# Citrix SecurSpaces™ > Citrix SecurSpaces™ is a secure, cloud-based development environment (CDE) designed to enhance developer productivity while maintaining enterprise-grade security. Each entry below links to a documentation page on docs.citrix.com. The full corpus in a single file is available at https://assets.sds.citrix.com/llms-full.txt. ## About SecurSpaces - [About SecurSpaces](https://docs.citrix.com/en-us/securspaces/): Citrix SecurSpaces™ is a secure, cloud-based development environment (CDE) designed to enhance developer productivity while maintaining enterprise-grade security. - [SecurSpaces for developers](https://docs.citrix.com/en-us/securspaces/about/securspaces-for-developers.html): `Developer` - [SecurSpaces for AI and ML engineers](https://docs.citrix.com/en-us/securspaces/about/securspaces-for-ai-ml-engineers.html): `AI/ML Engineer` - [SecurSpaces at a glance](https://docs.citrix.com/en-us/securspaces/about/at-a-glance.html): A summary of what Citrix SecurSpaces™ runs on, what it integrates with, and where its limits are, for anyone deciding whether it fits their environment. - [How it works](https://docs.citrix.com/en-us/securspaces/about/how-it-works.html): Citrix SecurSpaces™ is a cloud-native platform for hosting Cloud Development Environments (CDEs). - [Concepts](https://docs.citrix.com/en-us/securspaces/about/concepts/): Citrix SecurSpaces™ is arranged as four nested levels. - [Platform](https://docs.citrix.com/en-us/securspaces/about/concepts/platform.html): The platform is organized in organizations and projects. - [Organizations](https://docs.citrix.com/en-us/securspaces/about/concepts/organizations.html): The platform allows administrators and platform owners to organize projects into organizations. - [Projects](https://docs.citrix.com/en-us/securspaces/about/concepts/projects.html): A **Project** within an Organization regroups developers, resources, and security rules. - [Workspaces](https://docs.citrix.com/en-us/securspaces/about/concepts/workspaces.html): A workspace is a Cloud Development Environments (CDEs) available for coding and data science. - [SecurSpaces Flex](https://docs.citrix.com/en-us/securspaces/about/flex/): Citrix SecurSpaces™ Flex is a Citrix-managed service within Citrix Platform Flex that delivers secure Linux workspaces for development teams. - [Videos](https://docs.citrix.com/en-us/securspaces/about/videos.html): This video playlist features tutorials and best practices for Citrix SecurSpaces™, demonstrating how it accelerates innovation with self-service, secure, scalable, ready-to-code Linux developer environments. ## Get started - [Get started](https://docs.citrix.com/en-us/securspaces/get-started/): Start here if you are new to Citrix SecurSpaces™. - [Set up your account](https://docs.citrix.com/en-us/securspaces/get-started/set-up-your-account.html): `Developer` - [Your first workspace](https://docs.citrix.com/en-us/securspaces/get-started/your-first-workspace.html): `Developer` - [Hello World workspace](https://docs.citrix.com/en-us/securspaces/get-started/hello-world-workspace.html): `Developer` - [Develop, debug, and share a Node.js app](https://docs.citrix.com/en-us/securspaces/get-started/develop-debug-and-share.html): `Developer` - [Set up a project for your team](https://docs.citrix.com/en-us/securspaces/get-started/set-up-your-project.html): `Project Owner` - [Deploy for evaluation with the 1-Click VM](https://docs.citrix.com/en-us/securspaces/get-started/deploy-for-evaluation.html): Use this guide to deploy a virtual machine (VM) running the SecurSpaces platform using the automated installer. - [Deploy for evaluation on XenServer](https://docs.citrix.com/en-us/securspaces/get-started/deploy-for-evaluation-xenserver.html): The SecurSpaces platform provides a secure and productive cloud development environment that can be deployed on public, private clouds, and self-hosted servers. ## Develop - [Develop](https://docs.citrix.com/en-us/securspaces/develop/): This section is for **developers** working inside a Citrix SecurSpaces™ workspace. - [Develop in a workspace](https://docs.citrix.com/en-us/securspaces/develop/develop-in-a-workspace.html): `Developer` - [Console overview](https://docs.citrix.com/en-us/securspaces/develop/console-overview.html): The Overview page is the first page displayed when you access the platform's user interface. - [Workspaces page](https://docs.citrix.com/en-us/securspaces/develop/workspaces/): In the scope of a project, the **Workspaces Page** displays all workspaces created for that particular project to which you have access or you can view, depending on your permission level. - [Create a workspace](https://docs.citrix.com/en-us/securspaces/develop/workspaces/create.html): A workspace is a cloud development environment that you reach through the browser IDE, a terminal, or SSH. - [Manage workspaces](https://docs.citrix.com/en-us/securspaces/develop/workspaces/manage.html): Workspaces are managed from the Overview and Workspaces pages. - [Connect over SSH](https://docs.citrix.com/en-us/securspaces/develop/workspaces/connect-over-ssh.html): An SSH-based connection lets you work in a Citrix SecurSpaces™ workspace from a locally installed IDE such as VS Code, Cursor, Windsurf, Kiro, or JetBrains. - [What persists in a workspace](https://docs.citrix.com/en-us/securspaces/develop/what-persists.html): Citrix SecurSpaces™ workspaces are containerized and ephemeral. - [Connect to external services over SSH](https://docs.citrix.com/en-us/securspaces/develop/connect-to-external-services.html): You often need to reach systems outside your workspace over SSH — to push to a Git repository hosted on Azure DevOps, deploy to a staging server, or open a session on a remote database host. - [Share a running application](https://docs.citrix.com/en-us/securspaces/develop/collaborate/workspace-apps.html): A **Workspace App** lets you access an application or process through HTTP or HTTPS running on a port of your Workspace. - [Your profile](https://docs.citrix.com/en-us/securspaces/develop/profile/): The **Profile and Account Settings** pages let you manage personal data and set preferences around your work habits. - [Overview](https://docs.citrix.com/en-us/securspaces/develop/profile/overview.html): The **Profile Overview Page** serves as a comprehensive summary of the user's information, their workspace ownership and project membership. - [Integrations](https://docs.citrix.com/en-us/securspaces/develop/profile/integrations.html): In the **Integration Page** you can manage the different access keys, secrets and tokens that are linked to the user's profile. - [Configuration](https://docs.citrix.com/en-us/securspaces/develop/profile/configuration.html): The **Configuration Page** is used to create and edit custom shell scripts and configuration files, configure your IDE and define personal workspace startup scripts. - [Security](https://docs.citrix.com/en-us/securspaces/develop/profile/security.html): The **Security** page of your profile is where you manage the keys, secrets, and tokens tied to your user account, and where you review what has access to your account. - [Persistent Docker](https://docs.citrix.com/en-us/securspaces/develop/persistent-docker.html): Persistent Docker lets developers keep pulled Docker images on their workspace's persistent volume. - [Run a graphical desktop](https://docs.citrix.com/en-us/securspaces/develop/run-a-graphical-desktop.html): Some workflows need more than a browser-based IDE and terminal. - [Install SecurSpaces as a desktop app](https://docs.citrix.com/en-us/securspaces/develop/install-as-a-desktop-app.html): Citrix Secure Access with Chrome Enterprise Premium and SecurSpaces provide a high-performance, zero-trust environment for cloud-based development. - [Work from a virtual desktop](https://docs.citrix.com/en-us/securspaces/develop/work-from-a-vda.html): `Developer` - [Give your AI assistant access to the documentation](https://docs.citrix.com/en-us/securspaces/develop/ai-assistant-access.html): If you use an AI coding assistant — GitHub Copilot, Claude Code, Cursor, Windsurf, or a self-hosted LLM — you can give it access to the full Citrix SecurSpaces™ documentation so it can answer SecurSpaces-specific questions accurately and help you with SecurSpaces tasks. - [Troubleshooting](https://docs.citrix.com/en-us/securspaces/develop/troubleshooting.html): `Developer` ## Manage - [Manage](https://docs.citrix.com/en-us/securspaces/manage/): This section is for **project owners** and anyone else running a project day to day. - [Onboard developers](https://docs.citrix.com/en-us/securspaces/manage/onboard-developers/): `Project Owner` - [Reusable onboarding template](https://docs.citrix.com/en-us/securspaces/manage/onboard-developers/onboarding-template.html): Use this template to onboard developers to Citrix SecurSpaces™. - [People](https://docs.citrix.com/en-us/securspaces/manage/people/): The People page contains information about users onboarded to a project, an organization or the entire platform. - [Users](https://docs.citrix.com/en-us/securspaces/manage/people/users.html): The **People** page displays users at two levels: project and platform. - [Add and remove users](https://docs.citrix.com/en-us/securspaces/manage/people/add-and-remove-users.html): This page describes how to add and remove users and groups in a project. - [Roles and permissions](https://docs.citrix.com/en-us/securspaces/manage/people/roles.html): Access in Citrix SecurSpaces™ is granted through **roles**. - [Projects and organizations](https://docs.citrix.com/en-us/securspaces/manage/projects-and-organizations.html): General settings for a project and for the organization that contains it, and the recovery windows that apply when either is deleted. - [Templates](https://docs.citrix.com/en-us/securspaces/manage/templates/): Workspace **Templates** help streamline project onboarding by eliminating the need for manual workspace setup. - [Workspace images](https://docs.citrix.com/en-us/securspaces/manage/images/): While standard images provide a quick start, using custom workspace images within Citrix SecurSpaces™ ensures your development environment is tailored to your organization’s needs while maintaining strict compliance. - [Container images](https://docs.citrix.com/en-us/securspaces/manage/images/container-images.html): Container images or also Cloud Development Environments (CDEs) are used to define the configuration of a development environment. - [Update an existing container image](https://docs.citrix.com/en-us/securspaces/manage/images/update-container-image.html): This article focuses on the platform workflow to update an existing container image so teams can reuse a consistent, preconfigured toolchain across workspaces. - [Create an image from an existing one](https://docs.citrix.com/en-us/securspaces/manage/images/create-an-image.html): Requires the Resources permission set to **Import**. - [Manage workspace toolchains](https://docs.citrix.com/en-us/securspaces/manage/images/toolchains.html): A toolchain manager lets each project declare the language runtimes and tools it needs in a file in its own repository, so one base container image serves many teams. - [Manage toolchains with Mise](https://docs.citrix.com/en-us/securspaces/manage/images/toolchains-with-mise.html): Instead of building and maintaining separate container images for every team, you can use Mise-en-Place (Mise) to define project-specific toolchains on top of a single base image. - [Manage toolchains with Nix](https://docs.citrix.com/en-us/securspaces/manage/images/toolchains-with-nix.html): Instead of building and maintaining separate container images for every team, you can use Nix Package Manager (Nix) to define project-specific toolchains on top of a single base image. - [Project resources](https://docs.citrix.com/en-us/securspaces/manage/resources/): On the resources page, you can view and manage the different resources used in the project. - [Code repositories](https://docs.citrix.com/en-us/securspaces/manage/resources/code-repositories.html): Importing a repository into a project is what lets a developer clone and push without holding any credentials of their own. - [Secrets](https://docs.citrix.com/en-us/securspaces/manage/resources/secrets.html): Secret management allows developers to securely store sensitive data such as passwords, keys, and tokens, in a protected environment with access controls capabilities. - [Data buckets](https://docs.citrix.com/en-us/securspaces/manage/resources/data-buckets.html): A **Data Bucket** is used for general, unstructured storage of data online. - [Mount points](https://docs.citrix.com/en-us/securspaces/manage/resources/mount-points.html): A **Mount Point** connects external file-based storage directly to a workspace file system. - [Connected HTTP services](https://docs.citrix.com/en-us/securspaces/manage/resources/connected-http-services.html): **Connected HTTP Services** consist of services used for the implementation of software applications. - [Connected SSH services](https://docs.citrix.com/en-us/securspaces/manage/resources/connected-ssh-services.html): **Connected SSH Services** consist of services used for the implementation of software applications. - [Choose between data buckets and mount points](https://docs.citrix.com/en-us/securspaces/manage/resources/data-sharing-options.html): Citrix SecurSpaces™ provides two mechanisms for making external data available inside workspaces: **Data Buckets** and **Mount Points**. - [Enable outbound SSH](https://docs.citrix.com/en-us/securspaces/manage/security/enable-outbound-ssh.html): By default the SecurSpaces proxy service blocks outbound SSH connections from workspaces. - [SecurSpaces Flex workspace templates](https://docs.citrix.com/en-us/securspaces/manage/flex/workspace-templates.html): This article describes workspace templates in Citrix SecurSpaces™ Flex: what they are, how they work, and how to create and manage them. ## Deploy - [Deploy](https://docs.citrix.com/en-us/securspaces/deploy/): This section is for the team standing SecurSpaces up on their own infrastructure. - [Deploy to a cluster](https://docs.citrix.com/en-us/securspaces/deploy/kubernetes/): Citrix SecurSpaces™ runs on any Kubernetes-compatible cluster, including OpenShift. - [Amazon EKS](https://docs.citrix.com/en-us/securspaces/deploy/kubernetes/aws-eks.html): This page prepares the AWS infrastructure Citrix SecurSpaces™ needs: a Kubernetes cluster to run on, a container registry to pull images from, and a MongoDB database to store platform state. - [Azure AKS](https://docs.citrix.com/en-us/securspaces/deploy/kubernetes/azure-aks.html): This page prepares the Azure infrastructure Citrix SecurSpaces™ needs: a Kubernetes cluster to run on, a container registry to pull images from, and a MongoDB database to store platform state. - [Google GKE](https://docs.citrix.com/en-us/securspaces/deploy/kubernetes/google-gke.html): This page prepares the Google Cloud infrastructure Citrix SecurSpaces™ needs: a Kubernetes cluster to run on, a container registry to pull images from, and a MongoDB database to store platform state. - [Red Hat OpenShift](https://docs.citrix.com/en-us/securspaces/deploy/kubernetes/openshift.html): The Citrix SecurSpaces™ platform provides a secure and productive cloud development environment that can be deployed on public, private clouds, and self-hosted servers. - [Nutanix Kubernetes Platform](https://docs.citrix.com/en-us/securspaces/deploy/kubernetes/nutanix.html): Citrix SecurSpaces™ runs on the Nutanix Kubernetes Platform (NKP). - [Install with the Strong Installer CLI](https://docs.citrix.com/en-us/securspaces/deploy/install.html): The Strong Installer CLI (`sds-cli`) helps you install, upgrade, and manage Citrix SecurSpaces™ deployments. - [Ingress](https://docs.citrix.com/en-us/securspaces/deploy/ingress/): Every Citrix SecurSpaces™ deployment needs an ingress controller in front of it. - [NetScaler CPX](https://docs.citrix.com/en-us/securspaces/deploy/ingress/netscaler.html): NetScaler CPX is the recommended ingress controller for Citrix SecurSpaces™, and the only one the SecurSpaces Helm chart deploys for you. - [NGINX](https://docs.citrix.com/en-us/securspaces/deploy/ingress/nginx.html): These values apply to the **ingress-nginx** controller. - [SSH TCP forwarding with NGINX](https://docs.citrix.com/en-us/securspaces/deploy/ingress/ssh-tcp-forwarding.html): This guide describes how to configure the SecurSpaces platform to enable SSH access to Workspaces. - [External database](https://docs.citrix.com/en-us/securspaces/deploy/external-database.html): You can configure SecurSpaces to authenticate to an external MongoDB deployment with X.509 certificates instead of username and password credentials. - [External proxy](https://docs.citrix.com/en-us/securspaces/deploy/external-proxy.html): Many enterprise environments require all outbound HTTP/HTTPS traffic to flow through a corporate proxy — for egress filtering, TLS inspection, or compliance logging. - [Multiple regions](https://docs.citrix.com/en-us/securspaces/deploy/multi-region.html): This guide describes how to deploy Citrix SecurSpaces™ across multiple Kubernetes clusters or regions. - [GPU-enabled workspaces on AKS](https://docs.citrix.com/en-us/securspaces/deploy/gpu-workspaces-on-aks.html): This guide explains how to enable and validate GPU-enabled Citrix SecurSpaces™ workspaces on an Azure Kubernetes Service (AKS) cluster using NVIDIA GPUs. - [Upgrade](https://docs.citrix.com/en-us/securspaces/deploy/upgrade.html): This article describes how to upgrade the SecurSpaces platform using the official installer. ## Administer - [Administer](https://docs.citrix.com/en-us/securspaces/administer/): This section is for **platform administrators** running Citrix SecurSpaces™ for the whole organization. - [System configuration](https://docs.citrix.com/en-us/securspaces/administer/system-configuration.html): **System Configuration** is where you manage Citrix SecurSpaces™ at the platform level. - [Terraform provider](https://docs.citrix.com/en-us/securspaces/administer/terraform-provider.html): Citrix SecurSpaces™ publishes a Terraform provider so that platform configuration can be managed as code rather than through the console. - [Run AI coding agents in workspaces](https://docs.citrix.com/en-us/securspaces/administer/ai-agents.html): Developers increasingly run AI coding agents that edit files, execute commands, install packages, and call external services on their behalf. - [Identity and access](https://docs.citrix.com/en-us/securspaces/administer/identity/): There are five ways users can log in to the platform: - [Identity providers](https://docs.citrix.com/en-us/securspaces/administer/identity/providers.html): Let your users sign in with accounts they already have, and keep your user list in sync automatically. - [Platform roles](https://docs.citrix.com/en-us/securspaces/administer/identity/platform-roles.html): Most access in Citrix SecurSpaces™ is granted through project roles, which apply inside a single project. - [Google OAuth](https://docs.citrix.com/en-us/securspaces/administer/identity/google-oauth.html): To create an OAuth Client to use Google as an Identity Provider, follow these steps to obtain the OAuth Client ID and Secret required in the platform configuration: - [Microsoft Entra](https://docs.citrix.com/en-us/securspaces/administer/identity/microsoft-entra.html): The platform supports integration with Azure Active Directory for logging in with your Microsoft Azure account. - [OpenID Connect](https://docs.citrix.com/en-us/securspaces/administer/identity/openid-connect.html): This platform supports integration with OpenID Connect for logging in. - [SAML](https://docs.citrix.com/en-us/securspaces/administer/identity/saml.html): Citrix SecurSpaces™ acts as a SAML 2.0 service provider. - [SCIM](https://docs.citrix.com/en-us/securspaces/administer/identity/scim.html): The Citrix SecurSpaces™ platform adheres to the System for Cross-domain Identity Management (SCIM) 2.0 specification. - [User access control](https://docs.citrix.com/en-us/securspaces/administer/identity/user-access-control.html): **User Access Control** decides two things at platform level: which identity provider authenticates a given user, and what any user is permitted to do regardless of their role. - [Code repositories](https://docs.citrix.com/en-us/securspaces/administer/code-repositories/): Before a project owner can import a repository, the Git provider has to be connected at platform level. - [GitHub](https://docs.citrix.com/en-us/securspaces/administer/code-repositories/github.html): Follow these steps to create an OAuth App in GitHub to connect it to the platform: - [GitLab](https://docs.citrix.com/en-us/securspaces/administer/code-repositories/gitlab.html): Follow these steps to create an OAuth App in GitLab to connect it to the platform: - [Bitbucket](https://docs.citrix.com/en-us/securspaces/administer/code-repositories/bitbucket.html): Follow these steps to create an OAuth App in Bitbucket Cloud to connect it to the platform: - [Azure DevOps](https://docs.citrix.com/en-us/securspaces/administer/code-repositories/azure-devops.html): Follow these steps to create an OAuth App in Azure DevOps to connect it to the platform. - [Integrations](https://docs.citrix.com/en-us/securspaces/administer/integrations/): Connect Citrix SecurSpaces™ to the outside tools your teams rely on, from code repositories and third-party apps to storage and Citrix DaaS™. - [HashiCorp Vault as secret manager](https://docs.citrix.com/en-us/securspaces/administer/integrations/secret-manager.html): You can use **HashiCorp Vault** to store all platform secrets instead of encrypting them in MongoDB. - [JFrog](https://docs.citrix.com/en-us/securspaces/administer/integrations/jfrog.html): You can follow these steps to connect your JFrog instance and the Citrix SecurSpaces™ platform. - [AI Gateway](https://docs.citrix.com/en-us/securspaces/administer/integrations/ai-gateway.html): You can route selected AI service traffic from Citrix SecurSpaces™ workspaces through an internal AI Gateway by configuring Helm values. - [Publish JetBrains Gateway](https://docs.citrix.com/en-us/securspaces/administer/integrations/publish-jetbrains-gateway.html): This guide describes how to publish JetBrains IntelliJ Gateway as a virtual application in Citrix DaaS. - [Backstage plugin](https://docs.citrix.com/en-us/securspaces/administer/integrations/backstage.html): Integrate Citrix SecurSpaces™ Workspaces into your Backstage developer portal to direcly manage secure Workspaces. - [Citrix DaaS](https://docs.citrix.com/en-us/securspaces/administer/integrations/citrix-daas.html): The Citrix DaaS Integration connects Citrix SecurSpaces™ with Citrix DaaS and Citrix Workspace. - [Registry access](https://docs.citrix.com/en-us/securspaces/administer/platform-resources/registry-access.html): Two separate settings control how Citrix SecurSpaces™ deals with container registries: one restricts where workspace images may come **from**, the other sets where images built on the platform are stored. - [IDE versions](https://docs.citrix.com/en-us/securspaces/administer/platform-resources/ide-versions.html): The **VSCode Versions** resource page manages the IDE versions available to workspaces. - [Image caching](https://docs.citrix.com/en-us/securspaces/administer/platform-resources/image-caching.html): Pulling a workspace image is usually the largest single cost when a workspace starts. - [Mount point storage](https://docs.citrix.com/en-us/securspaces/administer/storage/mount-point-storage.html): The **Mount Point Storage** section allows platform administrators to enable or disable Mount Point storage types for the platform. - [AWS mount points](https://docs.citrix.com/en-us/securspaces/administer/storage/aws-mount-points/): AWS Mount Points give a project shared, persistent, POSIX file storage that is mounted into its workspace pods at `/mnt/`. - [Prepare the AWS resources](https://docs.citrix.com/en-us/securspaces/administer/storage/aws-mount-points/prepare-aws.html): Citrix SecurSpaces™ does not create or validate any of the AWS resources on this page. - [Configure SecurSpaces](https://docs.citrix.com/en-us/securspaces/administer/storage/aws-mount-points/configure-securspaces.html): Complete the AWS preparation first. - [Author a PersistentVolume](https://docs.citrix.com/en-us/securspaces/administer/storage/aws-mount-points/author-a-persistentvolume.html): SecurSpaces never creates, changes, or cleans up these volumes. - [Troubleshoot AWS Mount Points](https://docs.citrix.com/en-us/securspaces/administer/storage/aws-mount-points/troubleshooting.html): Provisioning is subject to two fixed timeouts that cannot be changed: three minutes for the volume to bind, and five minutes for the overall provisioning call. - [General](https://docs.citrix.com/en-us/securspaces/administer/platform/general.html): This section covers fundamental platform-wide configurations. - [Workspace policy](https://docs.citrix.com/en-us/securspaces/administer/platform/workspace-policy.html): Workspace policy governs the workspaces created on the platform: what they may copy, how many a user may have, whether they can be reached over SSH, and what network traffic they may generate. - [Workspace lifecycle and idle detection](https://docs.citrix.com/en-us/securspaces/administer/platform/workspace-lifecycle.html): Citrix SecurSpaces™ 2026.4 introduces a hybrid idle detection engine that uses multiple signals to determine whether a workspace is truly idle before pausing it. - [Regions](https://docs.citrix.com/en-us/securspaces/administer/platform/regions.html): Run workspaces closer to your users. - [Custom actions](https://docs.citrix.com/en-us/securspaces/administer/platform/custom-actions.html): Custom Actions let you automate routine platform maintenance. - [Project labels](https://docs.citrix.com/en-us/securspaces/administer/platform/project-labels.html): Project Labels let you build a shared taxonomy that organizes every project on the platform. - [Onboarding emails](https://docs.citrix.com/en-us/securspaces/administer/platform/onboarding-emails.html): Citrix SecurSpaces™ sends automatic email notifications that help new users find their way onto the platform and into their projects. - [Email gateway](https://docs.citrix.com/en-us/securspaces/administer/platform/email-gateway.html): **Others** brings together a handful of platform-wide settings that don't fit the other areas. - [Information security policy](https://docs.citrix.com/en-us/securspaces/administer/platform/information-security-policy.html): The Information Security Policy lets you publish your organization's security policy document to everyone on the platform. - [Terms of service agreements](https://docs.citrix.com/en-us/securspaces/administer/platform/terms-of-service.html): Terms of Service Agreements let you present one or more documents that users must accept before they use the platform. - [Security settings](https://docs.citrix.com/en-us/securspaces/administer/security/): Configure critical security parameters for the entire platform. - [Licensing](https://docs.citrix.com/en-us/securspaces/administer/operations/licensing.html): Your license does two jobs: it lets your installation run, and it decides which features and limits apply. - [The SecurSpaces database](https://docs.citrix.com/en-us/securspaces/administer/operations/database/): Citrix SecurSpaces™ stores its platform configuration and state in a MongoDB database. - [Database sizing](https://docs.citrix.com/en-us/securspaces/administer/operations/database/sizing.html): Use these figures to size the Citrix SecurSpaces™ database for initial deployment, then verify against actual usage during your PoC and in production. - [Back up the database](https://docs.citrix.com/en-us/securspaces/administer/operations/database/back-up.html): Back up the Citrix SecurSpaces™ database before upgrades, migrations, and major configuration changes, and on a recurring schedule in production. - [Restore the database](https://docs.citrix.com/en-us/securspaces/administer/operations/database/restore.html): Restoring the Citrix SecurSpaces™ database requires a maintenance window: the platform must be quiesced so services do not write to the database mid-restore. - [Analytics](https://docs.citrix.com/en-us/securspaces/administer/operations/analytics.html): Use the System Analytics section to download detailed reports and logs for the Citrix SecurSpaces™ platform. - [Workspace resource usage](https://docs.citrix.com/en-us/securspaces/administer/operations/workspace-usage.html): Citrix SecurSpaces™ provides historical insights into workspace CPU and memory usage. - [Audit](https://docs.citrix.com/en-us/securspaces/administer/audit/): Requires the Security permission set to **Access**. - [SIEM integration](https://docs.citrix.com/en-us/securspaces/administer/audit/siem-integration.html): SecurSpaces can forward platform audit events to an external Security Information and Event Management (SIEM) system using the **Common Event Format (CEF)**. - [Insights](https://docs.citrix.com/en-us/securspaces/administer/insights/): The **Insights Page** displays information about the activity of the **Project**'s members, resource allocation and container process' metrics. - [Resource allocation](https://docs.citrix.com/en-us/securspaces/administer/insights/resource-allocation.html): Requires the Metrics permission set to **Access Project**. - [Container process metrics](https://docs.citrix.com/en-us/securspaces/administer/insights/container-process-metrics.html): The section **Container Process** displays time metrics registered using the platform Command Line Interface (CLI) **strongcli** available in developers workspaces. ## Security and compliance - [Security and compliance](https://docs.citrix.com/en-us/securspaces/security/): This section is written for security reviewers, whether you are assessing SecurSpaces before adoption or answering questions about a deployment you already run. - [Control catalogue](https://docs.citrix.com/en-us/securspaces/security/control-catalogue.html): This document provides an overview of the security controls available in Citrix SecurSpaces™. - [Trust boundaries](https://docs.citrix.com/en-us/securspaces/security/trust-boundaries.html): Where a Citrix SecurSpaces™ deployment separates one level of trust from another, what enforces each separation, and which side of it you own. - [How the SecurSpaces proxy service works](https://docs.citrix.com/en-us/securspaces/security/proxy-service.html): Most of the security claims in this documentation resolve to one component. - [Layered controls with the Citrix platform](https://docs.citrix.com/en-us/securspaces/security/layered-controls.html): SecurSpaces enforces its own controls on the development environment. - [Data flows](https://docs.citrix.com/en-us/securspaces/security/data-flows.html): This document provides a security-focused overview of the Citrix SecurSpaces™ architecture and the main data flows between core components and external dependencies. - [Network policies](https://docs.citrix.com/en-us/securspaces/security/network-policies/): Network policies control the outbound network traffic that workspaces are allowed to generate. - [Create a network policy](https://docs.citrix.com/en-us/securspaces/security/network-policies/create-a-policy.html): You create and edit policies from a **Workspace settings > Network policy** page at the scope you manage: platform, organization, or project. - [Assign and enforce a policy](https://docs.citrix.com/en-us/securspaces/security/network-policies/assign-and-enforce.html): Creating a policy does not change any workspace on its own. - [Monitor and troubleshoot](https://docs.citrix.com/en-us/securspaces/security/network-policies/monitor-and-troubleshoot.html): Every network policy behavior feeds the **Audit** dashboard, which is your primary tool for understanding and fixing policy effects. - [SecurSpaces Flex security](https://docs.citrix.com/en-us/securspaces/security/flex/): This article describes the security architecture, shared responsibility model, data handling practices, and compliance posture of Citrix SecurSpaces™ Flex. - [Network connections](https://docs.citrix.com/en-us/securspaces/security/flex/network-connections.html): This article describes how Citrix SecurSpaces™ Flex workspaces connect to customer-owned systems, the available connectivity options, and what each option enables. ## Reference - [Reference](https://docs.citrix.com/en-us/securspaces/reference/): Look-up material: exact names, values, and limits. - [Audit event catalog](https://docs.citrix.com/en-us/securspaces/reference/audit-events.html): The tables below offers a quick reference to events monitored in real time on the Citrix SecurSpaces™ platform. - [Container image requirements](https://docs.citrix.com/en-us/securspaces/reference/container-image-requirements.html): Every container image used for a Citrix SecurSpaces™ workspace must meet the requirements on this page. - [Cryptography](https://docs.citrix.com/en-us/securspaces/reference/cryptography.html): The cryptographic algorithms Citrix SecurSpaces™ uses, and where each one applies. - [Mount point limits and behavior](https://docs.citrix.com/en-us/securspaces/reference/mount-point-limits.html): EFS and S3 Files are elastic. - [Network destinations](https://docs.citrix.com/en-us/securspaces/reference/network-destinations.html): The external addresses a Citrix SecurSpaces™ deployment must reach, for firewall rules and air-gapped planning. - [Network policy fields](https://docs.citrix.com/en-us/securspaces/reference/network-policy-fields.html): The fields available in the expert-mode YAML editor for a Citrix SecurSpaces™ network policy. - [Ports and protocols](https://docs.citrix.com/en-us/securspaces/reference/ports-and-protocols.html): The network ports that a Citrix SecurSpaces™ deployment exposes, for firewall rules and network security review. - [Sizing](https://docs.citrix.com/en-us/securspaces/reference/sizing.html): How much infrastructure a Citrix SecurSpaces™ deployment needs, and what drives it. - [REST API](https://docs.citrix.com/en-us/securspaces/reference/api.html): The Citrix SecurSpaces™ REST API exposes the platform's resources for automation: workspaces, projects, organizations, resources, users, and reporting. - [SDS CLI](https://docs.citrix.com/en-us/securspaces/reference/sds-cli.html): `sds-cli` installs, upgrades, and manages Citrix SecurSpaces™ deployments. - [Supported IDEs](https://docs.citrix.com/en-us/securspaces/reference/supported-ides.html): Which editors work with Citrix SecurSpaces™, and how each one connects. - [System requirements](https://docs.citrix.com/en-us/securspaces/reference/system-requirements.html): What a Citrix SecurSpaces™ deployment needs from your infrastructure. ## Release notes - [Release notes](https://docs.citrix.com/en-us/securspaces/release-notes/) - [What's new](https://docs.citrix.com/en-us/securspaces/release-notes/whats-new.html): Updates continuously enhance your Citrix SecurSpaces™ experience. - [Fixed issues](https://docs.citrix.com/en-us/securspaces/release-notes/fixed-issues.html) - [What's new in SecurSpaces Flex](https://docs.citrix.com/en-us/securspaces/release-notes/flex.html): This article summarizes new features, improvements, and fixes for Citrix SecurSpaces™ Flex. - [Document history](https://docs.citrix.com/en-us/securspaces/release-notes/document-history.html): The following table describes important changes to the Citrix SecurSpaces™ product documentation.