Citrix is capable and entrenched, which is why the per-user bill is so hard to swallow when Cloud Software Group raises it. The instinct is to look for a single product that replaces Citrix DaaS or Virtual Apps and Desktops outright. That product does not exist in open source, and chasing it leads to disappointment. What does exist is a set of open tools that each cover part of what Citrix does, and the smart move is to match them to your actual use cases rather than to Citrix’s feature list.
Start with what your users really do
Citrix estates usually serve a mix: some users just need secure access to a handful of published Windows apps or a shared session host, while others depend on persistent, customized desktops with layered applications and profile management. Those two groups have very different replacement paths. Sort your users this way before you evaluate anything, because it determines whether the migration is straightforward or genuinely involved.
Two open directions, for two kinds of users
Apache Guacamole is a clientless HTML5 gateway to RDP, VNC, and SSH. It gives users browser access to desktops and session hosts you already run, with single sign-on and MFA enforced at the gateway. It is not a desktop broker: it will not provision pools, manage images, or layer apps. For the large share of users whose real need is “reach my existing Windows session host securely from anywhere,” it is a clean, low-cost replacement for the Citrix access layer.
Kasm Workspaces takes a different tack, streaming containerized apps and desktops to the browser. Because it provisions ephemeral workspaces from images, it maps well onto published-app delivery and non-persistent desktops, and it adds browser isolation as a bonus. It is container streaming rather than a traditional persistent-VDI broker, so it fits some Citrix workloads squarely and others not at all.
Be realistic about the gap
For image lifecycle, instant provisioning of large persistent-desktop pools, or GPU-accelerated CAD workstations, the open tools cover part of the ground and you will keep some of that machinery on your hypervisor or accept a change in model. The honest framing is that a Citrix exit is usually a phased, use-case-by-use-case migration, not a single swap, and the savings are realized as each group moves. Pilot one low-risk group end to end, wire SSO and MFA, validate printing, USB, and multi-monitor behavior, then widen. Each path below opens to a full cost model, a plan, and an in-depth guide.