large report files. Administrators and security officers can download workspace analytics filtered by organization, project, and date range, even when the resulting files are too large for a standard API call. The download mechanism now uses an optimized transfer path to support large file sizes.

For more information, see Workspace resource usage insights - Access workspace measurements

Preserve Host proxy option for workspace apps

Workspace apps now include a Preserve Host proxy option. When enabled, the proxy forwards the workspace app’s public URL in the Host header, aligning it with the Origin and X-Forwarded-Host headers. This allows tools like Jupyter Notebook and pgAdmin to work behind the SecurSpaces proxy service without custom per-tool proxy configuration. The option is turned off by default to avoid breaking local development workflows that expect localhost.

For more information, see Workspace Apps - Override Host Header

Self-service OpenAPI specification downloads

The SecurSpaces REST API documentation page now includes a Download OpenAPI specification button. The OpenAPI spec is automatically packaged and shipped with every minor and major SecurSpaces release, so platform engineering teams can download the spec that matches their currently deployed SecurSpaces version without contacting Citrix.

Custom documentation URL

Platform admins can now replace the default SecurSpaces documentation link with a custom URL that points to their organization’s internal documentation. When enabled under Settings > General > Documentation, the custom link applies globally and updates the Documentation entry in the user profile menu for all users, projects, and organizations. When disabled, the link reverts to the default SecurSpaces documentation.

For more information, see General Settings - Documentation

Custom OpenVSX marketplace for VS Code extensions

Platform administrators can now point all VS Code workspaces to a custom OpenVSX marketplace under Settings > General > OpenVSX Marketplace, replacing the previous manual EXTENSIONS_GALLERY environment variable approach. The setting is inherited across all organizations, projects, and workspaces. New workspaces use the configured marketplace immediately; existing workspaces pick up the change after their next restart.

For more information, see General Settings - OpenVSX Marketplace

UI enhancements

Simpler workspace template versioning

Edit, Publish, and Set as Default actions are now directly available in the template version list, making versioning steps faster and easier to discover.

Streamlined Add Image workflow

The container image import flow now starts with the image URL, auto-fills fields where possible, supports inline credential entry, and includes clearer descriptions and tooltips.

Alphabetical sorting for workspaces and templates

Workspace and template lists are now sorted alphabetically by default.

Separate control for in-app guides

Usage Analytics settings now let administrators keep analytics enabled while turning off in-app guides independently.

Better search in dropdowns

Larger dropdowns now show a visible search field that is focused on open, with options sorted alphabetically.

Consistent select components

SecurSpaces now uses a unified select component with consistent search and sorting behavior across the console.

Cleaner Set as Default for container images

The Set as Default action is now shown more selectively in the container image version list, reducing visual clutter while keeping the action accessible.

Startup scripts description

The Startup Scripts step in the workspace and template wizard now includes a description explaining when and why to use startup scripts.

Language selector moved to user profile

Language selection has moved from the page footer to user profile settings, now labeled with language names instead of flags.

Consistent wizard exit warning

SecurSpaces now always warns users before they leave the workspace or template wizard, regardless of navigation path, and uses clearer dialog labels.

Improved empty secrets message

When no secrets exist, the wizard now shows guidance on how to add one instead of implying that a filter returned no results.

Clearer filter no-results messages

Filtered lists now show a contextual no-results message with a Clear Filters action so that users can distinguish between empty results and missing data.

Standardized UI components and tooltips

Icons, tooltips, and styling patterns are now more consistent across the SecurSpaces console.

Bug fixes

Context menus close on scroll

Context menus now close automatically when the user scrolls, preventing visual artifacts from continuous repositioning.

Maintenance banner stays aligned during scrolling

The maintenance notification banner no longer briefly slips under the menu bar when scrolling on long pages.

Validation checkmark no longer appears on empty input

The secret name input field no longer shows a success checkmark when the field is empty or invalid.

Consistent image cache scheduling across nodes

Image cache pods are now scheduled with node-level anti-affinity, ensuring one pod runs on every Karpenter-managed workspace node instead of one per availability zone. This restores predictable warm node behavior in multi-AZ clusters.

SecurSpaces 2025.10

This release contains the following new features:

Renewal warning for CA certificates

SecurSpaces now displays a warning when a CA certificate is approaching expiration, enabling administrators to take timely action to renew certificates and prevent service disruptions.

Workspace resource usage insights

SecurSpaces now provides historic insights into workspace CPU and RAM consumption. This data is automatically collected and stored in the SecurSpaces database, and can be accessed via the workspace-measurements and workspace-measurement-samples APIs to support rightsizing analysis and long-term trending insights.

The system gathers the following information:

  • CPU usage over time
  • RAM usage over time

The data is retained for 7 days.

For more information, see Workspace resource usage insights

Enhanced idle detection for SSH sessions

When users connect to a SecurSpaces workspace via SSH with the SecurSpaces/Strong Network plugin, SecurSpaces can now monitor activity with greater precision. This will allow the system to pause idle workspaces more reliably, improving cost efficiency without disrupting active sessions. Users without the SecurSpaces/Strong Network plugin installed in their local IDE will be asked to install it via a notification within the SecurSpaces console. Administrators can use the SecurSpaces API /v1/metrics/ssh-workspaces-no-extension-usage to determine a list of users connecting via SSH without the plugin installed.

Note:

The initial version of this release will not change the behavior of the SecurSpaces scheduled to minimize the disruption to existing users. A future minor version will enable the scheduler changes.

Enhanced Quickstart workspace creation

The Quickstart interface, used when creating a new workspace via a Quickstart link, has been enhanced. Before provisioning, users can now review:

  • The image and template used to create the workspace
  • The organizational location where the workspace will be deployed

Additionally, users can select the template version and geographic deployment location, providing greater control and transparency during workspace setup.

For more information, see Quickstart

Support for Azure Cosmos DB

SecurSpaces now supports Azure Cosmos DB as a managed database option, in addition to MongoDB Atlas. This gives teams greater flexibility in choosing the database service that best fits their workloads and cloud environment.

Workspace template flow: Add draft & promote functionality

New Workspace template versions are now created in a draft state. Drafts can be modified and tested until they are explicitly promoted to the default version. This workflow simplifies the process of iterating on templates while preventing users from inadvertently using versions that are not production-ready.

For more information, see Create a new version of a Template

Template duplication in the SecurSpaces console

Project owners can now duplicate existing Workspace templates directly within the SecurSpaces console. This makes it easier to create new templates that share the same toolstack and integrations as existing ones, while allowing for fine-tuned configuration to meet specific developer needs.

Workspace resource visibility and sorting

The Project/Workspace view now displays the full resource configuration (CPU, RAM, and storage) for every workspace in a project. Workspaces can also be sorted by these attributes, enabling project owners to quickly identify high-resource allocations and support rightsizing activities.

New filters in Project/Workspaces view

A new filter option has been added to the Project/Workspaces view, making it easier to identify workspaces with specific characteristics within large projects. Available filter criteria include:

  • Owner – workspace owner
  • Image – base image used for the workspace
  • Created On – creation date
  • Status – current workspace status
  • CPU, RAM, Storage – allocated resources

This enhancement streamlines workspace management and helps quickly locate relevant workspaces.

For more information, see Filtering Workspaces

Optimized Console Responsiveness

We have significantly optimized the way the SecurSpaces console loads data, resulting in a much more responsive and fluid user experience.

  • Near-instant navigation: Actions that previously had a short delay are now almost instant. For example, navigating from the platform level into a specific project is notably faster.
  • Improved workflow: This foundational enhancement minimizes wait times, improving your overall workflow and making the console feel smoother and more efficient.

Interactive onboarding guides

When accessing the SecurSpaces web console for the first time, users are now presented with interactive onboarding guides. These guides highlight key functionality and walk through important first steps, helping new users get up and running more quickly.

Updated Visual Studio Code version

SecurSpaces workspaces now include Visual Studio Code v1.105.1, providing the latest features, improvements, and fixes.

Improved workspace creation workflow

The input fields for creating a new workspace from a template have been reorganized to reduce the number of clicks required. Additionally, the proposed workspace name is now automatically generated using the format <First Name><First 3 letters of Surname>-<TemplateName>, streamlining the setup process and ensuring consistent naming.

For example: StevenGal-Frontend Workspace

Enhanced UX for workspaces without resource limits

SecurSpaces now allows customers to create workspaces without CPU or RAM limits, enabling fully elastic scalability. Workspaces configured with unlimited resources will display an infinity symbol for the affected resource, providing a clear visual indicator of this configuration.

Default selection of current user for resource ownership

Whenever SecurSpaces prompts for an owner of a newly created resource, the current user is now listed at the top of the user list. This change streamlines common workflows and speeds up the resource creation process.

Enhanced user details page

The user details page now displays user-configured workspace schedules and lists all workspaces with custom schedules. This page is also accessible to project owners, in addition to security officers. The enhanced view provides better visibility into a user’s context and special configurations, aiding troubleshooting and workspace management.

Backstage plugin for SecurSpaces

SecurSpaces now offers a plugin for Backstage, enabling users to list and access all workspaces associated with a specific software project, as well as create new workspaces directly from Backstage. For organizations using a Backstage-based Integrated Developer Portal, this integration streamlines developer workflows and simplifies workspace management.

For more information, see SecurSpaces Workspaces Plugin for Backstage

HashiCorp Vault integration for secret management

SecurSpaces now integrates with HashiCorp Vault, the leading secret management solution. When enabled, all secrets previously stored in the SecurSpaces database are securely stored in Vault. This includes:

  • Platform secrets: Platform SSH private key, OAuth app secrets, email gateway secrets, and workspace image registry credentials
  • User secrets: User SSH personal identity, private SSH keys, and GPG keys

This integration enhances security by centralizing secret management and leveraging Vault’s robust access controls and auditing capabilities.

For more information, see Use HashiCorp Vault as a Secret Manager

Usage Telemetry

SecurSpaces now collects usage telemetry to help improve the platform. This telemetry is used for understanding feature adoption and identifying areas for performance and usability improvements. No personal data is collected, and all information is handled in accordance with organizational privacy policies.

Pendo integration for in-app guidance and analytics

SecurSpaces now collects usage telemetry to help improve the platform. This telemetry is used for understanding feature adoption and identifying areas for performance and usability improvements. No personal data is collected, and all information is handled in accordance with organizational privacy policies. https://FQDN/platform/settings/analytics/usage_analytics

For more information, see Usage Analytics

What's new