Citrix Secure Spaces Flex: A Smarter, More Secure Way to Power Modern Developer Environments

Aug 17, 2026

How do you support developers securely without drowning your IT team in VDI overhead? In episode 2 of season 2 of The Citrix Session (episode 191 overall), XenTegra’s Andy Whiteside and Charles Anderson are joined by Citrix’s Tarkan Kocoglu, Mathew Varghese, and Somesh Naidu, to break down the newly announced Citrix Secure Spaces Flex. They discuss why modern, Linux-heavy development doesn’t fit neatly into traditional virtual desktops, how Secure Spaces gives developers, and increasingly AI agents, secure, disposable container-based workspaces instead of persistent VMs, and how the new Flex consumption model lets organizations pay for exactly the developer personas they need. Whether you’re supporting in-house developers, outside contractors, or looking for a safe way to sandbox agentic AI, this episode makes the security, experience, and cost case for modernizing how developers work.

Secure, Scalable Developer Environments Without the Infrastructure Burden

For years, organizations have turned to Citrix virtual desktops to give in-house developers and outside contractors secure access to the tools they need. It solved a real problem, but it came with real costs: persistent machines that often required admin rights, sized for peak usage, and sitting idle (or worse, forgotten) long after a project wrapped.

Modern development doesn’t look like that anymore. Today, more than 80% of development work happens in some kind of Linux environment (whether that’s the Windows Subsystem for Linux, Docker, or a browser-based IDE), and traditional VDI was never built for it. In the latest episode of The Citrix Session, XenTegra’s Andy Whiteside sits down with Citrix’s Tarkan Kocoglu to talk through Citrix Secure Spaces and its new Flex consumption model, and why it may be the answer for any organization still wrestling with how to support developers, and their AI agents, securely.

What Is Secure Spaces Flex?

Citrix Secure Spaces gives organizations a Kubernetes- and container-based foundation for modern development: the same kind of control and governance Citrix has long provided for virtual desktops, applied to Docker and Kubernetes environments instead. Flex, a consumption model Citrix already uses for DaaS, now extends to Secure Spaces: rather than provisioning and licensing for peak usage, organizations choose from light, medium, and heavy workspace templates mapped to a developer’s actual needs, and Citrix manages the underlying Kubernetes cluster on Azure. Organizations that don’t already have a Kubernetes environment (or the in-house skills to build one) get that infrastructure handled for them.

The Hidden Cost of Supporting Developers the Old Way

Whether developers work on local hardware or a traditional VDI, the operational overhead adds up:

  • Procuring and provisioning hardware can take weeks, and CPU/RAM pricing keeps climbing.
  • Source code and secrets sitting on local endpoints create real IP-leakage risk.
  • Persistent, admin-rights VDI machines are hard to reconcile with a strong security posture.
  • VDI has to be sized for peak compute (compiling code, running containers), so organizations end up paying to double specs (and cost) for capacity that mostly sits idle.
  • Tooling like WSL and nested Linux environments can create blind spots for security tools that can’t see what’s happening inside them.
  • Projects end, but the VDI often doesn’t get decommissioned; it just sits unused until someone notices.

Containers, Not Full Desktops

Instead of a persistent VM, a project or engineering manager defines a workspace template (the tooling, libraries, and secrets a developer needs) and publishes it as a link. Developers open it from Citrix Workspace, a browser, or their existing local IDE, and get a ready-to-use environment (VS Code, JetBrains, and other container-friendly tools are all supported, with SSH access for anything else). It spins up in seconds, and when the project is done, it can be decommissioned just as quickly: no lingering VM, no cleanup project six months later.

Want to see it in action? Watch the Secure Spaces demo referenced in the episode.

Security Built In, Not Bolted On

Security is where Secure Spaces does its heaviest lifting:

  • DLP-style controls (paired with a secure browser) can detect and block a developer copying an API key or secret out of the environment, or simply log it for audit.
  • A secure proxy sits between the workspace and the backend, so code, credentials, and libraries never actually live on the local device, browser session, or VDI: if an endpoint is compromised, there’s nothing there to steal.
  • The architecture follows zero-trust principles by design: nothing persists locally, anywhere in the chain.
  • Paired with the NetScaler AI Gateway, organizations get visibility into which users are calling which AI models and how much they’re consuming, and can sandbox agentic AI so an agent can’t break out of its containment.

A Better Developer Experience

Security and user experience don’t have to fight each other. Developers keep working the way they already do (through a browser, a published app, or their own local VS Code) while the compute, and the risk, moves to a centralized, governed backend. Light, medium, and heavy templates map to task workers, knowledge workers, and developers respectively, so performance is sized to the job instead of guessed at.

Predictable, Persona-Based Cost

Flex introduces a new “developer worker” persona alongside its existing ones, so organizations spend Flex credits based on real usage instead of provisioning for worst-case scenarios. That predictability extends further with the NetScaler AI Gateway, which lets organizations track (and cap) AI token consumption per user, so one heavy user can’t quietly burn through a team’s monthly AI budget. It also sidesteps a familiar VDI cost trap: outgrowing a VM size and having to double specs (and cost) just to keep up with a handful of developers.

Modernize Without a Hard Cutover

Few organizations are ready to move every developer over at once, and they don’t have to. Citrix recommends starting small: pilot Secure Spaces Flex with one developer group or one particularly painful use case (yes, including the developer juggling eight laptops for eight different projects), measure the results, and expand from there. VDI can stay in place as the entry point for the organization while Secure Spaces takes over the compute and governance behind it.

Why Partner with XenTegra?

Nearly 200 episodes into The Citrix Session, XenTegra has spent years helping organizations get more out of the Citrix platform, and Secure Spaces Flex is no exception. XenTegra can help you:

  • Evaluate whether in-house developers, contractors, or emerging agentic AI use cases are a fit for Secure Spaces Flex.
  • Map your developer and AI personas to the right light, medium, or heavy template sizing.
  • Integrate Secure Spaces alongside your existing Citrix DaaS/VDI environment and NetScaler AI Gateway.
  • Build a phased, low-risk rollout plan that starts with a pilot and scales from there.

Good IT doesn’t just secure the business: it makes people more productive while doing it. That’s the balance Secure Spaces Flex is built around, and it’s the same balance XenTegra has helped Citrix customers strike for years.

en_USEnglish