{"docs":[{"id":32,"title":"Kasm Workspaces 1.19: Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production","description":"Kubernetes deployment in Kasm Workspaces is now Generally Available. That means standardized backends, production-ready Helm charts, and Helm-based RDP Gateway configuration - all shipping as a supported, first-class deployment path. ","heroImage":{"id":62,"alt":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production ","caption":null,"author":6,"updatedAt":"2026-06-15T13:10:59.802Z","createdAt":"2026-06-15T13:10:56.200Z","url":"/api/media/file/Kasm%20Workspaces%201.19_%20Kubernetes%20Goes%20GA%2C%20Zero-Trust%20Egress%2C%20and%20a%20Release%20Built%20for%20Production%20(1).png","thumbnailURL":"/api/media/file/Kasm%20Workspaces%201.19_%20Kubernetes%20Goes%20GA%2C%20Zero-Trust%20Egress%2C%20and%20a%20Release%20Built%20for%20Production%20(1)-300x214.png","filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1).png","mimeType":"image/png","filesize":1303253,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":57112,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-300x214.png"},"square":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":205155,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-500x500.png"},"small":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":191426,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-600x429.png"},"medium":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":383263,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-900x643.png"},"large":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":853058,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1400x1000.png"},"xlarge":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":1394011,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1920x1372.png"},"og":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":527643,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1200x630.png"}}},"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The gap between “interesting technology” and “production-ready infrastructure” is real, and it takes deliberate engineering to close it. Kasm Workspaces 1.19 is a release that closes several of those gaps at once - moving Kubernetes support from preview to Generally Available, hardening the networking layer with a native OpenZiti egress provider, and delivering a set of platform improvements that make Kasm Workspaces meaningfully easier to operate at scale.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This is not a release full of shiny features for the demo. It is a release built for teams who are running Kasm Workspaces in production and need the platform to grow with them.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kubernetes Is Now Generally Available","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For teams that have been watching Kasm’s Kubernetes support from a distance, 1.19 is the moment to look again.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kubernetes deployment in Kasm Workspaces is now Generally Available. That means standardized backends, production-ready Helm charts, and Helm-based RDP Gateway configuration - all shipping as a supported, first-class deployment path. If your organization already runs workloads on Kubernetes, you now have a clean, declarative way to run Kasm Workspaces alongside them.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The practical implications go beyond just “it works now.” Helm-based deployment means your Kasm Workspaces configuration lives in version control. It means your infrastructure team can review workspace platform changes the same way they review application deployments - as code, in a pull request, with a traceable history. That is a different operational posture than a wizard-driven install, and it matters for compliance-focused environments.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Zero-Trust Egress with OpenZiti","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Network access control is one of the more underappreciated dimensions of a workspace platform. You can isolate the session itself beautifully and still create exposure through permissive egress.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces 1.19 adds a native OpenZiti egress provider, giving administrators the ability to route workspace traffic through a software-defined zero-trust network fabric rather than relying on traditional VPN or firewall rules. OpenZiti connections are mutually authenticated, encrypted by default, and scoped to specific services - not the broad network access that VPNs typically grant.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For security teams that have been working toward a zero-trust architecture, this is a meaningful integration. It brings the egress layer into the same policy-driven model that governs the session itself.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Self-Service Diagnostics: Less Time Fighting the Platform","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"One of the quieter but consistently impactful investments in any platform is making it easier to understand what is happening when something goes wrong.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Version 1.19 introduces a self-service diagnostics and metrics system covering metrics collection and export, system health checks, and a support bundle generator. Administrators can now pull structured diagnostic data without needing to escalate to a support ticket or dig through logs manually. For teams running Kasm Workspaces as part of a larger observability stack, the metrics export feeds directly into existing monitoring pipelines.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This is the kind of work that does not generate excitement in a feature announcement but meaningfully reduces operational friction over time.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Configuration as Code, Done Properly","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces 1.19 delivers a substantial refresh to configuration import and export. The improvements include table-level selection so you can export exactly what you need, UUID tokenization to make configs portable across environments, a sanitize option to strip environment-specific values, additive imports that merge rather than overwrite, and preset export modes for common scenarios.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Taken together, these changes make it practical to treat Kasm Workspaces configuration as a versioned artifact - something you can promote from development to staging to production, review in a diff tool, and roll back if needed. That is what “config as code” actually means in practice, and most platforms do not get there cleanly.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"GPU Workloads and AI/ML Use Cases: MiG Support","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Organizations running AI and ML workloads have increasingly needed a way to share expensive GPU resources across multiple container sessions without the overhead of full GPU passthrough. NVIDIA Multi-Instance GPU (MiG) partitioning solves that problem at the hardware level, but the platform delivering those sessions needs to understand MiG topology to take advantage of it.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces 1.19 adds native NVIDIA MiG support, so administrators can assign MiG slices to container sessions. This makes GPU-accelerated workspaces practical for larger teams where a single high-end card needs to serve multiple concurrent users - a common scenario in data science and ML engineering environments.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"vSphere: Faster Provisioning with Instant Clones and CloudInit","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For environments running Kasm Workspaces on VMware vSphere, 1.19 delivers two complementary improvements: Instant Clone support and CloudInit startup scripts.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Instant Clones reduce the time it takes to provision a new VM session by forking from a running parent VM rather than starting from a snapshot. CloudInit startup scripts let administrators run configuration logic at session start without baking everything into the base image. Together, these changes tighten the provisioning loop - meaning users spend less time waiting and infrastructure teams have more flexibility in how they manage session images.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Linux VMs via RDP, Windows Autoscale Fixes, and More","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Version 1.19 also includes Phase 1 of Linux VM support via RDP, expanding the range of session types Kasm Workspaces can deliver beyond containers and Windows machines. Windows autoscale deployments now correctly use the Kasm Server Name as the hostname, resolving a long-standing friction point for teams managing larger Windows fleets.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"On the infrastructure side: PostgreSQL has been updated from version 14 to a newer release, SQLAlchemy has been updated to 2.0, and Guacamole has been updated to version 1.6. Debian 13 (Trixie) is now a supported install and upgrade target.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The public exec_kasm API is available for teams that need programmatic control over session execution. Server Auto-Expiration lets administrators define a lifecycle for servers so they do not accumulate indefinitely. Rolling builds are now the default, improving release stability. The install script now supports copying existing SSL certificates at install time - a small thing that eliminates a common deployment friction point.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"An Honest Assessment","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"1.19 is a release that rewards teams who are already invested in the platform. The Kubernetes GA milestone, the OpenZiti integration, and the configuration import/export overhaul are all changes that compound over time - they make the platform more operable, more auditable, and more adaptable to the infrastructure practices that serious engineering organizations already follow.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For teams evaluating Kasm Workspaces for the first time, 1.19 is also a meaningful moment. The Kubernetes deployment path being Generally Available means you are not adopting an experimental feature - you are adopting a supported, Helm-driven deployment model that integrates with the toolchain you already use.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Get Started","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Upgrade instructions, Helm chart documentation, and the full 1.19 changelog are available at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6a2c3b123183f472e901c2e6","type":"link","fields":{"url":"https://kasm.com/downloads","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasm.com/downloads","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"If you are new to Kasm Workspaces, the documentation at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6a2c3b123183f472e901c2e7","type":"link","fields":{"url":"https://kasmweb.com/docs","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasmweb.com/docs","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" is the right starting point.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"About Kasm Workspaces","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Technologies delivers a modern platform for secure, containerized desktop and application access. Kasm Workspaces streams browsers, desktops, and applications directly to users through ephemeral, policy-controlled sessions - eliminating the cost, rigidity, and risk of traditional VDI. Built by a team with deep roots in federal cybersecurity and offensive/defensive operations, Kasm is used by organizations ranging from government agencies to Fortune 500 companies to deliver secure, scalable developer and end-user environments.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Learn more at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6a2c3b123183f472e901c2e9","type":"link","fields":{"url":"https://kasm.com","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasm.com","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0}],"direction":"ltr"}},"relatedPosts":[{"id":10,"title":"Introducing Kasm Workspaces v1.18: Secure Access, Simplified Scaling, and Enhanced Streaming ","description":"We are excited to announce Kasm Workspaces v1.18, a feature-rich release that makes it easier to deploy at scale, enhances the end-user experience, and introduces new enterprise features like Smartcard Passthrough. ","heroImage":18,"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Remote work and secure application delivery continue to evolve—and so does Kasm Workspaces. We are excited to announce Kasm Workspaces v1.18, a feature-rich release that makes it easier to deploy at scale, enhances the end-user experience, and introduces new enterprise features like Smartcard Passthrough. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces v1.18 builds on our mission to deliver high-performance digital workspaces that are simple to administer and great to use—whether you’re supporting a handful of users or thousands across multiple regions. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"quote","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"“Kasm 1.18 delivers on our commitment to improve the quality of life for users and administrators of the Kasm platform.” — Justin Travis, CEO and Co-Founder, Kasm Technologies ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"quote","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"“The 1.18 release marks a significant step forward in helping our customers adopt next-generation technology, regardless of their business needs.\" — Daniel Ben-Chitrit, Chief Product Officer, Kasm Technologies ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"For a quick walkthrough, check out the release video (YouTube): ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"id":"692490dcea6cc988b617467a","type":"link","fields":{"url":"https://youtu.be/ld80EFi2lfk","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://youtu.be/ld80EFi2lfk","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":"  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"To see Kasm streaming in action right in your browser, try the on-demand demo: ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"id":"692490dcea6cc988b617467b","type":"link","fields":{"url":"https://app.kasmweb.com/#/cast/kasmos","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://app.kasmweb.com/#/cast/kasmos","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":"  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"What’s New in v1.18 ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces v1.18 focuses on three big themes: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ol","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Enterprise-grade Secure Access ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Enhanced Streaming Performance ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Simplified Scaling and Infrastructure Management ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"number","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Smartcard Pass-through + New Desktop Service ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Many organizations require smartcards for secure authentication. With version 1.18, Kasm introduces Smartcard Pass-through, supported by a new Desktop Service client installer for Windows and macOS. This feature lets users authenticate into streamed environments using their smartcards without losing the familiar Kasm browser-based workflow. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Why it matters: ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"You can now incorporate smartcard-based security policies directly into Kasm Workspaces, making it easier to support regulated environments and zero-trust access models. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"KasmVNC v1.4: DPI Scaling and GPU Acceleration ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Streaming clarity and responsiveness are essential to the Kasm experience, and v1.18 introduces KasmVNC v1.4 with two significant improvements. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"DPI scaling for sharper, more readable sessions across high-resolution displays ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Chrome GPU acceleration for higher FPS and smoother interaction in supported environments ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Why it matters: ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"End users experience a significantly improved performance—especially on modern laptops, large monitors, and when using graphics-intensive web apps. Learn more about KasmVNC. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kubernetes Helm Chart Updates for Modern Deployments ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces continues to enhance its Kubernetes readiness. v1.18 introduces important Helm chart improvements, including: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Multi-zone deployment support ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Simplified upgrades ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Standalone database options ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Why it matters: ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"Teams running Kasm in Kubernetes environments gain more flexibility, smoother scaling options, and easier operational control across regions. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Scaling and Admin Features That Save Time ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Enterprise deployments require consistent, low-effort scaling. v1.18 introduces several enhancements focused on increasing admin efficiency. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Workspace Labels — apply controls across agents, pools, and zones ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Bulk Import — quickly add users and servers as your environment grows ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Agent Draining — gracefully offload workloads during maintenance windows ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Enhanced Server Enrollment — streamlined bulk deployment of Windows Servers ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"User Assignment — map users to dedicated server resources ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":6,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Container Logging Console Access — view workspace logs directly in the logging UI ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Why it matters: ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"These features lower manual effort and simplify managing large deployments without downtime. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"RDP Gateway and Infrastructure Enhancements ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"v1.18 modernizes RDP connectivity and improves platform infrastructure: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"RDP Gateway update to Apache Guacamole v1.5.5 ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"New workspace images including Debian Trixie, Fedora 41, Obsidian, and Cyberbro ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Vulkan GPU acceleration for Chromium-based browsers ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Redis chat depreciation (chat removed from session sharing) ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Security tightening, including removal, of file browsing from browser images ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":6,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Documentation migration to a new ecosystem at ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"autolink","fields":{"url":"https://docs.kasm.com","linkType":"custom"},"format":"","indent":0,"version":2,"children":[{"mode":"normal","text":"https://docs.kasm.com","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Why it matters: ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"You gain a more secure platform, more modern image options, and increased performance headroom for future workloads. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Built for Secure, Scalable Workspaces—Anywhere ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces is a sophisticated container streaming platform that allows users to securely access desktops, applications, and web services from any device using a browser. By isolating workloads in Docker containers, Kasm helps prevent data leaks and supports strong security measures without compromising usability. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Whether your organization needs secure browsing, app streaming, remote work environments, collaboration tool access, or education labs, Kasm Workspaces offers a flexible solution built for enterprise scale. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Get the Full Release Details ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Want a deep dive into every feature, improvement, and fix in v1.18? ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"Read the full release notes here: ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"692490dcea6cc988b617467c","type":"link","fields":{"url":"https://docs.kasm.com/docs/release_notes/1.18.0","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://docs.kasm.com/docs/release_notes/1.18.0","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":"  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Ready to Try v1.18? ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"If you’re already running Kasm Workspaces, upgrade to v1.18 to take advantage of smarter access, smoother streaming, and admin features designed for real-world scaling. ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"692490dcea6cc988b617467d","type":"link","fields":{"url":"https://kasm.com/downloads","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Install v1.18 here.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"If you’re new to Kasm, now’s a great time to see what secure, browser-based workspaces can do for your team. Start with the demo or contact us to talk through your use case. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"692490dcea6cc988b617467e","type":"link","fields":{"url":"https://kasm.com/get-started","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Get Started with Kasm Workspaces","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0}],"direction":"ltr"}},"categories":[33,34,35,36,37,38,39,40,41],"meta":{"image":null,"description":"We are excited to announce Kasm Workspaces v1.18, a feature-rich release that makes it easier to deploy at scale, enhances the end-user experience, and introduces new enterprise features like Smartcard Passthrough. "},"publishedAt":"2025-11-24T20:00:00.000Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"introducing-kasm-workspaces-v118-secure-access-simplified-scaling-and-enhanced-streaming"}],"categories":[{"id":41,"title":"Platform Updates","author":6,"slug":"platform-updates","slugLock":true,"updatedAt":"2025-12-29T21:24:20.149Z","createdAt":"2025-12-29T21:24:20.148Z"}],"meta":{"title":"Kasm Workspaces 1.19: Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production","image":{"id":62,"alt":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production ","caption":null,"author":6,"updatedAt":"2026-06-15T13:10:59.802Z","createdAt":"2026-06-15T13:10:56.200Z","url":"/api/media/file/Kasm%20Workspaces%201.19_%20Kubernetes%20Goes%20GA%2C%20Zero-Trust%20Egress%2C%20and%20a%20Release%20Built%20for%20Production%20(1).png","thumbnailURL":"/api/media/file/Kasm%20Workspaces%201.19_%20Kubernetes%20Goes%20GA%2C%20Zero-Trust%20Egress%2C%20and%20a%20Release%20Built%20for%20Production%20(1)-300x214.png","filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1).png","mimeType":"image/png","filesize":1303253,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":57112,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-300x214.png"},"square":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":205155,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-500x500.png"},"small":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":191426,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-600x429.png"},"medium":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":383263,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-900x643.png"},"large":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":853058,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1400x1000.png"},"xlarge":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":1394011,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1920x1372.png"},"og":{"url":"/api/media/file/Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":527643,"filename":"Kasm Workspaces 1.19_ Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production (1)-1200x630.png"}}},"description":"Kasm Workspaces 1.19 brings Kubernetes GA, OpenZiti zero-trust egress, NVIDIA MiG support, self-service diagnostics, and enterprise-ready scalability."},"publishedAt":"2026-06-15T06:00:00.000Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"kasm-workspaces-119-kubernetes-goes-ga-zero-trust-egress-and-a-release-built-for-production","slugLock":false,"updatedAt":"2026-06-15T13:11:11.972Z","createdAt":"2026-06-12T16:58:23.735Z","_status":"published"},{"id":31,"title":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale","description":"Kubernetes was designed to manage complex, distributed platform deployments declaratively. When Kasm’s management and control plane components are deployed via Helm into a Kubernetes cluster, the operational characteristics of the platform change fundamentally.","heroImage":{"id":63,"alt":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale ","caption":null,"author":6,"updatedAt":"2026-06-15T13:11:33.997Z","createdAt":"2026-06-15T13:11:32.128Z","url":"/api/media/file/Why%20Kubernetes%20Is%20the%20Right%20Foundation%20for%20Operating%20Kasm%20at%20Scale%20(1).jpg","thumbnailURL":"/api/media/file/Why%20Kubernetes%20Is%20the%20Right%20Foundation%20for%20Operating%20Kasm%20at%20Scale%20(1)-300x214.jpg","filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1).jpg","mimeType":"image/jpeg","filesize":144013,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-300x214.jpg","width":300,"height":214,"mimeType":"image/jpeg","filesize":7753,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-300x214.jpg"},"square":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-500x500.jpg","width":500,"height":500,"mimeType":"image/jpeg","filesize":21338,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-500x500.jpg"},"small":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-600x429.jpg","width":600,"height":429,"mimeType":"image/jpeg","filesize":23697,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-600x429.jpg"},"medium":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-900x643.jpg","width":900,"height":643,"mimeType":"image/jpeg","filesize":46298,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-900x643.jpg"},"large":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1400x1000.jpg","width":1400,"height":1000,"mimeType":"image/jpeg","filesize":87307,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1400x1000.jpg"},"xlarge":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1920x1372.jpg","width":1920,"height":1372,"mimeType":"image/jpeg","filesize":136231,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1920x1372.jpg"},"og":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1200x630.jpg","width":1200,"height":630,"mimeType":"image/jpeg","filesize":54489,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1200x630.jpg"}}},"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Most conversations about Kubernetes focus on application workloads — microservices, APIs, batch processing pipelines. The idea that Kubernetes should also be the operational home for your workspace delivery platform tends to generate a moment’s hesitation the first time you hear it.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"That hesitation is worth taking seriously. Then set it aside, because the operational model Kubernetes provides maps almost perfectly onto the day-2 management problems that make running workspace infrastructure at scale genuinely hard.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The Problem with Static Desktop Infrastructure","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Legacy desktop delivery infrastructure is built around permanence. Virtual machines are provisioned, configured, and then managed indefinitely. Patches are applied in place. Images drift. The gap between what your gold image looked like at provisioning time and what a user’s environment looks like six months later is filled with accumulated state — installed software, configuration changes, browser extensions, downloaded files, and credentials stored in ways that were never sanctioned.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This is not a criticism of the teams managing that infrastructure. It is a structural property of persistent desktop environments. The longer a desktop exists, the more it diverges from its intended state. And divergence creates risk.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"At scale, these problems multiply. A fleet of five hundred persistent VMs is five hundred independent state management problems. Rolling out an image update means coordinating reboots, managing user interruption windows, and handling the inevitable edge cases where the update interacts badly with accumulated local state. For security-sensitive environments — government agencies, financial services firms, healthcare organizations — the compliance overhead of auditing that kind of fleet is substantial.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces was designed around an ephemeral session model: sessions that are created from a known-good image, run for the duration of a user’s work, and are discarded completely. No accumulated state. No drift. Every session starts from the same baseline.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The operational challenge is managing the platform that delivers those sessions consistently, at scale, across environments. That is where Kubernetes enters the picture.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Why Kubernetes Changes the Game for Platform Operations","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kubernetes was designed to manage complex, distributed platform deployments declaratively. When Kasm’s management and control plane components are deployed via Helm into a Kubernetes cluster, the operational characteristics of the platform change fundamentally.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Declarative configuration.","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Kubernetes deployments are defined as code — Helm charts, values files, configuration exports stored in version control. The state of your Kasm deployment, including how it is configured and how it is connected to the rest of your infrastructure, is expressed in files that can be reviewed, versioned, and audited. For compliance-driven organizations, the ability to demonstrate that your infrastructure matches a documented, version-controlled specification is operationally significant.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Portability.","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Kubernetes runs on every major cloud provider and on-premises. An organization that deploys Kasm’s management layer on a self-hosted Kubernetes cluster today can migrate to a managed Kubernetes service later without rearchitecting the workspace platform. The Helm charts work. The configuration works. The operational knowledge transfers. Infrastructure decisions no longer lock the workspace platform in place.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Managed upgrade paths.","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Helm-managed deployments make upgrading Kasm a controlled, reversible process. Rolling updates reduce disruption. Failed updates can be rolled back without manual intervention. For organizations managing multiple Kasm environments, this matters: keeping deployments current becomes an operational routine, not a project.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"What Kasm Workspaces on Kubernetes Looks Like in Practice","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Deploying Kasm Workspaces on Kubernetes starts with the official Helm charts, which cover Kasm’s management and control plane components — the parts of the platform responsible for orchestrating sessions, managing users and policies, handling authentication, and exposing the administrative interface. A minimal evaluation install can be up and running in a cluster with a handful of commands. A production deployment is more involved, but the configuration lives in values files that are readable, diffable, and stored in version control.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Importantly, workspace sessions themselves — the secure browsers, virtual desktops, and streamed applications that users connect to — run on dedicated Kasm agent servers, not inside the Kubernetes cluster. The Kubernetes deployment manages Kasm’s control plane. The agent infrastructure that delivers sessions is provisioned and scaled separately, according to the organization’s capacity model. This is a meaningful architectural distinction: Kubernetes provides the operational foundation for managing the platform, while session delivery remains on agent infrastructure designed for that purpose.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The Configuration Import/Export system is a meaningful part of the operational story. The ability to export Kasm platform configuration — workspace types, access policies, image registries, network settings — as a portable, sanitized artifact means your Kasm configuration can live in the same repository as your Helm values files. Promoting a configuration from a staging environment to production becomes a controlled, reviewable process rather than a manual re-configuration exercise. Environment drift between staging and production, one of the most persistent sources of “it worked in staging” failures, becomes manageable.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For organizations connecting workspace sessions to internal services, Kasm supports configurable egress providers. The OpenZiti integration gives administrators the option to route session egress traffic through an existing OpenZiti-based zero-trust network — organizations that already run OpenZiti infrastructure can extend it to cover Kasm session connectivity without additional VPN configuration or broad network access grants. This is a complement to Kubernetes network policy, not a replacement for it: Kubernetes controls platform component communication inside the cluster; OpenZiti governs how workspace sessions reach internal services.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The Operational Case for Platform Teams","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Three operational questions tend to drive the adoption of Kubernetes-based Kasm deployments among platform engineering teams.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"How do we keep multiple Kasm environments consistent?","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Organizations running separate Kasm instances for different departments, regions, security classifications, or development stages face a consistency problem. Without a declarative, version-controlled deployment model, environments diverge. Helm-based deployment with shared charts and environment-specific values files makes consistency a structural property of the deployment model rather than a discipline that has to be enforced manually.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"How do we manage Kasm upgrades without disrupting operations?","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Rolling Kasm upgrades through Helm means upgrade operations are predictable, reversible, and integrated with the same change management process the team uses for everything else. There is no separate “Kasm upgrade procedure” that lives outside the standard operational workflow.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"How do we demonstrate infrastructure compliance?","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Regulated organizations need to show that their infrastructure matches a documented, authorized configuration. Helm charts in version control, GitOps deployment pipelines, and exportable Kasm configuration artifacts together provide a clear configuration audit trail — from the Kubernetes deployment specification down to the Kasm platform settings.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Where This Deployment Model Makes the Most Sense","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Enterprise deployments with multiple environments.","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Organizations running Kasm across multiple regions, data centers, or tenancy boundaries benefit most from a deployment model that enforces consistency at scale. Helm-based deployment with config-as-code practices makes managing a distributed Kasm fleet operationally tractable.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Government and classified environments.","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Agencies handling sensitive or classified data need workspace infrastructure that can demonstrate consistent configuration. Kubernetes-based deployments with Helm chart management and GitOps workflows provide an auditable configuration trail. Air-gapped Kubernetes clusters are supported for environments where the management plane must remain isolated. The zero-trust egress integration means workspace network access can be scoped tightly to authorized services.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Developer and engineering workspaces.","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Platform teams managing Kasm as developer workspace infrastructure benefit from treating it as a first-class platform service: versioned, monitored, upgraded through a pipeline, and configured alongside the rest of the organization’s infrastructure. Developer workspaces running through Kasm on Kubernetes are fully consistent, fully ephemeral — code and credentials stay inside the session, not on the endpoint — and operationally managed through the same tooling the platform team uses everywhere else.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Getting Started","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For teams evaluating a Kubernetes-based Kasm deployment, the documentation at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6a2c3e733183f472e901c2f3","type":"link","fields":{"url":"https://kasmweb.com/docs","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasmweb.com/docs","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" covers both single-node evaluation configurations and multi-zone production architectures. The Helm charts are the right starting point for understanding the deployment model.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The gap between “interesting technology” and “production infrastructure” closes when the operational model is sound. Kubernetes provides that model for managing Kasm at scale: declarative, portable, GitOps-compatible, and built for the day-2 operations that determine whether platform infrastructure is actually sustainable to run.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"About Kasm Workspaces","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Technologies delivers a modern platform for secure, containerized desktop and application access. Kasm Workspaces streams browsers, desktops, and applications directly to users through ephemeral, policy-controlled sessions — eliminating the cost, rigidity, and risk of traditional VDI. Built by a team with deep roots in federal cybersecurity and offensive/defensive operations, Kasm is used by organizations ranging from government agencies to Fortune 500 companies to deliver secure, scalable developer and end-user environments.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Learn more at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6a2c3e733183f472e901c2f5","type":"link","fields":{"url":"https://kasm.com","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasm.com","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0}],"direction":"ltr"}},"relatedPosts":[{"id":32,"title":"Kasm Workspaces 1.19: Kubernetes Goes GA, Zero-Trust Egress, and a Release Built for Production","description":"Kubernetes deployment in Kasm Workspaces is now Generally Available. That means standardized backends, production-ready Helm charts, and Helm-based RDP Gateway configuration - all shipping as a supported, first-class deployment path. ","heroImage":62,"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The gap between “interesting technology” and “production-ready infrastructure” is real, and it takes deliberate engineering to close it. Kasm Workspaces 1.19 is a release that closes several of those gaps at once - moving Kubernetes support from preview to Generally Available, hardening the networking layer with a native OpenZiti egress provider, and delivering a set of platform improvements that make Kasm Workspaces meaningfully easier to operate at scale.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This is not a release full of shiny features for the demo. It is a release built for teams who are running Kasm Workspaces in production and need the platform to grow with them.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kubernetes Is Now Generally Available","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For teams that have been watching Kasm’s Kubernetes support from a distance, 1.19 is the moment to look again.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kubernetes deployment in Kasm Workspaces is now Generally Available. That means standardized backends, production-ready Helm charts, and Helm-based RDP Gateway configuration - all shipping as a supported, first-class deployment path. If your organization already runs workloads on Kubernetes, you now have a clean, declarative way to run Kasm Workspaces alongside them.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The practical implications go beyond just “it works now.” Helm-based deployment means your Kasm Workspaces configuration lives in version control. It means your infrastructure team can review workspace platform changes the same way they review application deployments - as code, in a pull request, with a traceable history. That is a different operational posture than a wizard-driven install, and it matters for compliance-focused environments.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Zero-Trust Egress with OpenZiti","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Network access control is one of the more underappreciated dimensions of a workspace platform. You can isolate the session itself beautifully and still create exposure through permissive egress.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces 1.19 adds a native OpenZiti egress provider, giving administrators the ability to route workspace traffic through a software-defined zero-trust network fabric rather than relying on traditional VPN or firewall rules. OpenZiti connections are mutually authenticated, encrypted by default, and scoped to specific services - not the broad network access that VPNs typically grant.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For security teams that have been working toward a zero-trust architecture, this is a meaningful integration. It brings the egress layer into the same policy-driven model that governs the session itself.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Self-Service Diagnostics: Less Time Fighting the Platform","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"One of the quieter but consistently impactful investments in any platform is making it easier to understand what is happening when something goes wrong.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Version 1.19 introduces a self-service diagnostics and metrics system covering metrics collection and export, system health checks, and a support bundle generator. Administrators can now pull structured diagnostic data without needing to escalate to a support ticket or dig through logs manually. For teams running Kasm Workspaces as part of a larger observability stack, the metrics export feeds directly into existing monitoring pipelines.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This is the kind of work that does not generate excitement in a feature announcement but meaningfully reduces operational friction over time.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Configuration as Code, Done Properly","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces 1.19 delivers a substantial refresh to configuration import and export. The improvements include table-level selection so you can export exactly what you need, UUID tokenization to make configs portable across environments, a sanitize option to strip environment-specific values, additive imports that merge rather than overwrite, and preset export modes for common scenarios.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Taken together, these changes make it practical to treat Kasm Workspaces configuration as a versioned artifact - something you can promote from development to staging to production, review in a diff tool, and roll back if needed. That is what “config as code” actually means in practice, and most platforms do not get there cleanly.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"GPU Workloads and AI/ML Use Cases: MiG Support","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Organizations running AI and ML workloads have increasingly needed a way to share expensive GPU resources across multiple container sessions without the overhead of full GPU passthrough. NVIDIA Multi-Instance GPU (MiG) partitioning solves that problem at the hardware level, but the platform delivering those sessions needs to understand MiG topology to take advantage of it.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces 1.19 adds native NVIDIA MiG support, so administrators can assign MiG slices to container sessions. This makes GPU-accelerated workspaces practical for larger teams where a single high-end card needs to serve multiple concurrent users - a common scenario in data science and ML engineering environments.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"vSphere: Faster Provisioning with Instant Clones and CloudInit","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For environments running Kasm Workspaces on VMware vSphere, 1.19 delivers two complementary improvements: Instant Clone support and CloudInit startup scripts.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Instant Clones reduce the time it takes to provision a new VM session by forking from a running parent VM rather than starting from a snapshot. CloudInit startup scripts let administrators run configuration logic at session start without baking everything into the base image. Together, these changes tighten the provisioning loop - meaning users spend less time waiting and infrastructure teams have more flexibility in how they manage session images.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Linux VMs via RDP, Windows Autoscale Fixes, and More","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Version 1.19 also includes Phase 1 of Linux VM support via RDP, expanding the range of session types Kasm Workspaces can deliver beyond containers and Windows machines. Windows autoscale deployments now correctly use the Kasm Server Name as the hostname, resolving a long-standing friction point for teams managing larger Windows fleets.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"On the infrastructure side: PostgreSQL has been updated from version 14 to a newer release, SQLAlchemy has been updated to 2.0, and Guacamole has been updated to version 1.6. Debian 13 (Trixie) is now a supported install and upgrade target.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The public exec_kasm API is available for teams that need programmatic control over session execution. Server Auto-Expiration lets administrators define a lifecycle for servers so they do not accumulate indefinitely. Rolling builds are now the default, improving release stability. The install script now supports copying existing SSL certificates at install time - a small thing that eliminates a common deployment friction point.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"An Honest Assessment","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"1.19 is a release that rewards teams who are already invested in the platform. The Kubernetes GA milestone, the OpenZiti integration, and the configuration import/export overhaul are all changes that compound over time - they make the platform more operable, more auditable, and more adaptable to the infrastructure practices that serious engineering organizations already follow.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For teams evaluating Kasm Workspaces for the first time, 1.19 is also a meaningful moment. The Kubernetes deployment path being Generally Available means you are not adopting an experimental feature - you are adopting a supported, Helm-driven deployment model that integrates with the toolchain you already use.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Get Started","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Upgrade instructions, Helm chart documentation, and the full 1.19 changelog are available at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6a2c3b123183f472e901c2e6","type":"link","fields":{"url":"https://kasm.com/downloads","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasm.com/downloads","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"If you are new to Kasm Workspaces, the documentation at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6a2c3b123183f472e901c2e7","type":"link","fields":{"url":"https://kasmweb.com/docs","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasmweb.com/docs","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" is the right starting point.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"center","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"tag":"h2","type":"heading","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"About Kasm Workspaces","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Technologies delivers a modern platform for secure, containerized desktop and application access. Kasm Workspaces streams browsers, desktops, and applications directly to users through ephemeral, policy-controlled sessions - eliminating the cost, rigidity, and risk of traditional VDI. Built by a team with deep roots in federal cybersecurity and offensive/defensive operations, Kasm is used by organizations ranging from government agencies to Fortune 500 companies to deliver secure, scalable developer and end-user environments.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Learn more at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6a2c3b123183f472e901c2e9","type":"link","fields":{"url":"https://kasm.com","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasm.com","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0}],"direction":"ltr"}},"categories":[41],"meta":{"image":62,"description":"Kasm Workspaces 1.19 brings Kubernetes GA, OpenZiti zero-trust egress, NVIDIA MiG support, self-service diagnostics, and enterprise-ready scalability."},"publishedAt":"2026-06-15T06:00:00.000Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"kasm-workspaces-119-kubernetes-goes-ga-zero-trust-egress-and-a-release-built-for-production"}],"categories":[{"id":41,"title":"Platform Updates","author":6,"slug":"platform-updates","slugLock":true,"updatedAt":"2025-12-29T21:24:20.149Z","createdAt":"2025-12-29T21:24:20.148Z"}],"meta":{"title":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale","image":{"id":63,"alt":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale ","caption":null,"author":6,"updatedAt":"2026-06-15T13:11:33.997Z","createdAt":"2026-06-15T13:11:32.128Z","url":"/api/media/file/Why%20Kubernetes%20Is%20the%20Right%20Foundation%20for%20Operating%20Kasm%20at%20Scale%20(1).jpg","thumbnailURL":"/api/media/file/Why%20Kubernetes%20Is%20the%20Right%20Foundation%20for%20Operating%20Kasm%20at%20Scale%20(1)-300x214.jpg","filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1).jpg","mimeType":"image/jpeg","filesize":144013,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-300x214.jpg","width":300,"height":214,"mimeType":"image/jpeg","filesize":7753,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-300x214.jpg"},"square":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-500x500.jpg","width":500,"height":500,"mimeType":"image/jpeg","filesize":21338,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-500x500.jpg"},"small":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-600x429.jpg","width":600,"height":429,"mimeType":"image/jpeg","filesize":23697,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-600x429.jpg"},"medium":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-900x643.jpg","width":900,"height":643,"mimeType":"image/jpeg","filesize":46298,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-900x643.jpg"},"large":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1400x1000.jpg","width":1400,"height":1000,"mimeType":"image/jpeg","filesize":87307,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1400x1000.jpg"},"xlarge":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1920x1372.jpg","width":1920,"height":1372,"mimeType":"image/jpeg","filesize":136231,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1920x1372.jpg"},"og":{"url":"/api/media/file/Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1200x630.jpg","width":1200,"height":630,"mimeType":"image/jpeg","filesize":54489,"filename":"Why Kubernetes Is the Right Foundation for Operating Kasm at Scale (1)-1200x630.jpg"}}},"description":"Learn how Kubernetes helps platform teams scale, secure, and simplify Kasm operations with Helm, GitOps, and declarative infrastructure."},"publishedAt":"2026-06-15T02:44:15.835Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"why-kubernetes-is-the-right-foundation-for-operating-kasm-at-scale","slugLock":true,"updatedAt":"2026-07-08T02:29:59.635Z","createdAt":"2026-05-14T17:20:34.692Z","_status":"published"},{"id":29,"title":"Copy Fail (CVE-2026-31431), Container Escape, and the Case for Ephemeral Architecture","description":"Containerization changed how most organizations think about workload isolation. The mental model is intuitive: each container runs in its own space, with its own filesystem, its own network stack, its own identity. ","heroImage":{"id":61,"alt":null,"caption":null,"author":6,"updatedAt":"2026-05-04T17:43:49.596Z","createdAt":"2026-05-04T17:43:46.523Z","url":"/api/media/file/copy%20fail%20blog.png","thumbnailURL":"/api/media/file/copy%20fail%20blog-300x214.png","filename":"copy fail blog.png","mimeType":"image/png","filesize":4418438,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/copy fail blog-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":135003,"filename":"copy fail blog-300x214.png"},"square":{"url":"/api/media/file/copy fail blog-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":467172,"filename":"copy fail blog-500x500.png"},"small":{"url":"/api/media/file/copy fail blog-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":495987,"filename":"copy fail blog-600x429.png"},"medium":{"url":"/api/media/file/copy fail blog-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":1065488,"filename":"copy fail blog-900x643.png"},"large":{"url":"/api/media/file/copy fail blog-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2474749,"filename":"copy fail blog-1400x1000.png"},"xlarge":{"url":"/api/media/file/copy fail blog-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":4330960,"filename":"copy fail blog-1920x1372.png"},"og":{"url":"/api/media/file/copy fail blog-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1445765,"filename":"copy fail blog-1200x630.png"}}},"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The Trust Assumption Nobody Talks About","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Containerization changed how most organizations think about workload isolation. The mental model is intuitive: each container runs in its own space, with its own filesystem, its own network stack, its own identity. What happens inside one container stays inside one container.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"That model has a flaw, and Copy Fail (CVE-2026-31431) exposes it cleanly. The flaw is not in how containers are built. It is in what they share: the kernel.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Every container on a host runs on the same Linux kernel. That shared kernel manages memory, handles system calls, and - critically - maintains the page cache, the in-memory representation of files on disk. When a vulnerability allows an unprivileged process to write into that shared page cache, the container boundary becomes irrelevant. A write from one container is a write that every other container on that host can be affected by.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"That is what Copy Fail does. A 732-byte Python script, executable by any unprivileged local user, triggers a logic flaw in the kernel's cryptographic subsystem to corrupt a target file in the page cache - including setuid binaries - and obtain root. CISA added it to the Known Exploited Vulnerabilities catalog within days of disclosure. The vulnerability has been present in Linux kernels since 2017.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Why This Pattern Keeps Appearing","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Copy Fail is not an anomaly. It is an example of a class of vulnerability that surfaces regularly: a flaw at the OS layer that bypasses the isolation mechanisms built on top of it. The Linux kernel is an extraordinarily complex piece of software, maintained across decades, with subsystems interacting in ways that no individual reviewer sees in full. Logic bugs accumulate. Some stay dormant for years before someone finds the right combination of system calls to trigger them reliably.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The security tooling most organizations rely on - EDR, container scanning, image signing, SBOM verification - operates above the kernel. It catches problems in application code, in package dependencies, in runtime behavior. It does not catch a kernel logic flaw that lets any user rewrite arbitrary files in memory. That is a different layer, and it requires a different architectural response.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"How Kasm Workspaces Is Built for This","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces was designed around a specific premise: the endpoint and the underlying OS cannot be fully trusted. That premise shapes every architectural decision in the platform - and it turns out to be exactly the right frame for thinking about a vulnerability like Copy Fail.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The most important property is ephemerality. Every Kasm workspace is a container that is created on demand and destroyed when the session ends. There is no persistent filesystem, no stored credentials, no accumulated state for an attacker to return to. Gaining root inside a Kasm workspace during an active session means gaining root in a container that will not exist in an hour. The attacker's foothold evaporates with the session.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Persistence is what transforms a privilege escalation into a serious breach. Without it, the blast radius of an exploit like Copy Fail is bounded by the session lifetime. An attacker who exploits Copy Fail inside an ephemeral workspace gains root over nothing that persists.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The platform also manages seccomp policies centrally across workspace images. Blocking AF_ALG socket creation - the first step in the Copy Fail exploit chain - is a configuration that can be enforced at the image level, across every user session, without depending on individual users or developers to secure their own environments. That kind of centralized enforcement is not possible when workloads run on unmanaged endpoints.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"We run our own development environment on Kasm Workspaces, so this is not a theoretical architecture for our team - it is how we work every day. ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69f8d9fa014048249ab58900","type":"link","fields":{"url":"https://kasm.com/solutions/platform","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about the Kasm Workspaces platform.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The Right Question to Be Asking","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Every organization running Linux workloads should patch for Copy Fail. That is not optional. But patching is reactive, and kernel vulnerabilities are not going away. The more useful question is structural: when the next one surfaces, how much can an attacker actually accomplish before you respond?","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Ephemeral sessions, centrally managed images, no persistent endpoint state, and workloads that assume a hostile OS underneath - these properties do not prevent kernel vulnerabilities. They determine how much those vulnerabilities cost when they appear.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Copy Fail is a good test case for that question. For environments built on these principles, the answer is: not much.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"About Kasm Workspaces","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Technologies delivers a modern platform for secure, containerized desktop and application access. Kasm Workspaces streams browsers, desktops, and applications directly to users through ephemeral, policy-controlled sessions - eliminating the cost, rigidity, and risk of traditional VDI. Built by a team with deep roots in federal cybersecurity and offensive/defensive operations, Kasm is used by organizations ranging from government agencies to Fortune 500 companies to deliver secure, scalable developer and end-user environments.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Learn more about how Kasm Workspaces delivers secure, ephemeral environments for developer and end-user access at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69f8d959014048249ab588f9","type":"link","fields":{"url":"https://kasm.com","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasm.com","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"References","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"1. Wiz","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - \"Copy Fail: Universal Linux Local Privilege Escalation Vulnerability\"","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"id":"69f8d959014048249ab588fa","type":"link","fields":{"url":"https://www.wiz.io/blog/copyfail-cve-2026-31431-linux-privilege-escalation-vulnerability","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://www.wiz.io/blog/copyfail-cve-2026-31431-linux-privilege-escalation-vulnerability","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"2. The Hacker News","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - \"CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV\"","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"id":"69f8d959014048249ab588fb","type":"link","fields":{"url":"https://thehackernews.com/2026/05/cisa-adds-actively-exploited-linux-root.html","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://thehackernews.com/2026/05/cisa-adds-actively-exploited-linux-root.html","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"3. Microsoft Security Blog","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - \"CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments\"","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"id":"69f8d959014048249ab588fc","type":"link","fields":{"url":"https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"4. Help Net Security","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - \"Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431)\"","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"id":"69f8d959014048249ab588fd","type":"link","fields":{"url":"https://www.helpnetsecurity.com/2026/04/30/copyfail-linux-lpe-vulnerability-cve-2026-31431/","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://www.helpnetsecurity.com/2026/04/30/copyfail-linux-lpe-vulnerability-cve-2026-31431/","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"5. Xint","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - \"Copy Fail: 732 Bytes to Root on Every Major Linux Distribution\"","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"id":"69f8d959014048249ab588fe","type":"link","fields":{"url":"https://xint.io/blog/copy-fail-linux-distributions","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://xint.io/blog/copy-fail-linux-distributions","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"6. CERT-EU","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - \"High Vulnerability in the Linux Kernel (Copy Fail)\"","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"id":"69f8d959014048249ab588ff","type":"link","fields":{"url":"https://cert.europa.eu/publications/security-advisories/2026-005/","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://cert.europa.eu/publications/security-advisories/2026-005/","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0}],"direction":"ltr"}},"relatedPosts":[],"categories":[],"meta":{"title":"Copy Fail (CVE-2026-31431), Container Escape, and the Case for Ephemeral Architecture","image":{"id":61,"alt":null,"caption":null,"author":6,"updatedAt":"2026-05-04T17:43:49.596Z","createdAt":"2026-05-04T17:43:46.523Z","url":"/api/media/file/copy%20fail%20blog.png","thumbnailURL":"/api/media/file/copy%20fail%20blog-300x214.png","filename":"copy fail blog.png","mimeType":"image/png","filesize":4418438,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/copy fail blog-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":135003,"filename":"copy fail blog-300x214.png"},"square":{"url":"/api/media/file/copy fail blog-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":467172,"filename":"copy fail blog-500x500.png"},"small":{"url":"/api/media/file/copy fail blog-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":495987,"filename":"copy fail blog-600x429.png"},"medium":{"url":"/api/media/file/copy fail blog-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":1065488,"filename":"copy fail blog-900x643.png"},"large":{"url":"/api/media/file/copy fail blog-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2474749,"filename":"copy fail blog-1400x1000.png"},"xlarge":{"url":"/api/media/file/copy fail blog-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":4330960,"filename":"copy fail blog-1920x1372.png"},"og":{"url":"/api/media/file/copy fail blog-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1445765,"filename":"copy fail blog-1200x630.png"}}},"description":"Explore the “Copy Fail” Linux kernel vulnerability (CVE-2026-31431) and why container isolation isn’t enough—plus how Kasm Workspaces’ ephemeral architecture limits risk and reduces attack impact."},"publishedAt":"2026-05-04T17:44:03.456Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"copy-fail-cve-2026-31431-container-escape-and-the-case-for-ephemeral-architecture","slugLock":true,"updatedAt":"2026-05-04T17:44:03.458Z","createdAt":"2026-05-04T17:37:12.065Z","_status":"published"},{"id":28,"title":"EUC Isn’t VDI Anymore: What Changed at Nutanix .NEXT 2026 and What It Means for Modern Workspaces","description":"After spending time at Nutanix .NEXT 2026 and talking with folks like Jim Luna, Kevin Bacon, Marian, and others across the EUC community, one takeaway stood out: EUC has moved beyond legacy VDI architectures.","heroImage":{"id":60,"alt":null,"caption":null,"author":6,"updatedAt":"2026-05-04T17:31:22.925Z","createdAt":"2026-05-04T17:31:22.266Z","url":"/api/media/file/Kasm%20and%20Nutanix.png","thumbnailURL":"/api/media/file/Kasm%20and%20Nutanix-300x300.png","filename":"Kasm and Nutanix.png","mimeType":"image/png","filesize":111599,"width":602,"height":602,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Kasm and Nutanix-300x300.png","width":300,"height":300,"mimeType":"image/png","filesize":57089,"filename":"Kasm and Nutanix-300x300.png"},"square":{"url":"/api/media/file/Kasm and Nutanix-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":130586,"filename":"Kasm and Nutanix-500x500.png"},"small":{"url":"/api/media/file/Kasm and Nutanix-600x600.png","width":600,"height":600,"mimeType":"image/png","filesize":170814,"filename":"Kasm and Nutanix-600x600.png"},"medium":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"large":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"xlarge":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"og":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null}}},"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"What actually shifted at .NEXT—and why it matters","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"After spending time at Nutanix .NEXT 2026 and talking with folks like Jim Luna, Kevin Bacon, Marian, and others across the EUC community, one takeaway stood out:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"EUC has moved beyond legacy VDI architectures.","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Not incrementally—fundamentally.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The definition of end-user computing is expanding. We’re no longer designing just for human users, but for:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"AI agents","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Browser-based workspaces","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"AI-powered applications and workflows","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Isolated browsing environments","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"All tied together through ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"zero-trust access to data","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":", not flat network-based access.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"That’s a very different design point than what traditional VDI was built for.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"A shift in leadership—and architecture","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"One of the more important (and understated) themes at .NEXT was the direction Nutanix is taking.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For years, parts of the industry have focused more on profit models than architectural innovation—creating a bit of a gap.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Nutanix is stepping into that gap.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"By embracing open source and building a ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"heterogeneous execution environment","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":", they’re bringing together hyperscalers, hardware vendors, and ISVs—even traditional competitors—into a model that encourages interoperability and competition.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"And that matters.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Because competition drives innovation—and innovation ultimately drives cost efficiency.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Why NKP is more than “Kubernetes on Nutanix”","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This shift becomes more tangible when you look at NKP (Nutanix Kubernetes Platform).","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"NKP isn’t just Kubernetes packaged for Nutanix—it’s a ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69f8d8cd014048249ab588f6","type":"link","fields":{"url":"https://kasm.com/alliance-partnership/nutanix","linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"CNCF-certified platform","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1},{"mode":"normal","text":"designed for:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Portability across environments","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Interoperability between systems","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Consistency across cloud and on-prem","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"It brings together:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"GitOps workflows","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Centralized governance","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Integrated data services","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Support for both containers and virtual machines","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"But the bigger story is ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"standardization","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"CNCF is evolving into the foundation for how organizations think about not just Kubernetes—but ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"security, AI workloads, and cloud-native infrastructure as a whole","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Security is shifting to the center","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This evolution aligns closely with a broader move toward ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69f8d8f8014048249ab588f7","type":"link","fields":{"url":"https://kasm.com/integration-partnership/atx-defense","linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"CMMC-style security models","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Traditional EUC and VDI architectures were largely built with NIST-style perimeter thinking.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"What’s emerging now is different:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Centralized policy enforcement","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Secure-by-design environments","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Protection of controlled data at the core","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Support for secure supply chains","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"In this model, environments are:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Secured from the center—not the edge.","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"And when you build this way, BYOD shifts from being a liability to an advantage—reducing both cost and operational overhead.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Performance, scale, and the role of bare metal","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"NKP Metal is where this model becomes operationally real.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Running Kubernetes on bare metal has always made sense—especially for edge and AI workloads where GPU density matters—but it’s traditionally been difficult to manage.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"NKP Metal simplifies that.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"You get:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"A unified operating model","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Built-in automation and lifecycle management","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"First-class support for both containers and VMs","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This directly impacts two of the biggest EUC challenges:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Scale and performance—without excessive cost.","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"With technologies like KubeVirt, organizations can also run VMs inside Kubernetes—allowing modernization without full refactoring.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Multi-cloud, AI, and what comes next","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Nutanix is also expanding its multi-cloud approach with NC2 on AWS and Azure, running on bare-metal instances. This delivers:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Stronger performance SLAs","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Improved availability","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Greater flexibility across environments","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"At the same time, Nutanix AI (NAI) is tackling a growing challenge:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Not access to AI models—but how to ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"run and manage them efficiently","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Because AI isn’t just a model problem.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"It’s an infrastructure problem.","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Why this matters for Kasm Workspaces","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This is where the architecture shift directly connects to Kasm Workspaces.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm wasn’t built to replicate legacy VDI—it was built for this emerging model.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"id":"69f8d92f014048249ab588f8","type":"link","fields":{"url":"https://kasm.com/alliance-partnership/nutanix","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"As the first NKP-validated workspace control","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" plane, Kasm aligns directly with where EUC architecture is heading.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm enables:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kubernetes-based control planes","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Containerized application delivery","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Browser-based workspaces and secure browsing","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Autoscaling Windows workloads on AHV","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Deployment across hybrid and multi-cloud environments","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"All within a ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"security-first architecture","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" designed to increase cyber maturity—not compensate for gaps.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"A new model for workspaces","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"What’s emerging now are entirely new architectural patterns:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Isolated Browser Infrastructure (IBI)","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textFormat":1},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Secure Workspace Infrastructure (SWI)","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textFormat":1},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Enterprise Secure Browser Services","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textFormat":1}],"listType":"bullet","direction":"ltr","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"These aren’t just new terms—they reflect a shift in how work is delivered.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The workspace becomes the browser.","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"The user can be human—or an AI agent.","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"Policy enforcement remains consistent across both.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"And again:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Everything is secured from the center.","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"From months to hours","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"One of the most impactful changes is how quickly this can now be implemented.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"With Kasm available in the NKP Catalog, organizations can:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Deploy a control plane","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Integrate AHV autoscaling","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Launch agents and workloads","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Deliver secure apps, desktops, and browsers with DLP","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"In hours—not months.","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The cost of waiting","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"A theme that kept coming up in conversations at .NEXT was the cost of waiting.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Not just infrastructure cost—but the cost of staying in legacy VDI models while the rest of the ecosystem moves forward.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"A gap is forming between:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Organizations adopting CNCF-based EUC architectures","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Those maintaining traditional VDI stacks","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"That gap shows up in:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Cost","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Performance","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Security posture","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Speed of execution","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"What comes next","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"If you were at Nutanix .NEXT 2026, you likely felt it.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Something shifted—not just in the technology, but in how we think about EUC, security, and infrastructure overall.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The question now is:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"What are you going to build with it?","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Explore how Kasm fits into your EUC strategy: ","type":"text","style":"","detail":0,"format":1,"version":1},{"id":"69f2bd43b2df6bf004ddbeff","type":"link","fields":{"url":"https://kasm.com/solutions/platform","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://kasm.com/solutions/platform","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textFormat":1}],"direction":"ltr","textStyle":"","textFormat":1}],"direction":"ltr"}},"relatedPosts":[],"categories":[{"id":36,"title":"Remote Desktops & Applications ","author":6,"slug":"remote-desktops--applications-","slugLock":true,"updatedAt":"2025-12-29T21:22:27.098Z","createdAt":"2025-12-29T21:22:27.098Z"},{"id":37,"title":"Remote Workspaces","author":6,"slug":"remote-workspaces","slugLock":true,"updatedAt":"2025-12-29T21:22:49.448Z","createdAt":"2025-12-29T21:22:49.448Z"},{"id":43,"title":"Nutanix","author":6,"slug":"nutanix","slugLock":true,"updatedAt":"2026-04-30T02:28:17.818Z","createdAt":"2026-04-30T02:28:17.816Z"}],"meta":{"title":"EUC Isn’t VDI Anymore: What Changed at Nutanix .NEXT 2026 and What It Means for Modern Workspaces","image":{"id":60,"alt":null,"caption":null,"author":6,"updatedAt":"2026-05-04T17:31:22.925Z","createdAt":"2026-05-04T17:31:22.266Z","url":"/api/media/file/Kasm%20and%20Nutanix.png","thumbnailURL":"/api/media/file/Kasm%20and%20Nutanix-300x300.png","filename":"Kasm and Nutanix.png","mimeType":"image/png","filesize":111599,"width":602,"height":602,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Kasm and Nutanix-300x300.png","width":300,"height":300,"mimeType":"image/png","filesize":57089,"filename":"Kasm and Nutanix-300x300.png"},"square":{"url":"/api/media/file/Kasm and Nutanix-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":130586,"filename":"Kasm and Nutanix-500x500.png"},"small":{"url":"/api/media/file/Kasm and Nutanix-600x600.png","width":600,"height":600,"mimeType":"image/png","filesize":170814,"filename":"Kasm and Nutanix-600x600.png"},"medium":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"large":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"xlarge":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"og":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null}}},"description":"What changed at Nutanix .NEXT 2026? Explore how EUC is moving beyond legacy VDI toward cloud-native, zero trust, and containerized workspace architectures."},"publishedAt":"2026-04-30T02:36:42.942Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"euc-isnt-vdi-anymore-what-changed-at-nutanix-next-2026-and-what-it-means-for-modern-workspaces","slugLock":true,"updatedAt":"2026-05-04T17:37:08.063Z","createdAt":"2026-04-30T02:22:50.145Z","_status":"published"},{"id":27,"title":"Your Dev Environment Is Part of the Attack Surface. The Trivy Incident Proves It.","description":"The Trivy compromise, which unfolded over the past couple of weeks, is one of the clearest examples of this we've seen in the DevOps tooling space.","heroImage":{"id":52,"alt":null,"caption":null,"author":6,"updatedAt":"2026-04-07T19:41:16.417Z","createdAt":"2026-04-07T19:41:13.236Z","url":"/api/media/file/Trivy%20Cyber%20Attack.png","thumbnailURL":"/api/media/file/Trivy%20Cyber%20Attack-300x214.png","filename":"Trivy Cyber Attack.png","mimeType":"image/png","filesize":3964289,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Trivy Cyber Attack-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":139087,"filename":"Trivy Cyber Attack-300x214.png"},"square":{"url":"/api/media/file/Trivy Cyber Attack-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":501178,"filename":"Trivy Cyber Attack-500x500.png"},"small":{"url":"/api/media/file/Trivy Cyber Attack-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":486403,"filename":"Trivy Cyber Attack-600x429.png"},"medium":{"url":"/api/media/file/Trivy Cyber Attack-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":1004427,"filename":"Trivy Cyber Attack-900x643.png"},"large":{"url":"/api/media/file/Trivy Cyber Attack-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2236399,"filename":"Trivy Cyber Attack-1400x1000.png"},"xlarge":{"url":"/api/media/file/Trivy Cyber Attack-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":3849493,"filename":"Trivy Cyber Attack-1920x1372.png"},"og":{"url":"/api/media/file/Trivy Cyber Attack-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1276373,"filename":"Trivy Cyber Attack-1200x630.png"}}},"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Supply chain attacks have a pattern. The attacker doesn't break down the front door - they walk through one you left open for a tool you trusted. The Trivy compromise, which unfolded over the past couple of weeks, is one of the clearest examples of this we've seen in the DevOps tooling space.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Threat actors used stolen credentials to inject credential-stealing malware into an official Trivy release and into the GitHub Actions workflows that thousands of CI/CD pipelines invoke automatically. The malicious code ran silently, appearing to complete legitimate scans while exfiltrating cloud credentials, SSH keys, Kubernetes tokens, and more to attacker-controlled infrastructure. The attack spread further in the days that followed - into npm packages, Docker Hub images, and internal Aqua Security repositories. The incident has been assigned CVE-2026-33634 with a near-maximum CVSS score of 9.4, and Aqua Security, working with external forensic firm Sygnia, has nearly completed its investigation.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"If your pipelines were affected, ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9bf","type":"link","fields":{"url":"https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Aqua Security's official advisory","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" has the technical breakdown and remediation steps you need. But that's not what this post is about.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The Part of This Attack That Gets Less Attention","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Most of the security community's response to incidents like this one focuses on the pipeline - and rightly so. Mutable version tags, insufficient secret scoping, long-lived credentials in CI environments: these are real problems with real fixes, and the Trivy incident is an urgent reminder to address them.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"What gets less attention is what the malware was built to do beyond the pipeline. This wasn't just a CI infostealer. On persistent developer environments, the malicious Trivy binary attempted to install a systemd backdoor - a persistent service that would survive reboots and continue polling an external server for additional payloads indefinitely.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"That's a meaningfully different threat than stealing secrets from a disposable CI runner. A persistent foothold on a developer's machine is a long-term asset. It provides access to everything that engineer touches over time - not just the credentials in scope for a single pipeline run, but local keys, internal tooling, code review systems, communications, and the accumulated context of someone who likely has broad access to your engineering environment. Pipeline secrets are valuable. Developer machines are a goldmine.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This distinction matters because the defenses are different.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Why Ephemeral Developer Workspaces Change the Equation","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"At Kasm, we run our own development environment on Kasm Workspaces - and the security model behind that choice is directly relevant to this class of attack.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The core property of a Kasm workspace is that it is ephemeral. Each session runs in a containerized environment that is destroyed when the session ends. There is no persistent local installation of development tools. There is no state for malware to write to and survive in. A developer who ran a compromised binary inside a Kasm workspace and closed the session at the end of the day would have eliminated any persistence attempt entirely - the container is gone, and with it any foothold the attacker tried to establish.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The explicit logic in the Trivy malware - checking whether it was running on a developer machine before attempting to install persistence - tells you something important: attackers understand the difference between ephemeral and persistent environments. Persistent machines are valuable. Ephemeral containers are not worth the effort.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Beyond ephemerality, the workspace model adds several layers of protection relevant here. Tools and credentials can be mapped into a session at runtime without being stored permanently in the base image - keeping sensitive material available for development workflows without creating a persistent copy that survives the session. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Granular DLP controls govern what can move in or out of a session, bounding the blast radius of any compromise. And because developers connect through a browser rather than installing anything locally, BYOD is possible without extending trust to the endpoint device itself.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"One Layer, Not the Whole Answer","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"To be direct: ephemeral developer workspaces address the developer endpoint layer of this problem - not the pipeline layer. They don't prevent malicious code from running in a CI runner, and they don't replace the secrets rotation, SHA pinning, and pipeline hardening that this incident demands. Those steps are necessary regardless.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"What the workspace model does is remove the developer endpoint from the long-term threat calculus. When sessions don't persist, malware can't accumulate access. When credentials don't live on devices, they can't be harvested from them. When the development environment resets with every session, the attacker's window is measured in hours rather than months.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Supply chain attacks are not slowing down - the Trivy compromise itself is proof of how fast one stolen credential can travel. In the weeks following the initial breach, credentials harvested from Trivy pipelines were used to compromise Checkmarx, LiteLLM, and the Telnyx Python SDK across five separate ecosystems. CERT-EU has since confirmed that the European Commission's cloud infrastructure was breached as a direct downstream result, with over 340 GB of data exfiltrated. One compromised security tool. One set of stolen credentials. Cascading consequences across government and enterprise infrastructure worldwide.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The developer endpoint persistence component of this attack - the systemd backdoor targeting developer machines, not ephemeral CI runners - represents exactly the kind of long-tail risk that ephemeral workspace architecture is designed to cut off. When developer environments reset at the end of every session, the attacker's ability to use a compromised machine as a launchpad for the next stage of a campaign disappears with the container.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The question worth asking after an incident like this isn't just \"how do we fix our pipelines?\" It's \"what does our development environment look like if the next tool we trust gets compromised?\"","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"About Kasm Workspaces","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Technologies delivers a modern platform for secure, containerized desktop and application access. Kasm Workspaces streams browsers, desktops, and applications directly to users through ephemeral, policy-controlled sessions - eliminating the cost, rigidity, and risk of traditional VDI. Built by a team with deep roots in federal cybersecurity and offensive/defensive operations, Kasm is used by organizations ranging from government agencies to Fortune 500 companies to deliver secure, scalable developer and end-user environments.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Learn more at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9c0","type":"link","fields":{"url":"https://kasm.com","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasm.com","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"References","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"1. Aqua Security","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - Official Trivy Supply Chain Attack Advisory","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9c1","type":"link","fields":{"url":"https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"2. Wiz Research","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - Trivy Compromised by TeamPCP","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9c2","type":"link","fields":{"url":"https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"3. The Hacker News","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - Trivy Security Scanner GitHub Actions Breached","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9c3","type":"link","fields":{"url":"https://thehackernews.com/2026/03/trivy-security-scanner-github-actions.html","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://thehackernews.com/2026/03/trivy-security-scanner-github-actions.html","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"4. CrowdStrike","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - From Scanner to Stealer: Inside the trivy-action Supply Chain Compromise","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9c4","type":"link","fields":{"url":"https://www.crowdstrike.com/en-us/blog/from-scanner-to-stealer-inside-the-trivy-action-supply-chain-compromise/","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://www.crowdstrike.com/en-us/blog/from-scanner-to-stealer-inside-the-trivy-action-supply-chain-compromise/","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"5. BleepingComputer","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - Trivy supply-chain attack spreads to Docker, GitHub repos","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9c5","type":"link","fields":{"url":"https://www.bleepingcomputer.com/news/security/trivy-supply-chain-attack-spreads-to-docker-github-repos/","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://www.bleepingcomputer.com/news/security/trivy-supply-chain-attack-spreads-to-docker-github-repos/","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"6. CVE-2026-33634 / Aqua Security GitHub Advisory","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - GHSA-69fq-xp46-6x23","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9c6","type":"link","fields":{"url":"https://github.com/advisories/GHSA-69fq-xp46-6x23","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://github.com/advisories/GHSA-69fq-xp46-6x23","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"7. Help Net Security","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - Trivy supply chain attack enabled European Commission cloud breach","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9c7","type":"link","fields":{"url":"https://www.helpnetsecurity.com/2026/04/03/european-commission-cloud-breach/","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://www.helpnetsecurity.com/2026/04/03/european-commission-cloud-breach/","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"8. Sysdig","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9c8","type":"link","fields":{"url":"https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"9. Palo Alto Networks Unit 42","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" - Weaponizing the Protectors: TeamPCP's Multi-Stage Supply Chain Attack","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"69d55d0178bc74573433f9c9","type":"link","fields":{"url":"https://unit42.paloaltonetworks.com/teampcp-supply-chain-attacks/","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"https://unit42.paloaltonetworks.com/teampcp-supply-chain-attacks/","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0}],"direction":"ltr"}},"relatedPosts":[],"categories":[{"id":25,"title":"Government, Defense & Intelligence","author":6,"slug":"government-defense--intelligence","slugLock":true,"updatedAt":"2025-12-29T21:16:45.200Z","createdAt":"2025-12-29T21:16:45.200Z"},{"id":33,"title":"Web Isolation","author":6,"slug":"web-isolation","slugLock":true,"updatedAt":"2025-12-29T21:21:03.995Z","createdAt":"2025-12-29T21:21:03.995Z"},{"id":39,"title":"Secure Remote Access","author":6,"slug":"secure-remote-access","slugLock":true,"updatedAt":"2025-12-29T21:23:22.627Z","createdAt":"2025-12-29T21:23:22.627Z"},{"id":36,"title":"Remote Desktops & Applications ","author":6,"slug":"remote-desktops--applications-","slugLock":true,"updatedAt":"2025-12-29T21:22:27.098Z","createdAt":"2025-12-29T21:22:27.098Z"}],"meta":{"title":"Your Dev Environment Is Part of the Attack Surface. The Trivy Incident Proves It.","image":{"id":52,"alt":null,"caption":null,"author":6,"updatedAt":"2026-04-07T19:41:16.417Z","createdAt":"2026-04-07T19:41:13.236Z","url":"/api/media/file/Trivy%20Cyber%20Attack.png","thumbnailURL":"/api/media/file/Trivy%20Cyber%20Attack-300x214.png","filename":"Trivy Cyber Attack.png","mimeType":"image/png","filesize":3964289,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Trivy Cyber Attack-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":139087,"filename":"Trivy Cyber Attack-300x214.png"},"square":{"url":"/api/media/file/Trivy Cyber Attack-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":501178,"filename":"Trivy Cyber Attack-500x500.png"},"small":{"url":"/api/media/file/Trivy Cyber Attack-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":486403,"filename":"Trivy Cyber Attack-600x429.png"},"medium":{"url":"/api/media/file/Trivy Cyber Attack-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":1004427,"filename":"Trivy Cyber Attack-900x643.png"},"large":{"url":"/api/media/file/Trivy Cyber Attack-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2236399,"filename":"Trivy Cyber Attack-1400x1000.png"},"xlarge":{"url":"/api/media/file/Trivy Cyber Attack-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":3849493,"filename":"Trivy Cyber Attack-1920x1372.png"},"og":{"url":"/api/media/file/Trivy Cyber Attack-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1276373,"filename":"Trivy Cyber Attack-1200x630.png"}}},"description":"The Trivy supply chain attack exposed how vulnerable developer environments can be. Learn how ephemeral workspaces help eliminate persistence and reduce long-term risk."},"publishedAt":"2026-04-07T19:43:59.340Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"your-dev-environment-is-part-of-the-attack-surface-the-trivy-incident-proves-it","slugLock":true,"updatedAt":"2026-04-07T19:43:59.344Z","createdAt":"2026-04-03T17:43:31.855Z","_status":"published"},{"id":26,"title":"The Story of Kasm Workspaces: From an Idea to a Platform ","description":"The story of Kasm is different. It didn’t start in a boardroom or as part of a government program. It started with a problem—one that refused to go away. ","heroImage":{"id":51,"alt":null,"caption":null,"author":6,"updatedAt":"2026-04-07T19:28:21.532Z","createdAt":"2026-04-07T19:28:19.732Z","url":"/api/media/file/Story%20of%20Kasm.png","thumbnailURL":"/api/media/file/Story%20of%20Kasm-300x214.png","filename":"Story of Kasm.png","mimeType":"image/png","filesize":627852,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Story of Kasm-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":31135,"filename":"Story of Kasm-300x214.png"},"square":{"url":"/api/media/file/Story of Kasm-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":87696,"filename":"Story of Kasm-500x500.png"},"small":{"url":"/api/media/file/Story of Kasm-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":90826,"filename":"Story of Kasm-600x429.png"},"medium":{"url":"/api/media/file/Story of Kasm-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":174346,"filename":"Story of Kasm-900x643.png"},"large":{"url":"/api/media/file/Story of Kasm-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":368661,"filename":"Story of Kasm-1400x1000.png"},"xlarge":{"url":"/api/media/file/Story of Kasm-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":632633,"filename":"Story of Kasm-1920x1372.png"},"og":{"url":"/api/media/file/Story of Kasm-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":268891,"filename":"Story of Kasm-1200x630.png"}}},"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Every company has an origin story. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Some are polished. Some are exaggerated. Some take on a life of their own over time. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The story of Kasm is different. It didn’t start in a boardroom or as part of a government program. It started with a problem—one that refused to go away. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"A Problem Worth Solving ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Long before Kasm Technologies was founded, Justin Travis was studying cybersecurity as an undergraduate. At the time, one issue consistently ranked among the most significant threats to organizations: drive-by browser exploits. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The premise was simple. A user visits a website, their machine becomes compromised, and because that machine sits inside a trusted network, the threat spreads. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"For his capstone project, Justin explored a different approach: what if users never interacted with the web directly from their local machines? ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Instead, browsing would happen in a remote, isolated environment—something disposable, separate from the internal network. If it became compromised, it could simply be destroyed and replaced. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"At the time, it was just a concept. There was no product, no company—just an idea. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"But it stayed with him. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"When Theory Meets Reality ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Years later, Justin found himself working in offensive cybersecurity—researching vulnerabilities and investigating threats across some of the most dangerous corners of the internet. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The same problem resurfaced. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The tools available were limited. Analysts relied on remote machines or persistent systems that were difficult to maintain and, if compromised, carried ongoing risk. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The gap between what existed and what was needed became clear. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"That early idea—remote, disposable environments for interacting with untrusted content—was no longer theoretical. It was necessary. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Reconnecting and Rebuilding ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Around this time, Justin reconnected with Matt McClaskey, a longtime colleague. The two had previously worked together and had even attempted to build a company in the past, though it never fully materialized. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"This time was different. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"What began as a conversation quickly turned into a decision: they would build the solution themselves. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The timing aligned with the emergence of containerization technologies like Docker. Instead of relying on heavy, persistent virtual machines, they could create lightweight, ephemeral environments that spun up on demand and disappeared just as quickly. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"They built an early prototype—a browser running inside a container, delivered remotely to the user. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"It worked. And more importantly, people saw its potential. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The First Customer—and a Shift in Direction ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Initially, the vision centered on browser isolation. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"But the first real customer had a different need. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"They were solving a complex access challenge: enabling multiple external organizations to securely access a controlled environment containing sensitive data. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Traditional approaches—VPNs, client installations, network tunnels—introduced operational friction and security concerns. Coordinating across different organizations and IT teams made deployment difficult, and trusting external devices created risk. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm offered a different model. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"No client installations. No direct network exposure. No dependency on endpoint security. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Access was delivered entirely through the browser, with strict controls around data movement and user interaction. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The customer agreed to a six-month pilot. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"During that time, Justin and Matt—still working full-time jobs—built relentlessly. Nights, weekends, and any available time were spent refining the platform and delivering the features required. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"At the end of the pilot, the customer converted. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"They remain a customer today.  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Building Before It Was a Business ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"For several years, Kasm existed in a transitional state. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The product was real. Customers were using it. But the company itself was still being built in the margins of full-time careers. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Justin and Matt continued developing the platform incrementally—responding to real-world use cases, refining capabilities, and learning where the product delivered the most value. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"It wasn’t a traditional startup trajectory. There was no immediate scaling, no large funding rounds, and no rapid hiring. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Instead, it was methodical. Intentional. Built around real demand. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The Inflection Point ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"That changed in 2020. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"As the world shifted toward remote work during COVID, the relevance of Kasm’s approach became more apparent. At the same time, internal momentum had reached a point where continuing part-time was no longer sustainable. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"That year marked the transition to full-time focus. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"It wasn’t a perfectly timed leap. It came with uncertainty, risk, and significant personal challenges. But it was necessary. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm was no longer an experiment—it was a company. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Expanding Beyond the Original Vision ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"If Kasm had remained solely a browser isolation solution, it likely would have remained niche. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Instead, it evolved. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Customers began using the platform for more than browsing: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Secure remote access  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Application delivery  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Linux-based workspaces  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Full desktop environments  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Each new use case expanded the scope of the platform. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Over time, Kasm introduced support for full virtual desktops, including Windows environments—often driven by urgent, real-world needs from customers operating in high-stakes environments. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Some of these capabilities were developed rapidly to meet immediate demands, then refined over time into broader, more scalable solutions. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Rethinking How Technology Is Used ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"At the core of Kasm’s approach is a rethinking of how existing technologies can be applied. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Containers were never originally designed for interactive desktop streaming. They were built for packaging and deploying applications. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm adapted them. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"By leveraging containers for on-demand workspaces, the platform enables environments that are: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Ephemeral  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Isolated  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Scalable  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Efficient  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"This approach isn’t universal—but for organizations that need flexibility and control, it offers a fundamentally different model. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"How the Platform Evolves ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm’s evolution hasn’t followed a rigid roadmap. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Instead, it’s shaped by a continuous balancing act: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Customer needs and feedback  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Strategic direction and long-term vision  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Market opportunities  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Resource constraints  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Some features are driven directly by customer requirements. Others come from internal hypotheses about where the market is heading. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Every decision involves tradeoffs. Prioritizing one capability means delaying another. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Over time, this process has transformed Kasm from a single-purpose tool into a flexible platform. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Building the Right Team ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"As the company grew, Justin and Matt focused on building a team they trusted. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Many early team members were former colleagues—people they had worked with for years and knew could execute at a high level. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"This created a strong foundation of trust and alignment. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"As new team members joined, that foundation remained central to how the company operates. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"69d55bca78bc74573433f9be","type":"link","fields":{"url":"https://kasm.com/meet-the-team","linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about the team members at Kasm.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"A Commitment to Doing Things the Right Way ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Beyond the technology, Kasm has been shaped by a consistent approach to how business is done. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Transparency, consistency, and integrity have been core principles—from how features are delivered to how pricing is structured. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Rather than relying on aggressive tactics or short-term gains, the company has focused on building long-term trust with customers. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Where Kasm Is Today ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Today, Kasm is no longer defined by a single use case. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"It is a platform for delivering secure, on-demand workspaces—whether that means a browser session, an application, or a full desktop environment. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"It serves organizations with a wide range of needs, all centered around one core challenge: how to provide access without introducing risk. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Looking Ahead ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The journey from idea to platform has been anything but linear. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"What began as a concept in a capstone paper has evolved through real-world problems, customer-driven innovation, and years of incremental progress. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"And while the technology continues to evolve, the underlying goal remains the same: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"To provide secure, flexible access to the tools and environments people need—without compromising control. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0}],"direction":"ltr"}},"relatedPosts":[],"categories":[],"meta":{"title":"The Story of Kasm Workspaces: From an Idea to a Platform ","image":{"id":51,"alt":null,"caption":null,"author":6,"updatedAt":"2026-04-07T19:28:21.532Z","createdAt":"2026-04-07T19:28:19.732Z","url":"/api/media/file/Story%20of%20Kasm.png","thumbnailURL":"/api/media/file/Story%20of%20Kasm-300x214.png","filename":"Story of Kasm.png","mimeType":"image/png","filesize":627852,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Story of Kasm-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":31135,"filename":"Story of Kasm-300x214.png"},"square":{"url":"/api/media/file/Story of Kasm-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":87696,"filename":"Story of Kasm-500x500.png"},"small":{"url":"/api/media/file/Story of Kasm-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":90826,"filename":"Story of Kasm-600x429.png"},"medium":{"url":"/api/media/file/Story of Kasm-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":174346,"filename":"Story of Kasm-900x643.png"},"large":{"url":"/api/media/file/Story of Kasm-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":368661,"filename":"Story of Kasm-1400x1000.png"},"xlarge":{"url":"/api/media/file/Story of Kasm-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":632633,"filename":"Story of Kasm-1920x1372.png"},"og":{"url":"/api/media/file/Story of Kasm-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":268891,"filename":"Story of Kasm-1200x630.png"}}},"description":"The story of Kasm Workspaces—from a cybersecurity idea to a full platform delivering secure, on-demand browser, app, and desktop environments.\n "},"publishedAt":"2026-04-07T19:32:44.302Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"the-story-of-kasmworkspaces-from-an-idea-to-a-platform","slugLock":true,"updatedAt":"2026-04-07T19:32:44.304Z","createdAt":"2026-04-03T17:33:20.029Z","_status":"published"},{"id":25,"title":"A Look Forward: SR-IOV GPUs, Proxmox VE, and the Next Phase of VDI","description":"Over the last year, the VDI conversation has shifted. Between licensing realignments in the VMware ecosystem and continued cost pressure around GPU acceleration, many IT teams are re-evaluating their stack. ","heroImage":{"id":50,"alt":null,"caption":null,"author":6,"updatedAt":"2026-02-23T18:59:38.922Z","createdAt":"2026-02-23T18:59:35.829Z","url":"/api/media/file/v1.18%20Now%20Live%20(20).png","thumbnailURL":"/api/media/file/v1.18%20Now%20Live%20(20)-300x214.png","filename":"v1.18 Now Live (20).png","mimeType":"image/png","filesize":4365323,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/v1.18 Now Live (20)-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":126379,"filename":"v1.18 Now Live (20)-300x214.png"},"square":{"url":"/api/media/file/v1.18 Now Live (20)-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":439837,"filename":"v1.18 Now Live (20)-500x500.png"},"small":{"url":"/api/media/file/v1.18 Now Live (20)-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":447363,"filename":"v1.18 Now Live (20)-600x429.png"},"medium":{"url":"/api/media/file/v1.18 Now Live (20)-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":963162,"filename":"v1.18 Now Live (20)-900x643.png"},"large":{"url":"/api/media/file/v1.18 Now Live (20)-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2309218,"filename":"v1.18 Now Live (20)-1400x1000.png"},"xlarge":{"url":"/api/media/file/v1.18 Now Live (20)-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":4238307,"filename":"v1.18 Now Live (20)-1920x1372.png"},"og":{"url":"/api/media/file/v1.18 Now Live (20)-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1291509,"filename":"v1.18 Now Live (20)-1200x630.png"}}},"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" Over the last year, the VDI conversation has shifted.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Between licensing realignments in the VMware ecosystem and continued cost pressure around GPU acceleration, many IT teams are re-evaluating their stack. At the same time, open platforms like ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"699ca1e858a0d2b9eca2d0e5","type":"link","fields":{"url":"https://www.proxmox.com/en/proxmox-virtual-environment","newTab":false,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Proxmox VE","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textFormat":1},{"mode":"normal","text":" have matured into legitimate production contenders - a shift highlighted repeatedly by notably ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"Level1Techs","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" and others in their deep dives into Proxmox clustering and Intel’s new SR-IOV capable GPUs.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"As a solutions engineer at ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"699ca44258a0d2b9eca2d0ee","type":"link","fields":{"url":"https://kasm.com/","linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Kasm Technologies","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":",","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1},{"mode":"normal","text":" I spend a lot of time thinking about where VDI is going - not just where it is today.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This post is a look forward.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The GPU Question in VDI","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"When people think about GPU-accelerated VDI, they often jump straight to heavy compute:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"AI / data science workloads","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"CUDA-driven applications","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"ML model training","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"And for those use cases, ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"NVIDIA + CUDA","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" is the clear leader.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"But that’s not the whole VDI story.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"A large class of deployments need GPU acceleration for different reasons:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Delivering a smoother Windows desktop experience","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Engineers running CAD tools","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Creative teams using Photoshop or video editing software","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"WebGL-heavy browser workloads","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Light 3D visualization","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Historically, if you wanted to virtualize GPUs properly in this space, you used ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"NVIDIA vGPU","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":". It’s a mature, excellent technology - and notably, Proxmox now officially supports NVIDIA vGPU as of 2025.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"But the tradeoffs are well known:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Enterprise-grade GPU SKUs","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Paid vGPU licenses","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Licensed drivers","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Higher entry cost","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For some environments, that’s perfect. For others, it’s more than they need.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Enter SR-IOV on Professional GPUs","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Single Root I/O Virtualization (SR-IOV) changes the conversation.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Instead of time-slicing a GPU in software, SR-IOV allows a physical PCIe device to expose multiple hardware-backed ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"Virtual Functions (VFs)","type":"text","style":"","detail":0,"format":2,"version":1},{"mode":"normal","text":". Each VF can be assigned directly to a VM.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Conceptually, it’s similar to vGPU:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"One physical card -> multiple isolated virtual GPU devices.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"One of the most interesting developments here is the ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"Intel Arc Pro B50","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"At a workstation-friendly price point, the B50:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Provides 16GB of VRAM","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Implements SR-IOV","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Targets professional workloads","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Works on Linux","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Thanks in part to coverage and experimentation from Level1Techs, the community has been actively exploring what this means for virtualization.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The big shift?","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"SR-IOV support is steadily landing upstream in the Linux kernel. We are no longer in “custom patch and DKMS hack” territory.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The Test Environment: Real Versions, Real Results","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For this lab, we ran:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Proxmox VE 9.1.5","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textFormat":1},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kernel: ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"6.17.2-1-pve","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" (stock)","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Intel Arc Pro B50 with SR-IOV enabled","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"No custom kernel modules were required.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"No out-of-tree patches.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"No experimental builds.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This is important.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"In earlier cycles, GPU SR-IOV experimentation often required special kernels. In this test, everything that worked did so on a shipping Proxmox release.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"That’s a meaningful maturity milestone.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"How We Partitioned the GPU","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"In this test, we split a single 16GB B50 into ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"8 Virtual Functions","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":".","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"That allowed us to allocate:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"2GB of VRAM per Windows VM","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textFormat":1}],"listType":"bullet","direction":"ltr","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"From a VDI perspective, that’s a very interesting density profile:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"1 physical card","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"8 GPU-backed desktops","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Hardware-isolated functions","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For many task-worker, CAD-lite, browser-heavy, or creative workloads, 2GB per desktop is entirely usable.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"block","fields":{"id":"699ca55a58a0d2b9eca2d0f1","media":{"id":45,"alt":null,"caption":null,"author":6,"updatedAt":"2026-02-23T18:53:21.072Z","createdAt":"2026-02-23T18:53:18.082Z","url":"/api/media/file/image-20260213-124802.png","thumbnailURL":"/api/media/file/image-20260213-124802-300x195.png","filename":"image-20260213-124802.png","mimeType":"image/png","filesize":3950675,"width":1912,"height":1241,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/image-20260213-124802-300x195.png","width":300,"height":195,"mimeType":"image/png","filesize":136438,"filename":"image-20260213-124802-300x195.png"},"square":{"url":"/api/media/file/image-20260213-124802-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":526650,"filename":"image-20260213-124802-500x500.png"},"small":{"url":"/api/media/file/image-20260213-124802-600x389.png","width":600,"height":389,"mimeType":"image/png","filesize":503498,"filename":"image-20260213-124802-600x389.png"},"medium":{"url":"/api/media/file/image-20260213-124802-900x584.png","width":900,"height":584,"mimeType":"image/png","filesize":1083292,"filename":"image-20260213-124802-900x584.png"},"large":{"url":"/api/media/file/image-20260213-124802-1400x909.png","width":1400,"height":909,"mimeType":"image/png","filesize":2505453,"filename":"image-20260213-124802-1400x909.png"},"xlarge":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"og":{"url":"/api/media/file/image-20260213-124802-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1542472,"filename":"image-20260213-124802-1200x630.png"}}},"blockName":"","blockType":"mediaBlock"},"format":"","version":2},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"A Windows 11 VM using a 2GB slice of the B50 streamed via Kasm Workspaces","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"block","fields":{"id":"699ca56a58a0d2b9eca2d0f2","media":{"id":46,"alt":null,"caption":null,"author":6,"updatedAt":"2026-02-23T18:54:14.696Z","createdAt":"2026-02-23T18:54:12.651Z","url":"/api/media/file/image-20260213-130351.png","thumbnailURL":"/api/media/file/image-20260213-130351-300x326.png","filename":"image-20260213-130351.png","mimeType":"image/png","filesize":171030,"width":1087,"height":1181,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/image-20260213-130351-300x326.png","width":300,"height":326,"mimeType":"image/png","filesize":111649,"filename":"image-20260213-130351-300x326.png"},"square":{"url":"/api/media/file/image-20260213-130351-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":240172,"filename":"image-20260213-130351-500x500.png"},"small":{"url":"/api/media/file/image-20260213-130351-600x652.png","width":600,"height":652,"mimeType":"image/png","filesize":341468,"filename":"image-20260213-130351-600x652.png"},"medium":{"url":"/api/media/file/image-20260213-130351-900x978.png","width":900,"height":978,"mimeType":"image/png","filesize":605100,"filename":"image-20260213-130351-900x978.png"},"large":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"xlarge":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"og":{"url":"/api/media/file/image-20260213-130351-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":365944,"filename":"image-20260213-130351-1200x630.png"}}},"blockName":"","blockType":"mediaBlock"},"format":"","version":2},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The Intel B50 as seen from the PVE host advertising SR-IOV capabilities (12 available VFs , 8 configured in this case)","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This wasn’t theoretical. Each VM saw its own VF and operated independently.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Multi-Node Cluster + Resource Mapping","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"We deployed a multi-node Proxmox cluster, with GPUs distributed across nodes.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"In Proxmox, we grouped SR-IOV Virtual Functions into a ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"Resource Mapping","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" abstraction.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This was the key architectural enabler.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Instead of binding a VM to a specific PCI address:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"We created a resource pool of GPU VFs","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Allowed orchestration to request “a GPU”","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Let Proxmox resolve the actual physical mapping","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"With this in place, ","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":"Kasm Workspaces","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" could:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Clone a golden Windows template","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Deploy it to any eligible node","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Attach an available GPU VF dynamically","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This moves the pattern from static passthrough to programmable infrastructure. ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"699ca4a958a0d2b9eca2d0ef","type":"link","fields":{"url":"https:///kasm.com/workspaces","linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about VDI with Kasm Workspaces.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"block","fields":{"id":"699ca58558a0d2b9eca2d0f3","media":{"id":47,"alt":null,"caption":null,"author":6,"updatedAt":"2026-02-23T18:55:11.737Z","createdAt":"2026-02-23T18:55:10.727Z","url":"/api/media/file/image-20260213-125253.png","thumbnailURL":"/api/media/file/image-20260213-125253-300x223.png","filename":"image-20260213-125253.png","mimeType":"image/png","filesize":70384,"width":1207,"height":896,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/image-20260213-125253-300x223.png","width":300,"height":223,"mimeType":"image/png","filesize":47329,"filename":"image-20260213-125253-300x223.png"},"square":{"url":"/api/media/file/image-20260213-125253-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":140313,"filename":"image-20260213-125253-500x500.png"},"small":{"url":"/api/media/file/image-20260213-125253-600x445.png","width":600,"height":445,"mimeType":"image/png","filesize":143476,"filename":"image-20260213-125253-600x445.png"},"medium":{"url":"/api/media/file/image-20260213-125253-900x668.png","width":900,"height":668,"mimeType":"image/png","filesize":262612,"filename":"image-20260213-125253-900x668.png"},"large":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"xlarge":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"og":{"url":"/api/media/file/image-20260213-125253-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":338324,"filename":"image-20260213-125253-1200x630.png"}}},"blockName":"","blockType":"mediaBlock"},"format":"","version":2},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Resource Mapping of the B50 virtual functions across multiple Proxmox nodes","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"block","fields":{"id":"699ca59758a0d2b9eca2d0f4","media":{"id":48,"alt":null,"caption":null,"author":6,"updatedAt":"2026-02-23T18:56:02.214Z","createdAt":"2026-02-23T18:56:01.215Z","url":"/api/media/file/image-20260213-125048.png","thumbnailURL":"/api/media/file/image-20260213-125048-300x157.png","filename":"image-20260213-125048.png","mimeType":"image/png","filesize":67630,"width":1279,"height":670,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/image-20260213-125048-300x157.png","width":300,"height":157,"mimeType":"image/png","filesize":39670,"filename":"image-20260213-125048-300x157.png"},"square":{"url":"/api/media/file/image-20260213-125048-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":111260,"filename":"image-20260213-125048-500x500.png"},"small":{"url":"/api/media/file/image-20260213-125048-600x314.png","width":600,"height":314,"mimeType":"image/png","filesize":118425,"filename":"image-20260213-125048-600x314.png"},"medium":{"url":"/api/media/file/image-20260213-125048-900x471.png","width":900,"height":471,"mimeType":"image/png","filesize":214863,"filename":"image-20260213-125048-900x471.png"},"large":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"xlarge":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"og":{"url":"/api/media/file/image-20260213-125048-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":322651,"filename":"image-20260213-125048-1200x630.png"}}},"blockName":"","blockType":"mediaBlock"},"format":"","version":2},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Multiple GPU-enabled VMs are auto-scaled across the cluster using a single template","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"block","fields":{"id":"699ca5a458a0d2b9eca2d0f5","media":{"id":49,"alt":null,"caption":null,"author":6,"updatedAt":"2026-02-23T18:56:50.316Z","createdAt":"2026-02-23T18:56:47.571Z","url":"/api/media/file/image-20260213-142404.png","thumbnailURL":"/api/media/file/image-20260213-142404-300x227.png","filename":"image-20260213-142404.png","mimeType":"image/png","filesize":2572632,"width":1438,"height":1087,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/image-20260213-142404-300x227.png","width":300,"height":227,"mimeType":"image/png","filesize":149805,"filename":"image-20260213-142404-300x227.png"},"square":{"url":"/api/media/file/image-20260213-142404-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":486823,"filename":"image-20260213-142404-500x500.png"},"small":{"url":"/api/media/file/image-20260213-142404-600x454.png","width":600,"height":454,"mimeType":"image/png","filesize":532342,"filename":"image-20260213-142404-600x454.png"},"medium":{"url":"/api/media/file/image-20260213-142404-900x680.png","width":900,"height":680,"mimeType":"image/png","filesize":1130001,"filename":"image-20260213-142404-900x680.png"},"large":{"url":"/api/media/file/image-20260213-142404-1400x1058.png","width":1400,"height":1058,"mimeType":"image/png","filesize":2569291,"filename":"image-20260213-142404-1400x1058.png"},"xlarge":{"url":null,"width":null,"height":null,"mimeType":null,"filesize":null,"filename":null},"og":{"url":"/api/media/file/image-20260213-142404-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1399449,"filename":"image-20260213-142404-1200x630.png"}}},"blockName":"","blockType":"mediaBlock"},"format":"","version":2},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The test bench - pardon the mess","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Migration Testing Results","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"We tested real operational scenarios, not just boot success.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Results:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"✅ Cloning across cluster nodes - worked","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"✅ Powered-off migration - worked","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"❌ Live migration (powered-on) - not working yet","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Live migration of SR-IOV-backed VMs did not function in this kernel/driver combination.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For many autoscaling or non-persistent VDI environments, cold migration is acceptable. But live migration support would be an important future milestone.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Driver Observations","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"We did encounter driver considerations:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"To expose a higher number of VFs, we dropped back to an earlier Intel driver version.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Some quirks remain - this is still early in the lifecycle.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"That said, Intel’s GPU driver stack has steadily improved over time, and the fact that this works on a stock Proxmox kernel is a strong signal.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Intel could slot extremely well into this market - though their segmentation and messaging around driver support has felt fluid. If they lean into SR-IOV for professional virtualization, the opportunity is significant.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Why This Matters Now","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The broader context:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"VMware is focusing upward in the market.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Enterprises are re-evaluating cost structures.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"GPU-backed VDI demand is rising.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Open hypervisors are maturing.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This is not a takedown of VMware or NVIDIA. Both remain strong partners and technology leaders.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"But markets evolve.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"SR-IOV GPUs in the workstation class introduce a new acceleration tier:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Below full datacenter GPU stacks","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Above basic non-accelerated desktops","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"License-light","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Infrastructure-native","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For VDI platforms integrating across clouds and hypervisors, this unlocks new design space.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"A Look Forward","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This lab wasn’t meant to claim perfection.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"It was meant to answer:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Is it viable?","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Is it stable enough to explore?","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Does it integrate cleanly?","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Can it scale across a cluster?","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Does it behave operationally?","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The answer today:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"It works on stock Proxmox VE 9.1.5","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Kernel 6.17.2-1-pve is sufficient","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"8 VFs at 2GB each are practical","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Cluster cloning works","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Cold migration works","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":6,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Live migration isn’t there yet","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"That’s a very different place than we were even a year ago.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"If you’re an engineer, architect or CTO watching the direction of virtualization and GPU economics, this is worth paying attention.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This isn’t the final state of GPU-backed VDI.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"It’s a preview of what the next tier might look like.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"id":"699ca4ed58a0d2b9eca2d0f0","type":"link","fields":{"url":"https://kasm.com/get-started","linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Get Started with Kasm Workspaces","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0}],"direction":"ltr"}},"relatedPosts":[],"categories":[{"id":36,"title":"Remote Desktops & Applications ","author":6,"slug":"remote-desktops--applications-","slugLock":true,"updatedAt":"2025-12-29T21:22:27.098Z","createdAt":"2025-12-29T21:22:27.098Z"}],"meta":{"title":"A Look Forward: SR-IOV GPUs, Proxmox VE, and the Next Phase of VDI","image":{"id":50,"alt":null,"caption":null,"author":6,"updatedAt":"2026-02-23T18:59:38.922Z","createdAt":"2026-02-23T18:59:35.829Z","url":"/api/media/file/v1.18%20Now%20Live%20(20).png","thumbnailURL":"/api/media/file/v1.18%20Now%20Live%20(20)-300x214.png","filename":"v1.18 Now Live (20).png","mimeType":"image/png","filesize":4365323,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/v1.18 Now Live (20)-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":126379,"filename":"v1.18 Now Live (20)-300x214.png"},"square":{"url":"/api/media/file/v1.18 Now Live (20)-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":439837,"filename":"v1.18 Now Live (20)-500x500.png"},"small":{"url":"/api/media/file/v1.18 Now Live (20)-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":447363,"filename":"v1.18 Now Live (20)-600x429.png"},"medium":{"url":"/api/media/file/v1.18 Now Live (20)-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":963162,"filename":"v1.18 Now Live (20)-900x643.png"},"large":{"url":"/api/media/file/v1.18 Now Live (20)-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2309218,"filename":"v1.18 Now Live (20)-1400x1000.png"},"xlarge":{"url":"/api/media/file/v1.18 Now Live (20)-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":4238307,"filename":"v1.18 Now Live (20)-1920x1372.png"},"og":{"url":"/api/media/file/v1.18 Now Live (20)-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1291509,"filename":"v1.18 Now Live (20)-1200x630.png"}}},"description":"SR-IOV GPUs are reshaping VDI. Explore how Intel Arc Pro B50 and Proxmox VE 9.1 enable license-light, hardware-partitioned GPU acceleration for scalable Windows desktops and clustered environments—without custom kernels or enterprise GPU costs."},"publishedAt":"2026-02-23T19:08:36.694Z","authors":[4],"populatedAuthors":[{"id":4,"name":"Justin Travis","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"a-look-forward-sr-iov-gpus-proxmox-ve-and-the-next-phase-of-vdi","slugLock":true,"updatedAt":"2026-02-23T19:08:36.698Z","createdAt":"2026-02-23T13:51:39.616Z","_status":"published"},{"id":24,"title":"Hitting the Reset Button: Secure Remote Access for Modern OT","description":"The term Secure Remote Access has been overused in today’s Operational Technology world. It is impossible to read any blog, attend any industry conference or listen to a podcast where it is not mentioned. ","heroImage":{"id":44,"alt":"OT","caption":null,"author":6,"updatedAt":"2026-02-20T20:36:16.394Z","createdAt":"2026-02-20T20:36:12.753Z","url":"/api/media/file/v1.18%20Now%20Live%20(19).png","thumbnailURL":"/api/media/file/v1.18%20Now%20Live%20(19)-300x214.png","filename":"v1.18 Now Live (19).png","mimeType":"image/png","filesize":5396509,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/v1.18 Now Live (19)-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":142239,"filename":"v1.18 Now Live (19)-300x214.png"},"square":{"url":"/api/media/file/v1.18 Now Live (19)-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":513934,"filename":"v1.18 Now Live (19)-500x500.png"},"small":{"url":"/api/media/file/v1.18 Now Live (19)-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":536768,"filename":"v1.18 Now Live (19)-600x429.png"},"medium":{"url":"/api/media/file/v1.18 Now Live (19)-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":1172420,"filename":"v1.18 Now Live (19)-900x643.png"},"large":{"url":"/api/media/file/v1.18 Now Live (19)-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2802341,"filename":"v1.18 Now Live (19)-1400x1000.png"},"xlarge":{"url":"/api/media/file/v1.18 Now Live (19)-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":5107749,"filename":"v1.18 Now Live (19)-1920x1372.png"},"og":{"url":"/api/media/file/v1.18 Now Live (19)-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1618761,"filename":"v1.18 Now Live (19)-1200x630.png"}}},"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The term Secure Remote Access has been overused in today’s Operational Technology world. It is impossible to read any blog, attend any industry conference, or listen to a podcast where it is not mentioned. With so many vendors in the space and each one putting their own spin on what it is, why it is matters, and why you need it, the noise is deafening. Adding to this confusion is the influx of IT-focused staff and technology entering the space with their own thoughts and visions on the topic. Analysis paralysis has set in, causing companies to hold off on making a decision on how to properly implement it within their organization. With the attacks on critical infrastructure increasing every day, companies must start taking charge of their Secure Remote Access direction before it’s too late.","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Defining Secure Remote Access","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Before we discuss what ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6998c5daab258d181f7df944","type":"link","fields":{"url":"https:/kasm.com/secure-access","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Secure Remote Access (SRA)","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" is and why we need it in Operational Technology (OT), we need to define it.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Secure Remote Access (SRA) is defined by NIST as authorized, protected, and monitored access to an organization’s information systems by users or devices communicating through external, non-organization-controlled networks.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"And while this definition helps define SRA overall, it leaves out a few key points that we need to understand. OT is not IT, and both areas do some things differently when it comes to people, process, and technology. While IT embraces the use of Virtual Private Networks (VPN) for Secure Remote Access within their environments, OT regulatory guidance and security best practices deeply discourages their implementation and use for many reasons. Additionally, IT networks are considered to be external and untrusted, even if they are controlled by the IT organization. While there are many reasons for this, the core security risk reason is that 75% of the cyber-attacks that occur within OT originate from IT network connectivity.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Why do we need Secure Remote Access in OT?","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Now that we have defined the concept of Secure Remote Access, we now need to understand why we need it in Operational Technology. While there has been some form of outside access into Industrial Control Systems (ICS) within OT for many years, Covid played a significant role in increasing the need for access as contractors, vendors, and operational staff were not able to travel on-site to perform their roles or tasks. Much of this access was put in place ad-hoc and quickly to ensure system uptime and availability and without much forethought about operational safety or cybersecurity risks. This led to many organizations taking IT driven access methods such as VPN, 5G phone home cellular, and even unsecured cable modems and putting them in place. Unfortunately, many of these methods were never removed or redone with OT Safety and Security best practices put in place.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Today with the growth of Smart Factories (Industry 4.0), the large scale retiring of OT staff (Peak 65), the AI driven demand to access critical operational data within ICS resources (all of which will be covered in more detail in future blogs) the need to gain remote access to legacy and modern computing systems safely and securely has grown even bigger.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"This reach has expanded as well. There is a growing need to reach legacy and modern computing resources at challenging locations such as oil drilling platforms miles off the coast, quarries, mines, rail, wastewater, and water systems.  Modern infrastructure locations are driving the need for Secure Remote Access as well. These include Distributed Energy Resources such as solar, wind, hydroelectric, geothermal, Battery Energy Storage Systems (BESS), smart city/grid infrastructure, EV charging systems, and lights out data centers and factories to name just a few.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Who needs Secure Remote Access?","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"id":"6998c5feab258d181f7df945","type":"link","fields":{"url":"https://kasm.com/secure-access","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Secure Remote Access ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":"today is not only for remote contractors, vendors and IT/OT staff. The need is a growing need for its use for contractors, vendors and OT staff who walk the grated floor as well.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"While there is also an equally expanding need for getting access to data for analytics, monitoring, reducing Mean Time To Detect (MTTD), improving Operational Efficiency (OE), reducing Mean Time Between Failure (MTTB) and more, those will be covered in a future dedicated blog.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Contractors and vendors, both remote and on-site, in many cases require direct connectivity between their laptops,","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":"locally installed applications and internal OT devices such as PLCs and RTUs. This Bring Your Own Device / Application (BYOD/BYOA) approach gives them direct device and network level access to the OT environment. This level of access brings safety and security risks,","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":"including introducing malware, uncontrolled network access and movement, access to sensitive data and resources, to name just a few. By implementing a modern Secure Remote Access application-level approach to access, contractors can now safely and securely perform their required job tasks without network-level","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":",","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" access and organizations can mitigate","type":"text","style":"","detail":0,"format":0,"version":1},{"mode":"normal","text":",","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" the threats and risks discussed above.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"For on-site staff and operators, use cases such as having Mobile HMI Access can now allow them to not be tethered to a fixed production line, work area, or line-of-sight status indicator. They can securely and safely respond to a notification or alert through a browser anywhere in the facility. Maintenance and inspection staff can now walk the plant floor performing break/fix, asset inventory collection, safety inspections, remote augmented reality support, and more.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Internal staff, contractors, and vendors also encounter situations where physically accessing a resource or location in a facility could put their safety or the lives of others at risk. Risk areas that include chemical, nuclear, heat, cold, oxygen deprivation, toxins, hazardous operations, and more. While they could use an Engineering Workstation (EWS) in some situations, most of these legacy systems lack oversight and safety tools such as recording, multi-factor authentication, just-in-time access, and remote monitoring to ensure that highly dangerous operations are not done improperly, insecurely, or unsafely.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"With all of the growing needs above becoming commonplace, the long-standing concept of isolated or what is also commonly referred to as “air-gapped” environments is rapidly going away. While isolation had its safety and security benefits, we no longer live in a world that supports complete isolation for many of our critical infrastructure systems and resources.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Why not just use existing IT Access","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"While IT organizations have been providing Secure Remote Access for employees and third parties to systems and resources for decades, there are positives and negatives to this approach that must be weighed heavily.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Many IT organizations have a wealth of knowledge and expertise, and have an existing preferred solution to provide Secure Remote Access, which is controlled and managed by the IT network and cybersecurity teams most of the time. Being able to leverage this existing infrastructure, with features like identity and access management, provide several benefits for OT environments from a security, compliance, and management perspective.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Unfortunately, this quickly becomes a double-edged sword for many reasons. Two of the primary reasons stated prior are most attacks into OT originate from within IT, and IT may times embraces the tried-and-true use of VPNs for access. While this is may have positives, requiring OT third-party contractors and vendors to install yet another endpoint agent or security plugin onto their laptop or phone is, in many cases a difficult ask. Even if they are able to overcome these challenges and gain access, the technologies used within IT are not granular enough and feature rich enough to provide things such as Just-In-Time (JIT), Just-Enough-Access (JEA), session recording, supervision, keystroke logging, and time limit control.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Even if IT is able to provide features such as session recording or supervision through a jump-box, as an example, the recordings, session audit logging and collaboration are done within DMZ and cloud-based platforms which now expose that data and recordings to areas outside of OT Electronic Security Perimeter (ESP). While OT data while not deemed sensitive, is definitely critical and contains many process and formulation secrets that must be kept within OT.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Additionally, when an incident occurs within an organization, one of the first things I hear people within OT and IT say is that they are going disconnect connectivity between them and isolate. While this may seem like a good practice from a cybersecurity and safety perspective, access to critical systems within each realm is becoming so intertwined that it has the real potential to make the situation much worse.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Lastly, having OT staff be able to access the Secure Remote Access management platform within the bounds of their environment and enable, disable, or modify access based on the situation gives them direct control during an incident. Having this control when IT staff priorities and resources are focused elsewhere can have a huge impact when human and critical infrastructure safety are on the line and seconds truly matter.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Regulatory and Compliance Drivers of Secure Remote Access","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The cyberattacks that have happened already including the Bowman Avenue dam in NYC (2013) over an insecure cellular modem, Colonial Pipeline (2021) through an IT controlled VPN, wastewater treatment facility in Oldsmar, FL (2021) through insecure desktop sharing software and most recently the attack on Poland’s Energy Sector (2026) over internet facing devices using default credentials and lacking multi-factor authentication, should alone be enough of a wakeup call to adopt Secure Remote Access methods in OT but they are not.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"To help mitigate and reduce cyberattacks within OT, there have been many directives, frameworks, guidance and best practices published on the proper ways to implement Secure Remote Access in OT. These include NERC CIP-005, IEC 62443-3-3, NIST SP 800-53, 800-46, 800-171, 800-207, TSA SD02E, NIS2, CMMC, CISA and more.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Additionally, Secure Remote Access is Control No 4 in SANS in the Five Critical Controls for ICS/OT Security which acts as a simple yet effective prioritized roadmap to secure OT environments, prioritizing safety, uptime, security and reliability. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"What are the core foundations and features of Secure Remote Access for OT","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"While there is a myriad of additional features that vendors provide in their Secure Remote Access products, including AI the core features are:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Just In Time (JIT) and Just Enough Access (JEA)","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Session Recording, Supervision and Intervention","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Multi-Factor Authentication","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Identity, Role and Policy-Based Access Control","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Asset and Protocol Isolation","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":6,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Logging and Auditability","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":7,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Identity Access Management","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":8,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Legacy Protocol Support","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":9,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Outbound Connectivity","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":10,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Flexible Deployment Architecture Model","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":11,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Continuous Monitoring and Access Evaluation","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":12,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Browser-Based UI","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":13,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Agentless","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"These features align to the growing trend in a push towards a Zero Trust Architecture Security Framework (NIST SP 800-207) and the CISA model of 5 pillars and 3 platforms. This provides a \"never trust, always verify\" model across these areas to ensure a comprehensive, defense in depth approach to protect against modern, sophisticated cyber threats while moving away from the perimeter-based data-centric security approach.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The Five Pillars","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Identity: ","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":"Verifies user, service, or application identity using strong authentication (MFA) to ensure only authorized users access resources.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Devices:","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Monitors and secures all devices (endpoints, IoT) connecting to the network, verifying their security posture before granting access.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Networks:","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Uses micro-segmentation to break the network into small, secure zones, limiting the lateral movement of threats.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Applications and Workloads:","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Protects applications, including those in the cloud and on-premise, by securing access and verifying workloads, such as containers or virtual machines.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Data:","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Identifies, classifies, and encrypts data at rest and in transit, placing security controls as close to the data as possible. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1}],"listType":"bullet","direction":"ltr","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"The Three Platforms","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Visibility and Analytics:","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Continuous monitoring to analyze user activity, device posture, and network traffic to detect anomalies.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Automation and Orchestration:","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Enables rapid response to threats and automatic, dynamic policy enforcement. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Governance:","type":"text","style":"","detail":0,"format":1,"version":1},{"mode":"normal","text":" Enable policies that enable tailored local controls with continuous enforcement and dynamic updates.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textFormat":1}],"listType":"bullet","direction":"ltr","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"In Conclusion","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"As with any technology within OT the core pillars of safety, security, and operational availability must always be drivers when planning, architecting and implementing any solution.  We need to acknowledge that any external or internal connectivity to any resource always comes with risk. Due to the high level of specialization within OT environments, many of the tools that an organization chooses will likely differ from those used in IT.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Technology is only one piece of the puzzle when it comes to success for any solution or project. To be successful, you must ensure that you have trained, competent people and structured battle tested processes in place to ensure that your Secure Remote Access solution meets not only your business challenges and needs, but more importantly, that it keeps your staff and facilities safe and secure.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Secure Remote Access with Kasm Workspaces","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"To support modern ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6998c69aab258d181f7df946","type":"link","fields":{"url":"https://kasm.com/secure-access","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Secure Remote Access","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" strategies in Operational Technology environments, Kasm Workspaces delivers a browser-based, Zero Trust intermediary platform that acts as a secure gateway between internal systems and external networks. By removing direct network access and rendering workspaces through the browser, Kasm Workspaces significantly reduces the attack surface and prevents malware from infiltrating internal systems, eliminating the need for risky VPN-based approaches. With built-in logging, auditing, multi-factor authentication, and seamless integration with existing identity providers, it enables secure, compliant access to applications and data from any device, while keeping sensitive resources and regulatory controls within your infrastructure. This makes Kasm Workspaces an effective solution for enforcing JIT and JEA controls, protecting critical infrastructure, and aligning remote access with Zero Trust security principles.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[{"id":"6998c721ab258d181f7df948","type":"link","fields":{"url":"https://kasm.com/get-started","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Get Started with Kasm Workspaces","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":null,"textStyle":"","textFormat":0}],"direction":"ltr"}},"relatedPosts":[{"id":5,"title":"Securing the Edge: How Kasm Workspaces Align with IoT and OT Security ","description":"The convergence of IoT (Internet of Things) and OT (Operational Technology) has brought both remarkable innovation and significant cybersecurity challenges.","heroImage":16,"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The convergence of IoT (Internet of Things) and OT (Operational Technology) has brought both remarkable innovation and significant cybersecurity challenges. As industrial systems, critical infrastructure, and edge computing environments become increasingly interconnected, the need for robust isolation, controlled access, and secure visibility has never been greater. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"This is where ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"68ef02a6a230a364718f8e40","type":"link","fields":{"url":"https://kasm.com/","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Kasm Workspaces","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" comes in—offering a modern, containerized approach to managing, monitoring, and securing applications and interfaces for OT and IoT environments without exposing critical assets. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The IoT / OT Security Challenge ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"IoT and OT systems present unique and complex security risks that differ from traditional IT environments. Some of the key challenges include: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Device diversity & legacy systems: Many devices are sourced from multiple vendors and run outdated firmware, making patching and security standardization difficult. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Network segmentation issues: Weak or nonexistent segmentation can enable lateral movement between IT and OT networks after a compromise. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Remote management vulnerabilities: IoT/OT devices often rely on exposed management interfaces or outdated remote access mechanisms. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Limited visibility & logging: Many OT systems lack centralized logging or sufficient monitoring capabilities. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Physical safety & disruption risk: A breach can lead not only to data loss but also to physical damage, downtime, or safety incidents. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Organizations operating in ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"68ef02a6a230a364718f8e41","type":"link","fields":{"url":"http://kasm.com/solutions/industries/energy-and-industrial-applications","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"industrial, energy, utilities, and smart infrastructure sectors","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" must address these challenges proactively through secure design and isolation techniques. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"What Is Kasm Workspaces? ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces is a container-based workspace and application streaming platform that enables users to securely access browser sessions, desktop applications, and development environments from any device—all streamed over the web. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Key Capabilities: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Strong isolation: Each workspace runs in its own container, with strict control over resources, network access, and policies—minimizing the blast radius of a compromise. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Granular access control and auditability: Supports role-based access, identity integration, and detailed activity logging. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Flexible deployment: Works across on-premises, hybrid, or cloud environments, and can be tailored for edge or remote sites. ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"68ef02a6a230a364718f8e42","type":"link","fields":{"url":"https://kasm.com/cloud-vs-server","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"View Cloud vs Self-Hosted.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Secure streaming: Eliminates the need for direct device or network access by delivering applications through a browser interface. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Real-World Applications ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Industrial Plant Remote Maintenance ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"Engineers can securely connect to PLCs, HMIs, or sensor networks via isolated workspaces instead of broad VPN access. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Industrial Plant Remote Maintenance ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"Engineers can securely connect to PLCs, HMIs, or sensor networks via isolated workspaces instead of broad VPN access. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Smart City / Infrastructure Monitoring ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"Use Kasm to host dashboards for municipal systems—traffic, energy, water—without local device access. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Firmware Update & Testing Sandboxes ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"Create controlled environments to test device updates or configuration changes before deployment. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Edge Deployment for Critical Systems ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"For low-latency or high-availability requirements, deploy Kasm locally at the edge to keep data within controlled networks. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Best Practices & Recommendations ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"To ensure a secure, maintainable, and effective Kasm deployment in OT/IoT environments: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Adopt a Zero Trust model: Always verify, never assume trust. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Define clear network zones and flows: Control which systems communicate and through what paths. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Harden container and host infrastructure: Keep images updated, strip unnecessary components, and monitor for vulnerabilities. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Automate auditing and alerts: Detect anomalies or misuse early. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Plan for incident response: Establish protocols to isolate and investigate compromised sessions. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":6,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Train users effectively: Operator habits—such as credential reuse or unsafe browsing—remain major risk factors. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Next Steps for Strengthening OT/IoT Security ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"As organizations expand their IoT and OT footprints, security at the edge becomes an operational imperative. Kasm Workspaces empowers teams to ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"68ef02baa230a364718f8e43","type":"link","fields":{"url":"https://kasm.com/secure-access","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"secure remote access","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":", enforce isolation, and maintain operational continuity without sacrificing flexibility. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Whether in energy, manufacturing, transportation, or smart infrastructure, adopting secure workspace delivery is a critical step toward reducing exposure while improving manageability. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"To learn more about how Kasm Workspaces can strengthen your OT/IoT security posture or to see a demo tailored to your environment, visit ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"68ef02baa230a364718f8e44","type":"link","fields":{"url":"https://www.kasm.com/","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"kasm.com","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" or contact our team. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0}],"direction":"ltr"}},"categories":[20,39,40],"meta":{"image":null,"description":"Secure IoT and OT environments with Kasm Workspaces—containerized isolation, Zero Trust access, and edge-ready application streaming."},"publishedAt":"2025-10-14T06:00:00.000Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"securing-the-edge-how-kasm-workspaces-align-with-iot-and-ot-security"}],"categories":[{"id":20,"title":"Energy & Industrial Applications","author":6,"slug":"energy--industrial-applications","slugLock":true,"updatedAt":"2025-12-29T21:14:47.581Z","createdAt":"2025-12-29T21:14:47.580Z"},{"id":40,"title":"IoT/OT","author":6,"slug":"iotot","slugLock":true,"updatedAt":"2025-12-29T21:23:35.416Z","createdAt":"2025-12-29T21:23:35.416Z"},{"id":39,"title":"Secure Remote Access","author":6,"slug":"secure-remote-access","slugLock":true,"updatedAt":"2025-12-29T21:23:22.627Z","createdAt":"2025-12-29T21:23:22.627Z"}],"meta":{"title":"Hitting the Reset Button: Secure Remote Access for Modern OT","image":{"id":44,"alt":"OT","caption":null,"author":6,"updatedAt":"2026-02-20T20:36:16.394Z","createdAt":"2026-02-20T20:36:12.753Z","url":"/api/media/file/v1.18%20Now%20Live%20(19).png","thumbnailURL":"/api/media/file/v1.18%20Now%20Live%20(19)-300x214.png","filename":"v1.18 Now Live (19).png","mimeType":"image/png","filesize":5396509,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/v1.18 Now Live (19)-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":142239,"filename":"v1.18 Now Live (19)-300x214.png"},"square":{"url":"/api/media/file/v1.18 Now Live (19)-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":513934,"filename":"v1.18 Now Live (19)-500x500.png"},"small":{"url":"/api/media/file/v1.18 Now Live (19)-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":536768,"filename":"v1.18 Now Live (19)-600x429.png"},"medium":{"url":"/api/media/file/v1.18 Now Live (19)-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":1172420,"filename":"v1.18 Now Live (19)-900x643.png"},"large":{"url":"/api/media/file/v1.18 Now Live (19)-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2802341,"filename":"v1.18 Now Live (19)-1400x1000.png"},"xlarge":{"url":"/api/media/file/v1.18 Now Live (19)-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":5107749,"filename":"v1.18 Now Live (19)-1920x1372.png"},"og":{"url":"/api/media/file/v1.18 Now Live (19)-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1618761,"filename":"v1.18 Now Live (19)-1200x630.png"}}},"description":"With attacks on critical infrastructure rising, OT Secure Remote Access must evolve. Explore best practices, compliance drivers, and Zero Trust foundations."},"publishedAt":"2026-02-20T20:44:33.309Z","authors":[7],"populatedAuthors":[{"id":7,"name":"Kevin Kumpf","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"hitting-the-reset-button-secure-remote-access-for-modern-ot","slugLock":true,"updatedAt":"2026-02-23T13:57:58.376Z","createdAt":"2026-02-20T20:22:28.272Z","_status":"published"},{"id":22,"title":"Secure Access at Mission Tempo: Modernizing NOC and SOC Operations ","description":"Traditional access models force NOC and SOC teams to trade speed for security. Learn how Kasm provides a Zero Trust–aligned access layer that protects mission systems while supporting high-tempo operations.","heroImage":{"id":42,"alt":"NOC/SOC","caption":null,"author":6,"updatedAt":"2026-02-06T21:16:40.220Z","createdAt":"2026-02-06T21:16:36.858Z","url":"/api/media/file/SOC.png","thumbnailURL":"/api/media/file/SOC-300x214.png","filename":"SOC.png","mimeType":"image/png","filesize":4338995,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/SOC-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":143713,"filename":"SOC-300x214.png"},"square":{"url":"/api/media/file/SOC-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":466177,"filename":"SOC-500x500.png"},"small":{"url":"/api/media/file/SOC-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":517529,"filename":"SOC-600x429.png"},"medium":{"url":"/api/media/file/SOC-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":1091045,"filename":"SOC-900x643.png"},"large":{"url":"/api/media/file/SOC-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2499786,"filename":"SOC-1400x1000.png"},"xlarge":{"url":"/api/media/file/SOC-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":4318768,"filename":"SOC-1920x1372.png"},"og":{"url":"/api/media/file/SOC-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1463883,"filename":"SOC-1200x630.png"}}},"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Network Operations Centers (NOC) and Security Operations Centers (SOC) are the backbone of modern military and government missions. These teams operate in high-tempo, high-stress environments where seconds matter, systems must remain available, and security failures are not an option. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Yet many NOC and SOC teams are still forced to choose between operational speed and security control. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm exists to remove that tradeoff. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The Reality of NOC and SOC Operations ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"NOC and SOC personnel are tasked with maintaining mission systems, responding to incidents, and protecting critical infrastructure, often across distributed locations and around-the-clock shifts. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Common challenges include: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Analysts requiring access to multiple tools, consoles, and data sources ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Shift-based operations with frequent personnel changes ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Contractor and surge access during incidents or exercises ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Increased reliance on remote or hybrid operations ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Persistent pressure to reduce attack surface and insider risk ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Traditional approaches like VPNs, persistent credentials, and direct endpoint access expand risk precisely when organizations can least afford it. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Why Traditional Access Models Fall Short ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Most access models were not designed for the realities of modern NOC and SOC environments. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"They often: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Grant broad network access instead of tool-level access ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Leave credentials and data resident on analyst endpoints ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Increase risk when devices are compromised ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Create administrative burden during onboarding, offboarding, or surge events ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"For military and government organizations pursuing Zero Trust, these models directly conflict with least-privilege principles. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm: A Secure Access Layer for Operations Centers ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm provides browser-based, ephemeral workspaces that allow NOC and SOC teams to access required tools without exposing the underlying network or endpoints. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"With Kasm: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Analysts connect to isolated workspaces, not directly to mission systems ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Each session is non-persistent and automatically destroyed ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"No data, credentials, or artifacts remain on the analyst device ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Access is centrally controlled, monitored, and policy-driven ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm becomes the secure control point between users and critical systems. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Supporting SOC Missions ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"For Security Operations Centers, Kasm enables: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Secure access to SIEM, SOAR, forensic, and threat intelligence platforms ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Safe malware analysis and investigation environments ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Rapid onboarding of surge analysts or contractors ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Reduced risk from compromised endpoints during investigations ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Analysts get the tools they need, while leadership maintains confidence that access remains controlled and auditable. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Supporting NOC Missions ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"For Network Operations Centers, Kasm supports: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Secure access to network management and administration consoles ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Reduced exposure of privileged credentials ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Consistent operator experience across shifts and locations ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Faster response during outages or mission-critical events ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"By removing direct endpoint connections to infrastructure, Kasm reduces risk without slowing response. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Built for Military and Government Environments ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"6986594dd3d6aa4ba63c5fa4","type":"link","fields":{"url":"https://kasm.com/solutions/industries/government-defense-and-intelligence","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Kasm is well-suited for federal and DoD use cases:","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Supports classified and unclassified architectures ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Enables role-based access for civilians, contractors, and mission partners ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Aligns with Zero Trust Architecture (ZTA) initiatives ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Reduces operational friction while strengthening security posture ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Most importantly, Kasm respects the reality of mission operations: high stress, high tempo, and no margin for error. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Security Without Slowing the Mission ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"In NOC and SOC environments, security controls must enable the mission, not become another obstacle. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm helps organizations: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Reduce attack surface ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Improve analyst efficiency ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Support distributed operations ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Maintain mission assurance under stress ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Secure access should not be the limiting factor in mission success. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"With Kasm, it doesn’t have to be. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"6986594dd3d6aa4ba63c5fa5","type":"link","fields":{"url":"https://kasm.com/solutions/industries/government-defense-and-intelligence","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about Government, Defense and Intelligence.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":"  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"6986594dd3d6aa4ba63c5fa6","type":"link","fields":{"url":"https://kasm.com/get-started","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Get Started with Kasm Workspaces.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0}],"direction":"ltr"}},"relatedPosts":[{"id":13,"title":"Modernizing Mission Workspaces: How Kasm Accelerates Government, Defense & Intelligence Transitions ","description":"Agencies are being pushed off expensive, vendor-locked Type-1 hypervisors and into cloud-capable, container-first architectures—without compromising security or control. ","heroImage":20,"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Agencies are being pushed off expensive, vendor-locked Type-1 hypervisors and into cloud-capable, container-first architectures—without compromising security or control. Kasm Workspaces is a modern orchestration engine that delivers virtual desktops, secure remote access, OSINT tradecraft, and browser isolation on next-gen platforms (Kubernetes, hyper-converged hypervisors) across on-prem, air-gapped, and cloud environments. The result: faster deployments, lower total cost of ownership, and a cleaner path to zero-trust and data-loss-prevention outcomes. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Why Agencies Are Moving Now ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"1) Leaving legacy hypervisors ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"Pricing, access restrictions, and vendor lock are forcing programs to find replacements. Leaders want out of old tech stacks and toward open standards that won’t trap them again. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"2) Next-generation infrastructure mandates ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"Teams are consolidating VM and container workloads on modern platforms. They need a workspace layer that natively understands both. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"3) Cloud-capable, web-native operations ","type":"text","style":"","detail":0,"format":0,"version":1},{"type":"linebreak","version":1},{"mode":"normal","text":"Programs want software that is browser-delivered, DevOps-automated, and can run anywhere—on-prem for control, in the cloud for agility, or both for mission dispersion. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"What Kasm Brings to the Mission ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"An orchestration engine built for the next stack ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Runs desktops, apps, and secure browsers as ephemeral, policy-controlled sessions ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Works across Kubernetes and modern hyper-converged hypervisors for VM + container parity ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Web-native delivery ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"DevOps automation at enterprise scale ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Hours, not weeks: Multi-server, multi-region deployments automated by scripts and pipelines—no six-week, five-engineer standing-up exercises. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Auto-patching and streamlined upgrades reduce maintenance windows and human error. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Infrastructure-as-code posture fits existing CI/CD controls and approval flows. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Operational flexibility without lock-in ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Host anywhere: agency data center (including air-gapped), gov cloud, or multi-cloud. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Avoid single-vendor dependencies across hypervisor, cloud, and identity stacks. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Open standards and documentation to prevent future lock-in. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"692db82e67e909628793adf0","type":"link","fields":{"url":"https://kasm.com/solutions/industries/government-defense-and-intelligence","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about how Kasm is enabling Government, Defense and Intelligence.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Core Government Use Cases ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"692db82e67e909628793adf1","type":"link","fields":{"url":"https://kasm.com/workspaces","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Virtual Desktop Infrastructure (VDI) modernization","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Replace legacy VDIs with a container-forward workspace layer. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Build workspaces on the fly and destroy them at session end to cut idle capacity and lower risk. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"692db82e67e909628793adf2","type":"link","fields":{"url":"https://kasm.com/secure-access","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Secure Remote Access (SRA)","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Grant contractors, partners, and remote staff access to specific systems via session-casted browsers—no VPN sprawl or managed laptop fleets. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Enforce granular policies: no upload/download/print; rate-limited copy/paste; strict group-based entitlements. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"692db82e67e909628793adf3","type":"link","fields":{"url":"https://kasm.com/osint","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Open-Source Intelligence (OSINT) & tradecraft","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Managed-/non-attribution browsing in isolated containers for collection and perimeter recon. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Regionalized sessions support jurisdictional and classification constraints. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Centralized logging for evidentiary and oversight needs. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"692db82e67e909628793adf4","type":"link","fields":{"url":"https://kasm.com/browser-isolation","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Remote Browser Isolation (RBI)","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Keep open-web risk off mission networks. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"If downloads are permitted, route to segregated storage—not production zones. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Security & Compliance Posture ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Zero-Trust & DLP alignment: Per-group policies and ephemeral sessions minimize data egress and lateral movement. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Operate at multiple classifications: Browser-delivered model and infrastructure flexibility support installs ranging from unclassified to higher classifications (deployment specifics remainagency-controlled). ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Attestations: Kasm maintains SOC 2 Type II for Kasm Cloud. Agencies hosting Kasm in their own environments apply their own controls and certifications. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"CMMC Level 2: Engaging with assessors; position Kasm as a tool that helps programs implement required controls when deployed within accredited environments. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Important clarity: Kasm is a platform you configure to your accreditation regime. It is not “HIPAA/GDPR/FedRAMP by itself.” Agencies use Kasm to meet those controls inside their architectures. ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"692db82e67e909628793adf5","type":"link","fields":{"url":"https://kasm.com/compliance","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about regulatory and compliance here.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":"  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Where Kasm Outperforms Legacy Approaches ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Speed to field: Multi-region orchestration in hours vs. multi-week manual builds. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Lower TCO through ephemerality: Build only what’s used; destroy at session end. Reduce idle capacity and the heavy endpoint/agent stack. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Mission resilience: Run on mixed infrastructure (modern hypervisors, Kubernetes, on-prem, cloud). No single point of vendor failure. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Operational simplicity: No device shipping or full-device trust. Browser access with strong policy controls and dual audit trails (Kasm + target systems). ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Deployment Patterns That Work ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"tag":"ol","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Pilot for a defined slice (e.g., contractor access or a single mission team). ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Harden policy per group and classification (upload/download/copy, region pinning). ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Integrate logging/SIEM and identity; map session IDs to agency identity providers. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Expand by region/classification; retire equivalent legacy access paths as coverage grows. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Standardized code: Bake Kasm deployment/updates into your CI/CD and change processes. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"number","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"A Straightforward Position on Cloud Desktops ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"If your requirement is persistent Microsoft desktops hosted in the cloud as a commodity Desktop as a Service (DaaS), Kasm likely isn’t your best fit. Where Kasm excels is self-hosted, next-gen(K8s + modern hypervisors) and container-first desktop/app/browser delivery—especially when automation, security isolation, and vendor independence are priorities. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The Bottom Line ","type":"text","style":"","detail":0,"format":1,"version":1}],"direction":"ltr","textStyle":"","textFormat":1},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Agencies need to modernize quickly without swapping one lock-in for another. Kasm gives government, defense, and intelligence programs a fast, automated path off legacy VDI and VPN models and onto secure, ephemeral, policy-driven workspaces that run anywhere the mission demands. ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"692db82e67e909628793adf6","type":"link","fields":{"url":"https://kasm.com/solutions/industries/government-defense-and-intelligence","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about how Kasm is enabling Government, Defense and Intelligence.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"692db82e67e909628793adf7","type":"link","fields":{"url":"https://kasm.com/get-started","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Get Started with Kasm Workspaces.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0}],"direction":"ltr","textFormat":1}},"categories":[25,35],"meta":{"image":null,"description":"Modernize agency VDI fast with Kasm Workspaces: container-first virtual desktops, secure remote access, OSINT and browser isolation on-prem or cloud."},"publishedAt":"2025-12-18T15:09:31.532Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"modernizing-mission-workspaces-how-kasm-accelerates-government-defense--intelligence-transitions-"}],"categories":[{"id":25,"title":"Government, Defense & Intelligence","author":6,"slug":"government-defense--intelligence","slugLock":true,"updatedAt":"2025-12-29T21:16:45.200Z","createdAt":"2025-12-29T21:16:45.200Z"},{"id":35,"title":"Web Research (OSINT)","author":6,"slug":"web-research-osint","slugLock":true,"updatedAt":"2025-12-29T21:21:54.365Z","createdAt":"2025-12-29T21:21:54.364Z"}],"meta":{"title":"Secure Access at Mission Tempo: Modernizing NOC and SOC Operations ","image":{"id":42,"alt":"NOC/SOC","caption":null,"author":6,"updatedAt":"2026-02-06T21:16:40.220Z","createdAt":"2026-02-06T21:16:36.858Z","url":"/api/media/file/SOC.png","thumbnailURL":"/api/media/file/SOC-300x214.png","filename":"SOC.png","mimeType":"image/png","filesize":4338995,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/SOC-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":143713,"filename":"SOC-300x214.png"},"square":{"url":"/api/media/file/SOC-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":466177,"filename":"SOC-500x500.png"},"small":{"url":"/api/media/file/SOC-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":517529,"filename":"SOC-600x429.png"},"medium":{"url":"/api/media/file/SOC-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":1091045,"filename":"SOC-900x643.png"},"large":{"url":"/api/media/file/SOC-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2499786,"filename":"SOC-1400x1000.png"},"xlarge":{"url":"/api/media/file/SOC-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":4318768,"filename":"SOC-1920x1372.png"},"og":{"url":"/api/media/file/SOC-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1463883,"filename":"SOC-1200x630.png"}}},"description":"NOC and SOC teams operate at mission tempo. Learn how Kasm delivers secure, ephemeral access that reduces risk without slowing critical operations."},"publishedAt":"2026-02-09T14:00:00.000Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"secure-access-at-mission-tempo-modernizing-noc-and-soc-operations","slugLock":true,"updatedAt":"2026-02-06T21:17:14.410Z","createdAt":"2026-02-06T21:12:42.804Z","_status":"published"},{"id":21,"title":"Minimizing Risk, Maximizing Control: Why Financial Firms Choose Kasm Workspaces ","description":"Financial institutions are moving beyond VPNs and device-based trust. This blog explains how Kasm Workspaces enables secure, policy-driven access to internal systems and the web—reducing risk, enforcing data sovereignty, and simplifying access for global teams, contractors, and investigators.","heroImage":{"id":41,"alt":"Kasm Financial Services","caption":null,"author":6,"updatedAt":"2026-02-06T21:10:20.574Z","createdAt":"2026-02-06T21:10:17.465Z","url":"/api/media/file/Kasm%20Financial%20Services.png","thumbnailURL":"/api/media/file/Kasm%20Financial%20Services-300x214.png","filename":"Kasm Financial Services.png","mimeType":"image/png","filesize":4241687,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Kasm Financial Services-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":130554,"filename":"Kasm Financial Services-300x214.png"},"square":{"url":"/api/media/file/Kasm Financial Services-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":453020,"filename":"Kasm Financial Services-500x500.png"},"small":{"url":"/api/media/file/Kasm Financial Services-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":468709,"filename":"Kasm Financial Services-600x429.png"},"medium":{"url":"/api/media/file/Kasm Financial Services-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":1008929,"filename":"Kasm Financial Services-900x643.png"},"large":{"url":"/api/media/file/Kasm Financial Services-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2402112,"filename":"Kasm Financial Services-1400x1000.png"},"xlarge":{"url":"/api/media/file/Kasm Financial Services-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":4201823,"filename":"Kasm Financial Services-1920x1372.png"},"og":{"url":"/api/media/file/Kasm Financial Services-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1451926,"filename":"Kasm Financial Services-1200x630.png"}}},"content":{"root":{"type":"root","format":"","indent":0,"version":1,"children":[{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Financial institutions are rethinking how employees, contractors, and partners access sensitive systems. The drivers aren’t vanity “modernization” projects; they are board-level security concerns, data-sovereignty mandates, and the spiraling cost/complexity of legacy VPN-based access. Kasm Workspaces gives banks and FinTechs a secure, policy-driven alternative: session-casted, containerized access to internal resources and the public web that dramatically reduces data-exfiltration routes, simplifies oversight, and scales to global teams without shipping laptops or managing agents. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"The Business Problem: VPNs, Agents, and an Expanding Attack Surface ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Traditional remote access models were built around devices, not data. To enable remote workers and third-party consultants, firms ship laptops, install endpoint agents, and tunnel everything through VPN concentrators. This approach is: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Expensive: Hardware procurement, logistics, and ongoing endpoint management add up quickly, especially across multiple countries. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Operationally brittle: Every endpoint becomes an exception to manage (patching, certificates, policies, break/fix). ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Risk-prone: VPNs expose flat network pathways; once compromised, they provide lateral movement opportunities. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Non-sovereign by default: Global teams often cross borders; keeping data resident where laws require (e.g., UK/EU GDPR) is difficult when devices transit data. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"CISOs and CTOs want something different: least-privilege, auditable access that never lets sensitive data land on uncontrolled endpoints, and that can be tied cleanly to geo, role, and policy. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm’s Model: Session-Casted Access, Not Device Trust ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Kasm Workspaces replaces device trust with ephemeral, containerized sessions that render applications and web content to the user’s browser while keeping data inside the firm’s controlled environment. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"What changes for you: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"No data on the endpoint. Sessions are containerized; nothing persistent touches personal machines. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Policy first. Per-group rules (e.g., contractors in Frankfurt, analysts in London) define whether users can upload, download, print, or copy/paste, and to what extent, including character-rate limits. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"True data sovereignty. Run Kasm in-country (on your cloud or on-prem). UK data stays in the UK; EU data stays in the EU. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Complete visibility. Access events are logged by Kasm and by your downstream apps (e.g., SharePoint, CRM, case systems), giving security teams dual audit trails. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":5,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Simple onboarding. No device shipping. No endpoint agents. Authenticate to a Kasm landing page and launch only the tiles you’re entitled to. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Three High-Value Financial Services Use Cases ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"1) Secure Remote Access (Contractors, Subcontractors, Remote Employees) ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Enable external users to reach specific internal systems through session-casted browsers without VPNs, managed laptops, or broad network exposure. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Outcome for the business: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Lower operating costs by eliminating device logistics. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Reduced the likelihood of a breach by removing VPN trust assumptions. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Faster onboarding/offboarding with role-based tiles and concurrent session licensing. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Illustrative deployments: Global banks using Kasm to give non-employees access to SharePoint and line-of-business apps from abroad while enforcing strict no-download policies and country-locked residency. ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6986579ed3d6aa4ba63c5f95","type":"link","fields":{"url":"https://kasm.com/secure-access","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about Kasm for Secure Remote Access.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"2) Threat Intelligence & Financial Crimes (OSINT with Managed/Non-Attribution) ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Cyber and fraud teams need to investigate the open, deep, and dark web safely and view the bank’s perimeter “from the outside in.” ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Outcome for the business: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Investigators operate in isolated, disposable sessions that mask attribution. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Reduced risk of tooling exposure and cross-contamination with production networks. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Centralized logging/audit to satisfy internal controls and regulators. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Illustrative deployments: Financial institutions running Kasm for OSINT and attack-surface reconnaissance, with sessions spun up in designated regions (e.g., EU) to maintain jurisdictional control. ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6986579ed3d6aa4ba63c5f96","type":"link","fields":{"url":"https://kasm.com/osint","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about Kasm for OSINT.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":"  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"3) Remote Browser Isolation for Safe Internet Research ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Keep day-to-day browsing off the production network. Route research traffic through Kasm’s containerized Chrome/Edge sessions, not your standard corporate browser path. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Outcome for the business: ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Malware and drive-by downloads are contained in disposable sessions. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"If downloads are permitted, they land in segregated storage, never the production estate. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Security teams define granular rules by department (research, relationship management, customer service). ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Illustrative deployments: Regional banks running Kasm Cloud for RBI to further segregate risk away from internal datacenters while retaining strict policy control and auditability. ","type":"text","style":"","detail":0,"format":0,"version":1},{"id":"6986579ed3d6aa4ba63c5f97","type":"link","fields":{"url":"https://kasm.com/browser-isolation","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about Kasm for Browser Isolation.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"mode":"normal","text":"Why Firms Select Kasm Over “Bigger Names” ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr","textStyle":"","textFormat":0},{"tag":"ul","type":"list","start":1,"format":"start","indent":0,"version":1,"children":[{"type":"listitem","value":1,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Security substance, not sizzle: Eliminates VPN-centric risk, shrinks exfil paths, provides dual logging. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":2,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Operational simplicity: No hardware to ship. No agent sprawl. Hours, not weeks to onboard a new vendor team. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":3,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Cost discipline: Pay for concurrent use, not a laptop fleet. Reduce complexity in support and patching. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"type":"listitem","value":4,"format":"","indent":0,"version":1,"children":[{"mode":"normal","text":"Credibility and transparency: Extensive documentation and how-to guides for integrating firewalls, forward proxies, vulnerability scanning, and SIEM pipelines. ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"}],"listType":"bullet","direction":"ltr"},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"6986579ed3d6aa4ba63c5f98","type":"link","fields":{"url":"https://kasm.com/solutions/industries/financial-services","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Learn more about Kasm for Financial Services.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":"  ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0},{"type":"paragraph","format":"left","indent":0,"version":1,"children":[{"id":"6986579ed3d6aa4ba63c5f99","type":"link","fields":{"url":"https://kasm.com/get-started","newTab":true,"linkType":"custom"},"format":"","indent":0,"version":3,"children":[{"mode":"normal","text":"Get Started with Kasm Workspaces.","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":"ltr"},{"mode":"normal","text":" ","type":"text","style":"","detail":0,"format":0,"version":1}],"direction":null,"textStyle":"","textFormat":0}],"direction":"ltr"}},"relatedPosts":[],"categories":[{"id":22,"title":"Financial Services","author":6,"slug":"financial-services","slugLock":true,"updatedAt":"2025-12-29T21:15:47.352Z","createdAt":"2025-12-29T21:15:47.348Z"},{"id":35,"title":"Web Research (OSINT)","author":6,"slug":"web-research-osint","slugLock":true,"updatedAt":"2025-12-29T21:21:54.365Z","createdAt":"2025-12-29T21:21:54.364Z"},{"id":34,"title":"Remote Browser Isolation","author":6,"slug":"remote-browser-isolation","slugLock":true,"updatedAt":"2025-12-29T21:21:31.943Z","createdAt":"2025-12-29T21:21:18.532Z"},{"id":39,"title":"Secure Remote Access","author":6,"slug":"secure-remote-access","slugLock":true,"updatedAt":"2025-12-29T21:23:22.627Z","createdAt":"2025-12-29T21:23:22.627Z"}],"meta":{"title":"Minimizing Risk, Maximizing Control: Why Financial Firms Choose Kasm Workspaces ","image":{"id":41,"alt":"Kasm Financial Services","caption":null,"author":6,"updatedAt":"2026-02-06T21:10:20.574Z","createdAt":"2026-02-06T21:10:17.465Z","url":"/api/media/file/Kasm%20Financial%20Services.png","thumbnailURL":"/api/media/file/Kasm%20Financial%20Services-300x214.png","filename":"Kasm Financial Services.png","mimeType":"image/png","filesize":4241687,"width":2000,"height":1429,"focalX":50,"focalY":50,"sizes":{"thumbnail":{"url":"/api/media/file/Kasm Financial Services-300x214.png","width":300,"height":214,"mimeType":"image/png","filesize":130554,"filename":"Kasm Financial Services-300x214.png"},"square":{"url":"/api/media/file/Kasm Financial Services-500x500.png","width":500,"height":500,"mimeType":"image/png","filesize":453020,"filename":"Kasm Financial Services-500x500.png"},"small":{"url":"/api/media/file/Kasm Financial Services-600x429.png","width":600,"height":429,"mimeType":"image/png","filesize":468709,"filename":"Kasm Financial Services-600x429.png"},"medium":{"url":"/api/media/file/Kasm Financial Services-900x643.png","width":900,"height":643,"mimeType":"image/png","filesize":1008929,"filename":"Kasm Financial Services-900x643.png"},"large":{"url":"/api/media/file/Kasm Financial Services-1400x1000.png","width":1400,"height":1000,"mimeType":"image/png","filesize":2402112,"filename":"Kasm Financial Services-1400x1000.png"},"xlarge":{"url":"/api/media/file/Kasm Financial Services-1920x1372.png","width":1920,"height":1372,"mimeType":"image/png","filesize":4201823,"filename":"Kasm Financial Services-1920x1372.png"},"og":{"url":"/api/media/file/Kasm Financial Services-1200x630.png","width":1200,"height":630,"mimeType":"image/png","filesize":1451926,"filename":"Kasm Financial Services-1200x630.png"}}},"description":"Financial firms are moving beyond VPNs. Learn how Kasm Workspaces reduces risk, enforces data sovereignty, and delivers secure, policy-driven access."},"publishedAt":"2026-02-06T21:10:36.146Z","authors":[6],"populatedAuthors":[{"id":6,"name":"Jessica Banerjee","image":"/api/media/file/Kasm_Logo_Final.png"}],"slug":"minimizing-risk-maximizing-control-why-financial-firms-choose-kasm-workspaces","slugLock":true,"updatedAt":"2026-02-06T21:10:36.149Z","createdAt":"2026-02-06T20:59:51.782Z","_status":"published"}],"hasNextPage":true,"hasPrevPage":false,"limit":10,"nextPage":2,"page":1,"pagingCounter":1,"prevPage":null,"totalDocs":22,"totalPages":3}