

Kasm Workspaces
By Kasm Technologies.
Ensure server requirements are met (e.g., minimum 2 CPU cores, 4GB RAM, 50GB SSD) and Docker is installed.
Use the provided URL to download the latest Kasm Workspaces release package.
Extract the downloaded package and run the installation script using a single command.
Review and accept the End User License Agreement (EULA) during installation.
Configure server settings, including ports, SSL certificates, and workspace customization (e.g., CPU/memory allocation).
Test the installation to ensure proper functionality and optimize settings for performance.
Set up user accounts, roles, and permissions for workspace access.
Create and customize workspaces by selecting Docker images from the registry and defining resource allocations.
Access the platform through a web browser using admin credentials to finalize configurations.
.
Kasm Workspaces is highly customizable to fit specific business needs. Below are the key data points highlighting its flexibility:
Custom Docker Images: Administrators can create and deploy custom Docker images tailored to their requirements, allowing the addition of specific tools, configurations, and branding.
Workspace Customization: Businesses can define workspace settings such as CPU/memory allocations, session timeouts, and persistent storage paths for optimal performance.
Tailored Applications: Organizations can securely host legacy applications or specific software within isolated containers, ensuring compatibility while maintaining security.
Integration with Existing Systems: Kasm Workspaces supports integration with enterprise systems like SAML IdPs (Azure AD, Okta), backend infrastructure, and internal company portals for seamless workflows.
Custom Security Policies: Administrators can enforce granular control over uploads, downloads, clipboard usage, USB devices, and browsing restrictions to meet compliance and security requirements.
Developer API: The robust API enables businesses to integrate Kasm Workspaces into their existing workflows and develop custom solutions at scale.
Custom Branding: Businesses can brand their Linux desktop containers and workspaces with tailored designs and configurations to align with their corporate identity.
Flexible Deployment Options: Kasm Workspaces can be deployed on-premises, in private/public clouds, or in hybrid configurations to suit specific infrastructure needs.
Workflow Automation: Automated deployment pipelines using Docker simplify the creation and management of customized workspaces while reducing errors and improving efficiency.
Custom Images Repository: Organizations can always maintain up-to-date images that automatically deploy updates without downtime.
Regulatory Compliance Support: Features like centralized management and secure data handling make it easy for businesses to meet industry-specific compliance requirements (e.g., GDPR, HIPAA).
Custom Browser Isolation Settings: Businesses can configure browser isolation policies to filter traffic using whitelists/blacklists and safe-search options.
Session Management: Administrators can choose between persistent sessions (retaining user settings/documents) or resettable sessions for enhanced security.
Custom Streaming Quality: Streaming settings can be adjusted for optimal performance based on user needs or device capabilities.
Advanced Networking Configurations: Features like network segmentation and VPN egress customization allow businesses to tailor remote access policies securely.
Collaboration Tools Customization: Integrated chat systems and screen-sharing capabilities can be configured to enhance team collaboration within secured environments.
Customizable Resource Allocation: Businesses can allocate resources dynamically based on workload demands, ensuring efficient use of infrastructure during peak times.
Custom Development Environments: Developers can create isolated environments with specific programming tools (e.g., Python, Rust) for testing or project separation.
Custom Monitoring Tools Integration: Comprehensive logging and monitoring tools can be integrated to track usage and performance metrics effectively.
Kasm Workspaces provides robust training and support options to assist new users in effectively utilizing the platform. Below are the key offerings:
User guides are available to walk users through features like browser isolation, file sharing, clipboard usage, and workspace sessions
.
Detailed video tutorials cover topics such as launching workspaces, customizing settings, and troubleshooting common issues.
An in-depth course focuses on advanced topics like API integration, building custom workspace images, and troubleshooting failed containers.
Access to installation guides, administration guides, FAQs, and deployment sizing resources for self-paced learning.
A free version is available for testing and learning the platform without cost before scaling up to paid tiers.
Customer Success Services:
Dedicated support for deployment customization and performance optimization through Standard, Premium, or Enterprise contracts
Self-Service Tools:
Password reset tools, community support forums, and troubleshooting resources are available for immediate fixes.
Ticket Submission:
Users can submit detailed tickets for technical issues, including screenshots and log files for faster resolution.
Responsive Support Team:
Verified reviews praise the support team for being knowledgeable, responsive, and proactive in solving business challenges.
.
Knowledge Base:
Kasm Workspaces employs comprehensive security features to protect data and ensure safe operations. Below are the key measures:
Assumes no implicit trust, verifying every request as if it originates from an open network.
Uses containerized browsers that isolate web activity, preventing malware, phishing, and ransomware from reaching endpoints.
Controls for clipboard usage, file uploads/downloads, and USB device access to prevent unauthorized data transfers.
Includes text and image watermarking for RDP sessions.
Each session is isolated and destroyed after use, ensuring no residual data or malware persists across sessions.
.
Acts as a secure bastion host, isolating internal networks from direct attacks by rendering workspaces externally.
Encrypts data in transit and at rest to prevent unauthorized access or interception during remote sessions.
Integrates with identity providers to enforce MFA for secure access to applications and data.
Nightly pipelines ensure all components are patched with the latest security updates to mitigate vulnerabilities.
Each workspace runs in a Docker container with kernel-level isolation using technologies like SELinux and AppArmor.
Administrators can define whitelists/blacklists for web access within containerized sessions.
Automatically restarts containers upon process failure, eliminating memory-resident malware while preserving disk-based work.
Update Frequency:
Static Releases: Kasm Workspaces publishes new versions periodically, incorporating new features and security updates. These updates are tagged with specific versions (e.g., kasmweb/ubuntu-focal-desktop:1.16.1) and are static, meaning they are not updated further after release.
Rolling Updates: Daily and weekly rolling updates are available for workspace images (e.g., rolling-daily and rolling-weekly tags). These updates ensure continuous improvements in security and functionality, making them ideal for environments requiring frequent updates.
Update Management:
Workspace Registry:
Administrators can utilize the Kasm Workspaces Registry to pull updated workspace images compatible with the installed version.
Old workspace images should be removed to avoid compatibility issues.
Custom Workspace Updates:
Custom workspaces can be rebuilt using appropriately tagged Docker images to ensure compatibility with the latest release.
Staging environments can be created for testing new image updates before deploying them in production, minimizing the risk of disruptions.
Upgrade Scripts:
Automated upgrade scripts are included with installation packages to simplify the update process for both single-server and multi-server deployments.
Manual Updates:
Administrators may manually update workspace configurations, including image tags, to align with newer versions. Mass updates require manual intervention due to potential backward compatibility issues.
Maintenance Windows:
Kasm Workspaces provides flexibility and control over data ownership and portability, with the following key points:
Data Ownership:
Organizations retain ownership of their data hosted within Kasm Workspaces environments. The platform does not claim ownership of user or organizational data stored or processed within its containerized workspaces.
Persistent Data Management:
Administrators can configure persistent volume mappings to ensure data continuity across sessions. This allows users to access shared directories or host-mounted folders securely, ensuring organizational control over stored files.
Data Portability:
Kasm supports the use of shared storage solutions (e.g., NFS, SMB) for multi-server deployments, enabling seamless data portability across distributed environments.
Users can export session data or transfer files securely, adhering to organizational policies and compliance requirements.
Compliance with Regulations:
The platform meets stringent compliance standards such as SOC 2, HIPAA, and DoD RMF, ensuring secure handling of sensitive data while maintaining portability for regulatory needs.
Session-Based Data Isolation:
Kasm Workspaces provides flexible scaling options to adapt to organizational needs. Below are the key terms and features related to scaling:
Dynamic Provisioning:
Automatically provisions virtual machines (VMs) or Docker agents based on real-time user demand or predefined schedules.
Resource Optimization:
Ensures optimal resource utilization by scaling up when demand increases and scaling down when sessions end, minimizing compute costs.
Hot Spare Resources:
Maintains hot spare compute resources to support on-demand sessions, ensuring availability during peak usage.
Predefined Scheduling:
Administrators can configure active periods for AutoScaling, such as business hours or overnight schedules, to optimize costs.
Cloud Provider Support:
Supports AutoScaling across multiple cloud providers, including AWS, Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI), and Digital Ocean.
Custom Scaling Strategies:
Administrators can select VM instance sizes to accommodate single or multiple sessions per agent, balancing performance and cost savings.
Manual Adjustments:
Scaling configurations can be manually adjusted via the infrastructure menu to meet specific organizational requirements.
Session-Based Scaling:
Servers with active sessions are not scaled down to ensure uninterrupted user access.
Distributed Architecture Support:
Allows scaling across separate API, database, and agent components for distributed deployments.
Community Edition:
Contracts are set to auto-renew unless explicitly canceled by the user before the renewal deadline.
Notice Period for Non-Renewal:
For annual plans, a non-renewal notice must be provided at least 30 days before the renewal date.
For monthly plans, notice must be given at least 48 hours before the renewal date.
Renewal Notifications:
Users are notified in advance of upcoming renewals, including details about charges and deadlines for cancellation.
Flexibility in Adjustments:
During the renewal process, organizations can renegotiate terms or adjust their plans to better align with their evolving needs.
Users can cancel their subscription via the "Plan & Billing" tab on the billing page by selecting "Cancel auto-renew" and confirming their choice.
Transfer of Ownership:
If canceling due to a job change, users can transfer their subscription plan and workspace ownership to a colleague through a guided process.
Refund Policy:
Refunds may be issued if cancellation occurs within specific warranty periods or under certain conditions outlined in the End User License Agreement (EULA).
Immediate Termination by Kasm:
Kasm Technologies reserves the right to terminate contracts immediately in cases of non-payment, breach of terms, insolvency, or bankruptcy.
Effect of Cancellation:
Upon cancellation or termination, all licensed rights cease immediately, and users must stop using the software and destroy all related files, including license keys.
Subscription Transfer Options:
Kasm Workspaces adheres to several industry and federal compliance standards to ensure secure operations and data handling. Below are the key compliance frameworks supported:
Kasm integrates SOC 2 Type II controls into its Cloud Teams and Enterprise editions, providing high assurance for data security, availability, processing integrity, confidentiality, and privacy.
The platform supports HIPAA compliance, enabling secure remote access to medical information while protecting against data loss or compromise.
Kasm meets the National Institute of Standards and Technology (NIST) 800-53 controls for security and privacy, ensuring robust protection for sensitive government data.
The software is hardened to meet stringent DoD RMF guidelines for security within U.S. Department of Defense environments.
Kasm supports configurations aligned with FedRAMP requirements, ensuring secure cloud-based operations for federal agencies.
The platform complies with FISMA standards for securing federal information systems.
DISA-STIG compliance is supported through recommended operating systems like Ubuntu 20.04 LTS with FIPS enforcement.
Kasm ensures compliance with GDPR standards for data protection and privacy in European Union jurisdictions.