Charles Anderson: Yes sir
Andy Whiteside: You've been you've been dying to be on these for years, I'm sure.
Charles Anderson: Yeah, been looking forward to it for sure.
Andy Whiteside: Yeah. Well welcome. on the Citrix side, we're lucky enough to have TK, the TK. Tarkan K. Tarkan, you have to tell me with the last name, but I guess we're not talking about Tom Krause, we're talking about the original T K. Tarkan, give us give us your background and where where you've been at Citrix.
Tarkan Kocoglu: Sure. I mean I am a longtime Citrite, I would say like over 20 years, mostly in the end user computing side, left Citrix at some point, which was like in 21, explored a few startups, but came across secure spaces, what will be topic today. So I found it interesting and joined actually the team to support them with everything in the Americas with customers and partners.
Andy Whiteside: So Tarkan, I'm gonna put you on the spot here. I think you're gonna be easily prepared to answer this. What's what's the number one thing that brought you back?
Tarkan Kocoglu: The number one thing actually was the technology I'm dealing with. It is a very interesting area because I think it's an untapped opportunity for Citrix from a developer perspective, even though you know like we did it a lot from a VDI side. But at the same time, there is a lot of cutting-edge technology happening in this space around AI. And the two kind of convinced me, plus the Citrix DNA, I think was a no-brainer.
Andy Whiteside: Yeah. Yeah, you referred to it as a citrite a minute ago. I know if everybody listening knows what that means, but a citrite means you either work or have worked at Citrix. It's a it's a special community, especially of those OG guys or people that have been around a long time. It's it's been a special place to be around. And you know what makes it special? People, 100% always the case. But the technology has always been super cool. Do you do you I'm sorry to go on a tangent here, but it's just what I do. and a lot of our listeners will associate with this. Tarkan you remember the very first time you saw a a Citrix hosted app show up on a screen t seamlessly, in all the ideas that ran through your head as to how applicable that was?
Tarkan Kocoglu: There was windframe. That's where it hooked me up. I I try to understand a concept of okay, why is this not running on my machine and remotely? And that impressed me.
Andy Whiteside: You you know what's cool about that, all the things you thought at that moment are still very relevant. Just just as
Tarkan Kocoglu: Yeah. That
Andy Whiteside: relevant as ever. And there's a lot of browser-based apps. There's a lot of needs for a desktop, and we do a ton of desktops. Everybody does and should in the Citrix world, but it's as
Mathew Varghese: Okay.
Andy Whiteside: relevant as ever. also we have Samesh with us. Samesh is our ATS for the channel and XenTegra specifically. Samesh, welcome. Samesh is speechless. he's on mute.
Somesh Naidu: Absorption. Thank you. I was speaking on mute. thanks, thanks Andy. I mean it's always a pleasure to work with you guys and XenTegra is a very valued partner as well. I myself have been with Citrix for about fifteen years, so not as you know a a veteran as Tom and Matt. and and yourself as well. So you you guys have worked on Citrix for much longer than I have. But again, as you say, a fan of the technology. a lot of things that we do is quite unique. and And yeah, the goal is that customers should be you know aware of those things so that they can leverage all those benefits, right? So that's what I'm here for.
Andy Whiteside: Yeah. I love that you said technology and Tarkan said technology. What what customers don't necessarily appreciate enough is how much Citrix is investing into technology and we're gonna talk about that some here in a minute. But it's as true and as real as ever. And we do we spend a lot of time at XenTegra trying to that message across because it is very misconstrued in the industry. Mathew Varghese, how are you?
Mathew Varghese: I am good sir. Thank you for having me on the podcast again. I
Andy Whiteside: Yeah.
Mathew Varghese: I I I didn't think I'd make it.
Andy Whiteside: Did did I get the last name pronounced correctly this time?
Mathew Varghese: You did. I mean it's Mathew Varghese. ninety nine percent there. That's
Andy Whiteside: right, I'm getting closer. I'm getting closer. As long as I've known you, I've never really tried to practice your last name. And now I'm forcing myself too. So welcome. Mathew, Matthew's actually the reason why we have the topic we have today. Let me share my screen and we'll jump into that. So our our blog for today, which all we do on this podcast is we take a blog and we review it. And it's just a great way for us to get Citrix content with context out to people and they can listen to it while they're you know going to bed at night. Believe it or not, I've had people tell me they they they use some of our podcasts to put them to sleep. funny way to look at it, but I'm just glad they're listening. they can listen to it while driving to work, walking the dog, you name it, walking around the grocery store. We don't care as long as you listen to the content and get value out of it. But the podcast or the blog was released yesterday, and the title is Announcing Citrix Secure Spaces Flex. So Tarkan, I want you to explain the concept of Flex along the way, and then specifically this version of Flex, a different operating model for modern development needs. I'll just read a little bit here and then I'll take it to Tarkan. Modern development depends on distributed teams, external contributors, and fast access. I'm gonna add the word secure, fast access to the right tools. need to find a way to give developers and AI agents, interesting, secure, ready-to-use environments without adding infrastructure burden, endpoint risk, and unpredictable spin. Tarkan, what's the general idea of this blog?
Tarkan Kocoglu: So the general idea is, I mean, as we launched Flex before, more specifically around DAS and like a really flexible model actually for any organization to consume like DAS services based on persona, pretty much. Because as you know, like if I take the VDI analogy, I mean you pretty much have to plan for maybe peak usage in means of licensing. and then usually probably have like life sitting idle. So in the flex concept. I mean, you really define the persona. The persona means like, okay, is it a task worker, knowledge worker, maybe even a developer? And based on that, you have certain capacities, needs, like I mean, a VDI of specific size. Flex gives you like that flexibility to actually pay for what you actually use based on the persona and the resource that persona needs. So, in the context of today, Secure Spaces, this is the new addition to this licensing model. And what it does like, I mean, similar to like where Citrix kind of takes care of infrastructure infrastructure components in Citrix Cloud, we can do pretty much the same now with Secure Spaces, meaning we can take care and provide based on Azure your let's say modern development architecture, in this case, Kubernetes. Before I go into the details, let me explain maybe like what is even secure spaces. I think it's important to understand what it needs. So any organization has some sort As developers in-house, the larger the organization becomes, the more you see development happening in-house, could be like their own apps, legacy apps, but also as applications become more modern, like SASIFI, or like more developed on a Linux type of foundation. Because modern development is really Linux-heavy. So you may run on a Mac or on a Linux machine or even on a Windows machine, in this case, with the Windows sub. System for Linux, for example. What it entails is like you change development into this modern type. So coming back to Secure Spaces, Secure Spaces needs that type of foundation to actually control and govern the dev environment. in this case, a Kubernetes environment, a Docker environment. To answer your question on the flex side. We run into customers and I saw actually recently a customer who is very interested in actually solving the developer challenges they have, but they don't have a Kubernetes environment today, meaning they have to build it, maybe they have to they don't even have the skills for it. So with this model, Secure Space Flex, we can actually provide you that core infrastructure. you can build on top of that and actually move into a more flexible, modern way of not only consuming the services, but also building your developer landscape.
Andy Whiteside: Okay.
Mathew Varghese: Okay. So I I I have a question for Tarkan. Tarkan, I I know this is totally unscripted. I don't want to put you on the
Tarkan Kocoglu: Yeah.
Mathew Varghese: spot. I I do
Andy Whiteside: But here it comes.
Mathew Varghese: I I do a fair amount of development myself and I think watching the Secure Spaces demos just b blew me away. I I've always thought about development more in the traditional way where you have this monolithic apps and you've got these huge code repositories and stuff like that. But as you just mentioned, modern application development is very different, right? Modern apps is almost orchestrating the entire dev e you know lifecycle. So essentially what you're saying is you can have a containerized developer environment that contains everything that a developer needs, right? Right from the source code, your programming environment, your credentials, your your secrets, all of that. And it can all be orchestrated by Kubernetes. Right? So that that's essentially what you're saying.
Tarkan Kocoglu: Correct.
Mathew Varghese: But but what I found magical was the fact that y you could, and correct me if I'm wrong, and that's why I don't want to put you on the spot. What I d what I discovered is the the app the the the the the the the development manager or whoever it is who owns the project could go create the environment by specifying everything that the developer needs it could be dependencies like you know libraries and runtimes and everything hit a button get a url and publish that url and when the developer then goes and clicks on the url they they get into this developer workspace Which in which for a Citrix user is similar to a Citrix workspace, right? Except that this is a developer workspace, you get your IDE and everything in that workspace, you hit on say VS Code, opens up, your code is ready, you do whatever, you know, commit, push to GitHub, and you're good to go. So
Tarkan Kocoglu: Correct.
Mathew Varghese: so is my assumption correct that it's the containerized environment that a manager can then publish as a link. into GitHub as well.
Tarkan Kocoglu: That is great. You did a good marketing summary of the value.
Andy Whiteside: Because I I think for our listeners and just for me, like it I think we need to translate this. Which I think would be easy to do, and to what we've done historically using Citrix as the as really the enabler of these developers, whether they were contractors or internal staff, but this in-house development. I think we've historically used Citrix, DAS, if you will, virtual desktops, like Mathew was alluding to, to solve this problem. But it came with challenges that this thing now fixes. For example, lighter IT burden, so in other words, you don't have to have all that infrastructure in place. a great user experience no matter where they're sitting and predicting. predictable amount of money associated with it. So we're not relying on you know bandwidth constraints or something from someone maybe developing in in a remote area, let's say someone developing for a US company out of India, for example. And little to no, let's just say no, endpoint risk, similar to what we had before, but even more predictable endpoint risk goes away.
Tarkan Kocoglu: Correct. Let me touch on those three, maybe, to just gonna start on that. So on the IT burden, I mean you're 100% right. Typically and what we see today, again, like modern development is kinda happening for the last two, three years intense intensely. It got got amplified by whole, let's say, AI usage to even develop code. But not every organization is quite there yet. So where the IT burden comes in, it's like I mean typically, let's say a developer environment looks like okay, either it's running locally on a laptop or PC. The challenges there are usually I have to procure the hardware. Try to kind of find hardware if like CPU RAM pricing goes up. It takes weeks to kind of get maybe the device to a developer. And then once it's at the developer, if you look into con let's say security. Code can sit on the device as well, and I think nothing's worse if IP leaks out through like local endpoints that are not controlled. Secondly, is the the experience for a developer, for example, on a laptop will vary and they may have to set spend time on like setting up their environment. And ideally, if you have developers, you want them to be productive right away because that's their core value. But you don't want them to spend on configuration, setting it up, and then assume like to continue on. The example Matt mentioned if the project is over, they probably have to wipe it and start from scratch. So it's just time they lose on productivity side. On the VDI side, is the burden is really as you install these toolings on in a VDI, I mean you definitely have to upgrade that VDI spec from a memory. CPU usage and even probably storage. On top of that, like if they start compiling code, it will require more resources. So meaning do you plan that VDI for like these high peak moments and then the rest sits idle? So, and I mentioned before on the modern development side, you have so-called like you can run Docker in a VDI, you can run Windows subsystem for Linux, which is pretty much a nested Linux in a in a Windows 11 machine, for example. All of that is just creates a lot of IT nightmare. I'm not downplaying VDI, it does a good job, it serves well, but I ran personally across like many organizations who are hitting, let's say, a limit of like an Azure D8 instance and consider it upgrading to D16. Which doubles the cost. So,
Andy Whiteside: Very expensive.
Tarkan Kocoglu: from an IT burden perspective, manageability, there's a cost aspect, and then also even security, because for example, in all these subsystems, certain security tooling can't even see what's happening, meaning it creates a blind spot. So the combination of let's say a VDI and secure spaces. finds that IT operational let's say efficiency like maybe you can downgrade the VDI to be just a landing VM for any type of developer coming in because a company may choose VDI as the only entry point in the organization. But you kind of offload the compute or and the security to secure spaces which is running in the back end on the Kubernetes cluster. That's kind of the IT burden you manage. The VDI team kind of or it's the EOC team still continues to manage these VDIs. but you pretty much enable the developer space to become more of let's say they get control about what they do within the given let's say confinements of like security and governance. That would be the IT burden side.
Andy Whiteside: I'm I'm gonna double down actually on this security issue here, because here's what I've seen historically. We would let developers come in through a Citrix type approach of VDI, virtual desktop infrastructure. And not only would we let them come in, but we would then have to give them a persistent, not a non-persistent reboots back to a gold image, but a persistent machine. And more than likely we'd have to give them admin rights, a double whammy if we're trying to, you know, have a security posture. It's actually even worse historically, even though it was the answer more often than not. Just to get development done.
Tarkan Kocoglu: Correct. You're a hundred percent right. I mean that's the case. And then maybe on top of that, and again touch on Matthew's earlier point, developers work on projects. Like a project could be two weeks, it could be four weeks. So what happens after that to that VDI or that machine? You probably have to
Andy Whiteside: We don't.
Tarkan Kocoglu: decommission, recommission. So it's too a lot of dynamics that the developers have compared to a typical VDI user, for example. That kinda that's the IT burden I see.
Andy Whiteside: I bet in many cases those things just sit out there for months and months and months. Nobody knows what to do with them. And then finally somebody re realizes it's a problem and something happens.
Tarkan Kocoglu: Yeah, correct.
Andy Whiteside: Alright, let's let's move on to this next section. This is where I think it's gonna get even more interesting. You've had secure spaces for a while, but now there's a flex version, which is the way to pay for it and consume it differently. Which by the way, this is my promo for Citrix to say the following: Old Citrix wouldn't have been this flexible for their clients. New Citrix is. So every time I run into somebody saying that Citrix is just like Broadcom, I have to tell them, No, you're you're not, you're not right. They're very more flexible to to double down on the word flex than ever before. You just don't realize it, and that's when we have the conversation. but this next topic, I Announcing a new approach that is purpose built around these core pillars. Today, Citrix is announcing secure Citrix Secure Spaces Flex, a Citrix managed service. So going back to your comment a while ago, you don't have to build this thing yourself. A Citrix managed service for Citrix platform Flex. Tarkan, help us digest what this next section is trying to tell us.
Tarkan Kocoglu: So What it is, what I mentioned earlier on is like really that you take well let's say, assume you're an organization, you're not even on a let's say Kubernetes Docker type of environment, but you know you're developing in that modern development context, we can provide you that infrastructure. Or assume you don't want to manage secure spaces and maybe the underlying workspaces, then we can take care of that. Like it's similar to what you see in the CPX DAS space. Like I mean, we we have the control plane. if you use the flex model, you kind of consume the services from Citrix perspective, it means of the VMs. the same thing has been applied now to Secure space where let's say we will manage that Kubernetes cluster in the back on Azure, but also the workspaces. So in the flex model you have like today, I think three types of like sizings available that you can choose based on your developer needs, and then you pretty much consume that. but the management is still on your side meaning you have to kind of manage what's goes what goes into that image what do you what are the resources you have to map into it again as Mathew mentioned early on for in the context of a project so it's really we are the control plane and you consume the the the resources based on your needs for your developers
Andy Whiteside: So easier to consume, more predictable cost, and then the persona stuff that we've have been learning around DASFlex, that applies over here, but it's more developer personas this time.
Tarkan Kocoglu: Correct. Yeah.
Somesh Naidu: Yeah. Basically we've introduced a new persona developer worker for this particular service, right? So you can use the flex credits to now consume for this particular service.
Andy Whiteside: Yeah.
Tarkan Kocoglu: Correct.
Andy Whiteside: And and Samesh and Charles, if if you've got something you want to add, just chime in with it. We I've got a great group here. I just don't w I can't I can't round Robin the way I normally do. we've got a special guest with Tarkan on. We want to make sure we focus on him. But Samesh, absolutely thank you for chiming in. I will go to Mathew though, one time with that one. Mathew, anything that that you want to add to Tarkin's approach there?
Mathew Varghese: Yeah. Yeah, yeah. There are two things
Tarkan Kocoglu: Yeah.
Mathew Varghese: that get me excited or three. development, I mean developer stuff, data stuff, and networking. Those three things that get excited. so in this particular case, I I I love the point Tarkan made. You don't need an entire VM to support a developer. What you need is a highly disposable container. Because again What the developers need are at any given point in time, you know, the the run times, libraries, dependencies, you know, keys, secrets, all of that good stuff. They use it, they develop, they they push to GitHub, and probably, you know, you you you can you you can destroy that container and then come back to it later. you don't need a whole VM for it. would that be the right way to put it, Tarkan?
Tarkan Kocoglu: Yes, I mean you're a hundred percent right. I mean the container is probably more efficient because again You don't you don't have like a GUI in this case unless you kind of consider a Linux type of environment. But typically it's lightweight, it's more dynamic, it spins up in seconds and you can decommission and so on. So you really tap into the benefits of like that again, I have to say modern development, which is all about like that flexibility, and that's actually what developers want from an experience
Andy Whiteside: Yeah.
Tarkan Kocoglu: perspective.
Andy Whiteside: Hey, quick question for you guys. I'm putting my developer hat on like from twenty years ago, which should tell you I haven't done it in a while and I'm pretty old. how about like control of my own ability to snapshot that container and put it back if I need to? Is that fall in the hands of the developer here?
Tarkan Kocoglu: So you have options to kind of keep some persistence set up. Like I mean, yes, there's a template, which starts always with like with the default, but there's an aspect you can define. It it all d depends on like how you configure your environment for a specific project or workspace, but there's certain aspects you can maintain and save. They will be saved in a database or somewhere in let's say GitHub in the back.
Andy Whiteside: Okay, good. Good to know. next section here talks about operational management, reduce the infrastructure work. Tarkan, what's the goal of this section?
Tarkan Kocoglu: So the main goal is here again comes back to if you scroll down, you see like I mean there are certain workspace sizes based in this model, like light, medium, and heavy. And they're defined by like number of CPUs, the memory size, and the storage size. and then within that, I mean, you not only take that size, but you create your template, like where you define, okay, what should be in this image, like tooling, what libraries or maybe what secret keys do you need food to kind of do your work so templatizing and the template like of a workspace size gives you like that almost like setup that is easy to manage versus having like one off settings per developer that makes it really difficult to manage so they kind of navigate with that and then as you asked before once you kind of even look into the like what I what should I pertain as a setting maybe for a project on top of that gives you like really that developer experience and environment and simplifies the operational aspect of it.
Andy Whiteside: Yeah. Mathew, anything to add to that?
Mathew Varghese: I I don't have anything to add to that, but I I do have a question for you, Andy. I know you go you keep saying you're old, yeah, yeah, we all know you're not. question to you. I I know that we you know acquired strong networks a few years ago, you know, and and we've seen some traction with customers. What is your take on a technology like this from a North America perspective? You know, Strong Networks is a European company, founded there, we we brought the technology here. How how do you think customers can benefit from this? And and what kind of customers do you think will go adopt a technology like this?
Andy Whiteside: So the the simple answer is this is a technology that we need to have with every one of our clients that does in-house development, whether they do it through contractors or not, we need to have this conversation. interestingly the you should ask me that 'cause I'm sitting here thinking through it and have been for weeks now around how this technology works. It it potentially under undermines our use case historically for a lot of virtual desktops where we've made a lot of money providing virtual desktops to developers. but the truth of that is things get have to evolve, things have to get better. Overall it's going to reduce the cost and management for our clients. So it's a good thing. I guess one way to sum it up is you know good things don't last forever and selling a lot of VDI and servers to host that is going away. Kubernetes and technologies like that has impacted that already. and you know this is just enhancement that Citrix has has evolved with and bought into and and acquired another company to make their clients more get more value out of the Citrix product stack, which if it's good for the client, good for Citrix, then it's ultimately good for us.
Tarkan Kocoglu: I'll I'll add to that any. I mean it's a good question, and thanks for the insights as well. I think they are what I said at the very beginning, I wasn't even aware that there's so much opportunity out there. I think the ones we know, and I think that's where Strix navigates the most, like we are talking mostly to the end-user computing side of the business. Yes, they have developers on VDI as well, but I'm also Equally surprised how much is still locally being developed. Like, meaning I think there's that untapped opportunity that an organization didn't see as an opportunity to kind of move them to VDI because either it impacted their developer experience or it impacted maybe like offshoring in one way or another. So I think that's where I see. use cases you can onboard to the Citrix ice is it through VDI or not? the key is like you kind of keep them in the Citrix ecosystem and the platform really generates that overall value for an organization.
Andy Whiteside: Here's a quick tactical question
Mathew Varghese: Yeah.
Andy Whiteside: for you guys. Does this is this gonna enable me to develop for Linux and Mac and Windows all in the same system or is this just Windows based?
Tarkan Kocoglu: So, good question. So, basically, again, if I go back to modern development, modern development is really Linux-based. And if you look into like market data, it is above 80% today's development work is happening in some sort of a Linux environment. Is it on Windows via like the subsystem of for Linux? Is it on Windows with Docker? Is it on Mac somewhere running in like a cloud development environment in the in the in the cloud? The endpoint doesn't matter. I think we can serve all use cases from like are you coming from a browser, are you coming through like a VDI or even from a like VS Code locally installed? The key is really this technology helps you to move that compute to like a centralized location to really get the security and governance benefits. But to answer your question, it is heavily focused on this Linux development environment. Meaning if someone is using .NET, if someone is using Mac OS, iOS development environments, that's not the use case for secure spaces. Like that's that doesn't fit into this plugin. But I think what I see is like 70% of what I come across is definitely almost like a no-brainer for getting into secure spaces.
Charles Anderson: what kind of flexibility around the tool sets that you can actually deploy inside those Kubernetes workspaces? Is it all Linux based? Does it cover all aspects
Tarkan Kocoglu: Yeah.
Charles Anderson: of like those those specific tool sets?
Tarkan Kocoglu: So we support pretty much every again I have to go on a modern expression, like modern tooling, like I mean VS Code is the most prominent one. I mean we see that pretty much everywhere. but if I have to call out like other tools like JetBrains or anything that use kind of darker type of like container environment, you can use all of those all those tools. However, if there is a tool that is not like kind of support By default, I mean you have always ways of connecting to this environment via SSH. So there's a key you can connect security to the back end. Use like any tooling that you have today to use a container environment. So we have that flexibility.
Mathew Varghese: Yeah, in in in fact what I would say and and we should probably supply the link to the demo in in in this episode, it it gets really magical when you see how it is launched. So you you can launch it from workspace. is that right, Tarkan? You can go to Workspace, Citrix workspace and and you'll see this published right next to your Citrix desktop. And
Tarkan Kocoglu: So yeah, yeah, go
Mathew Varghese: right?
Tarkan Kocoglu: ahead.
Mathew Varghese: And and and once you enter it. you will see all the tools that are available. So if you think about it from a developer perspective, and Tarkan keeps talking about the modern about developing modern apps. So developing modern apps is all about having an IDE at the top and then having a whole bunch of things under it. So it goes to your you know your libraries, your runtimes and everything. so if you're doing OS specific app development, then probably this is not for you, but that's not where 80 to 90% of the market is, right? So if you go take Any modern application, you know, whether it's a banking application or a booking application, whatever, they are all modern apps. They run on containers in the cloud. Right. And for that, this is this is ideal. A couple of other things that I found amazing about this technology. Two years ago, when we acquired strong networks, the first is the security aspect of it. And Tarkan, maybe you know more about it than I do, but the security in secure spaces is very similar to what Citrix users are used to like clipboard control is something that is available natively in secure spaces. then we all use you know secrets and ways to encrypt you know data going in and out of a container I I think secure spaces and I might be misrepresenting this and Tarkan maybe you should talk about it a little bit is about how secure spaces secures the ingress and egress of data you know in a developer environment. Tarkan, over to you.
Tarkan Kocoglu: Fair point. So on the security side, obviously like at the front end, especially if you have like a Chrome Enterprise Premium, kind of like some type of secure browser, and the combination of like secure spaces with DLP gives you a lot of control of like what actually a developer can do or not. the easiest example in demos is always like to show like I'm trying to kind of copy a secret key or an API key that is not supposed to be copied. And our system will detect that automatically. Either you block it, or if you just monitor it, it will audit and lock it in the in the record so you can feed it into a sim system to for like an overall tracking. So that's the front end. On the back end, I think that's where the bigger magic happens, especially these days. Again, if I go back to from a VDI or even local device perspective, you don't want that. Code leaks out. You don't want secrets sitting on the device locally. You don't want API keys there. You don't want like certain libraries being copied locally. So SecureSpace comes with this so-called secure proxy, which is pretty much like that. one thing that these workspaces use to communicate to the backend to the to the containers where let's say the the keys sit where the libraries are connected meaning in case of a workspace being hijacked by a a hacker or something like that There is nothing sitting in there. And kind of goes back to on the early points you had on the blog where it says like zero trust. So there's nothing locally left. Like is it on the VDI, is it on a local laptop, or even in your browser session? There's nothing locally left because every secret sits pretty much on a secure proxy, which sits in a secured environment behind load balancer, firewalls and so on. So it it is the security comes into the game there to really provide let's say The best developer experience because We don't want to change the developer experience because they want to work fast, they want to work with their tooling they like, but at the same time, you want to ensure it's kind of contained because it's corporate IP, you want to ensure that no one kind of gets into the environment, you want to ensure that no one steals data. So that's what's happening in the back from a secure proxy perspective. And then obviously you can kind of level this all up into the whole platform story, like for example, the Netscale AI gateway, if you're using AI. There are unique ways of let's say not only tracking token usage but also who's communicating what with what at with the endpoints. So lots of flexibility there, but the control or let's say strong networks was really built around secure and governance and I think that's the value we bring in into let's say any type of developer environment.
Andy Whiteside: Yeah. I I do think I love something you just did. You just tied security and and user experience together, which is my one of my favorite things to talk about because that's all we do in IT. I don't care what your job is in IT, you're getting users access to the the apps to run the business and you're doing it securely. That's what Citrix has done forever. And this is just a continuation of that, just a different way to solve it and more of a modern way to solve it. that that takes us into the next section here. Great user experience, you know, match the workspace to the work. user experience problems for developers. has always been around. Citrix has always been a great way to solve that, but you still can't help their bandwidth challenges. You can't help their misconfigured endpoint. You can't help you know, some things they do to break their own desktop. And in this case you're simplifying a lot of those things to make those common complaints go away for the developers. Is that a fair way
Tarkan Kocoglu: Yeah.
Andy Whiteside: to say it?
Tarkan Kocoglu: Yeah. So I mean, as you said, I think it's always a balancing act in my opinion. to have user experience and security. I think they don't like each other because
Andy Whiteside: Yeah.
Tarkan Kocoglu: you want to have experience, but
Mathew Varghese: Right.
Tarkan Kocoglu: also you want to have a security. And again, in this specific use case with developers, obviously they need some you mentioned earlier, Andy, like they need more admin permissions just kind of get to certain things done. So meaning IT has to give in. Or I give you another example like I ran into a customer who wants to use Windows subsystem for Lin for Linux on their Windows 11 BDIs, but InfoSec has to approve it because it comes with certain security guidelines. So point is like finding that balance is key, and I think Secure Spaces strikes that balance really well because from what I saw personally and not having a heavy let's say developer background, but you can still work the way a developer wants to work. And there are plenty of examples, like is it through a browser? you know, developers mostly probably type fast in terminalizations, encoding, whatever. Then latency becomes a key user experience issue. Like, I mean, depending on where, for example, where your BDI sits, if that's the choice of an organization to kind of give you an entry point. I heard it many times that I mean, obviously, developers don't like the latency. Like they type in and it delays the keys coming through. So, yes, we solved that, we optimized quite a bit, but it still seems to be sometimes an issue. So, again, points like how do I provide that best user experience based on how the developer wants to work? And be productive because at the end of the day, that's what the organization wants. You have to be productive because they are paying you for kind of creating the code, but at the same time, you want to keep the security up. So Secure Spaces does in that regard really really well to find the balance between okay, here's the security aspect and here's the best user experience, and that's why to
Andy Whiteside: Yeah, Mathew.
Tarkan Kocoglu: close up, I think fits into that overall Citrix value proposition, and because that's what we did since we are here. Like, I mean, it's all about the
Andy Whiteside: Well
Tarkan Kocoglu: Yeah.
Andy Whiteside: that's anybody any citrite, I'm gonna go back to the term citrite, knows that's our job is to help the the user experience side of the house get along with the security side of the house while making users productive, happy, and secure. It is it is you know, when somebody gets that, they get Citrix. When they fight you on one side or the other of that, they don't get Citrix They don't understand. Mathew,
Mathew Varghese: Yeah.
Andy Whiteside: thoughts on that?
Mathew Varghese: No, one one hundred percent agree with you. In fact, that's a great insight. I honestly being a citrite, I hadn't I hadn't honestly thought that way, but you're one hundred percent correct, Andy.
Andy Whiteside: yeah, lots lots of years having those conversations. And so okay, so we were talking to the end user team just now when we had that section of the blog we were talking about. Okay, now we gotta put on our let's go talk to the CISO side. Here we go. This next security keep the control boundary clear. Go ahead, Tarkan
Tarkan Kocoglu: Yeah, I I mean security, I think in the context of anything you do either remotely in the cloud or these days. I mean it it's everywhere and I think it became it is a board topic and if I bring it down specific to this discussion on the developer side, I think there were plenty of cases this year alone on breaches just from like GitHub repository here on or there. So it is a concern. And I think that to to really Let's say see the value of even the secure space in this case. I mean, the security side is a big discussion. And again, from our conversations, there's no customer conversation without even the security team being involved because they have to clear this too. And once we are in front of a security team and we kind of talk about the solution, they they see the value. And it's actually a door-opening conversation because it just kind of continues because it shows them, wow, it's kind of centralized, contained. And I think we didn't touch on this enough before because we are talking about the developer use case. But one reason why you see secure spaces being secure spaces, because initially it was secure developer spaces, is Over the last I would say six months and again AI taking so much let's say almost like mainstream in the developer space as well because they're coding with it, we see more and more use case even for let's say sandboxing AI, like agenti AI, like customers who consider actually deploying their own AI like LLM, Cloud, you name them, many of them. But they want to contain it. So they while they want to encourage their developers or even knowledge workers to use AI because especially if you look into specific industries like fine and like FSIs, there's a huge effort going on. Like I mean they all have their some sort of their own AIs, either for their customers or for themselves. But it has to be contained because AI can break out. I think we heard about that over the last weeks as well. So that's another value now coming into the mix. Hence the name change to be secure spaces because it's not just developers. We see also AI, for example, as a as a use case coming up more and more, where let's say this solution can play. And then to round up on the security, so security, the zero trust, like nothing on the local machine. Again, almost like door opening conversation just because that's what security wants and because you still keep the user experience at the same time alive.
Andy Whiteside: Yeah. Mathew, anything to add to that part?
Mathew Varghese: I'm I'm glad you brought that up. I was going to ask that question earlier, Tarkan. So thanks for talking about agents. That's an excellent point. So secure spaces is for both developers and developer agents and it's a way to keep those agents secure and prevent them from going rogue. so thank you, Tarkan, for for addressing that.
Andy Whiteside: Yeah, just a quick note. mean, we talked about in-user experience, talk security, just Citrix in general. Forget about this. This is like doubling down the concept, especially around developers. I I met with a financial firm last week for lunch and they brought another guy and I'm like, great. So who is this guy? this is our CISO. And when the in-user compute team brings the CISO to lunch, you're like, okay, this is a team effort. I love it. And that's exactly where, you know, where this is at. We don't we don't want to be look you know fighting each other, we want to be cohesively talking about how to deliver, and that's that's when you know you're working with organization that gets it. All right. So we've talked it, we've had our we've had our in-user compute director hat conversation on, we've had our CISO conversation hat on. Now we've got to go talk to the CFO, the guy with the money. Karkin, where does this help people understand the what where does this get better from a financial perspective?
Tarkan Kocoglu: So I mean cloud you can spend a fortune and especially add the AI piece to it. I think it there's like multiple aspects that kinda fit into the pred predictable spent here. Not only just from let's say the flex license, but also even I think on the customer side. from a secure services secure spaces flex perspective, because since you kinda have like these l light, medium, heavy templates you can choose from. you kind of went through your persona exercise. it's much more predictable in means of like the consumption because I mean over time I mean we will look into like okay what's being used, kind of map those personas and then you figure out okay this is the consumption model for that. And I think that's the predictable spent around that. In means of and maybe not specifically here but as part of maybe platform flex in if if I add let's say Now the Netscape AI gateway to this, or even with secure spaces and the capabilities of let's say feeding what we see as a data into let's say a tool like a dashboard like Grafana as an example. We can give you like the insights into not only let's say what's being used, how it's being used, but in the context of AI, even okay, what user is using which models, how much do they consume, and then put even some caps because For example, if you have a let's say monthly budget agreed on AI spend, you don't want one user, let's say, using the opus model on cloud side and eats up all the tokens for the rest of the team. Like, I mean, like there has to be some control. So the predictable spend here is not only, I think, from a our licensing perspective, for this specific use case of developers, but at the same time if you look into the broader platform story, then you have more let's say tooling that gives you more control and actually more predictable let's say spending which obviously in the context of FinOps the CFO will like
Andy Whiteside: Yeah. I I listen to a couple of podcasts every morning while I'm getting ready and token the AI token out of control spending was a topic on both of them. this combating that has to be something that the financial side of IT needs to better understand.
Tarkan Kocoglu: Yeah. I mean again If you it's it's doesn't matter which you use which user to probably deal with. Like I mean if if I stay on the secure space side, I mean you assume you gave your developers three templates to choose from. I'm sure that they will always choose the biggest templates because hey it has more CPUs, more memory. Same with like if you give almost like a blank check to hey, use AI, they will probably use it all up. until like you have to put some guard rates around it. So I think yes, encourage But at the same time there has to be some sort of control, especially maybe like does like do certain things leave, let's say, the containment and so on. So I think that's that allows you the spending control as well.
Andy Whiteside: I mean at a minimum you need to be able to monitor it and then step in and control it if it if it gets out of control,
Tarkan Kocoglu: Yeah. Correct.
Andy Whiteside: which it will. It it definitely seems to. Mathew, topic any anything you'll add on the the cost, the predictable cost topic we just covered.
Mathew Varghese: Yeah. I I think Tarkan did a great job. flex equals predictable predictable cost. I think that would be the key message here.
Somesh Naidu: Yeah, I do want to add, I mean yeah, a flex is so when you talk about flex you'll understand more about the predictable spend, right? But I do want to touch upon a separate point again from a Citrix point of view. We have been committed and our intent, right? A lot of people have questions around the Citrix intent, what Citrix going to do in terms of and the messaging that we have been consistently delivering is we are committed, heavily committed to simplifying our solutions, delivery of our solutions and adding value to our offerings. And time and time again we have done that. So we have our own existing license offerings, right? But every time we acquire a new technology, like Unicorn is an example, Secure Developer Spaces is an example, we add that retrospectively back to our offerings. Customer does not have to do anything extra. So I want to keep emphasizing that fact that we are we just don't talk the talk, we do walk the talk. Every time we acquire new technology innovations, we include that in our existing offerings, right? That's not a small thing, and we need to convey that to the customer the value that they get from our offerings, right? And so that's on that side. While I slight question to Tarkan as well is we've kind of comprehensively addressed the security and the operational efficiency aspect of it in terms of saving cost and so on and so forth. But I did hear Tarkan's initial note where he also alluded to the fact that not only we are saving costs in terms of administrative overheads and infrastructure, but also in terms of time to deliver deliver deliver value, right? that using secure developer spaces enables you to quickly deploy environments to your So is that accurate, Tarkan?
Tarkan Kocoglu: Yes, that is correct. I mean we have a few customers who went through the exercise to actually put a cost factor behind like downtime, meaning like updating this and that. It it can be significant cost if you let's say look into a few thousand developers, for example. It adds up.
Andy Whiteside: you know at the end of the day, security, user access, user experience. It always comes down to money. And if you're saving money here, then it's it it should be something that every, and I'll use the word every customer that uses Citrix strategically for some portion of your population should take a look at this, especially if you're currently using it for developers, because this is a fantastic way to make it more secure, better experience, and lower the cost, that total cost of ownership that Citrix has always been blamed for, but wasn't necessarily directly responsible for. It's all that other stuff you need to make those Citrix workloads run. Tarkan, if you could kind of take us home here with this this last last section, the title of its Modernized Modernization Without The Cutover Risk. What is that trying to tell us?
Tarkan Kocoglu: So b basically I mean again like I think there's many companies in in some sort of transformation across the like organization itself, but also like if I take it to the developer context, they they try to kind of keep up. we touched on that earlier on, like I mean container Linux modern development it's time to value and things are happening fast it's not like that one app I have to develop and wait six months till it's done it's happening weekly daily or by the hour I think we see that in our industry quite a bit where things happening however transformation takes time and modernization is key like I mean many many customers we talk to they kind of are in this stage we don't want to just kind of almost like cut the cord and make A hard cut, so with this offering, they can take small steps like in pilot stages. Meaning, maybe there's one developer group, for example, who is actually at the point where like they are maybe not happy with what they're using today, it's slow. it's maybe like even I'm not kidding, like they may be the customer who has like a developer sitting with eight laptops because it's eight different projects they have to work so. That is not ideal from an experience perspective. That's not ideal from a security perspective. And then even a nightmare from an IT side. So taking small steps with maybe those low-hanging fruit type of use cases. So really start modernization and take the first steps towards like this type of environment and then kind of move over. So I think that kind of gives you that flexibility without heavily investing initially, maybe into your own, let's say, Kubernetes clusters infrastructure. And so on. So that's kind of where we can help to kind of make those small steps and then grow from there.
Andy Whiteside: I I love what you just talked about and it i it kinda flashed on my head and I thought about it for a I like, you he's probably not that wrong. There's probably some really stupid things going on out there where people literally have multiple physical PCs to be doing development on. I mean, those obviously aren't historically good Citrix customers 'cause we we how to fix that and have for a long time, but I bet that is happening.
Tarkan Kocoglu: Yes, it does.
Andy Whiteside: Yeah. Yeah. Tarkan, I appreciate you jumping on, Mathew. I appreciate you bringing the topic. that's great timing.
Tarkan Kocoglu: Yeah.
Andy Whiteside: Hopefully I didn't lose you guys. But that's great. Great. Thank you for having for jumping on, Mathew. Thanks for bringing the topic. Samesh, thank you as always for being part of what you do to help us. And we look forward to the next podcast.
Tarkan Kocoglu: Same. Thank you so much.
Somesh Naidu: Thank you.