Citrix Secure Developer Spaces™

Configure AI Gateway routing in Citrix Secure Developer Spaces™

You can route selected AI service traffic from SDS workspaces through an internal AI Gateway by configuring Helm values. Use this option when your organization wants centralized routing or policy control for AI provider endpoints.

Prerequisites

  • An internal AI Gateway service that is reachable from the SDS proxy pods
  • The DNS endpoint names that must be routed through the AI Gateway
  • Access to update the SDS Helm values and run helm upgrade

Configure platform-wide AI Gateway routing

Add the platform.aiGateway block to your Helm values:

platform:
  aiGateway:
    address: "envoy-default-envoy-ai-gateway-07856df5.envoy-gateway-system.svc.cluster.local"
    dnsEndpoints:
      - "api.business.githubcopilot.com."
      - "copilot-proxy.githubusercontent.com."
      - "api.openai.com."
      - "chat.openai.com."
      - "chatgpt.com."
      - "api.anthropic.com."
      - "claude.ai."
      - "generativelanguage.googleapis.com."
      - "gemini.google.com."
      - "bard.google.com."
<!--NeedCopy-->

The address value is the internal service address for the AI Gateway. The dnsEndpoints list defines the AI provider domains that SDS intercepts and routes through that gateway.

Override AI Gateway routing for a region

For an external region, add region.aiGateway to override the platform-wide settings:

region:
  isExternalRegion: true
  aiGateway:
    address: "ai-gateway.region.example.svc.cluster.local"
    dnsEndpoints:
      - "api.openai.com."
      - "api.anthropic.com."
<!--NeedCopy-->

The regional values apply only to that region. If you omit region.aiGateway, the region uses the platform-wide platform.aiGateway configuration.

Apply the configuration

  1. Update your SDS Helm values file.
  2. Run your standard helm upgrade command.
  3. Restart any affected workspace sessions if you need existing connections to use the new routing.

After the upgrade, SDS routes requests for the configured DNS endpoints through the configured AI Gateway address.

Configure AI Gateway routing in Citrix Secure Developer Spaces™