The Anka product ladder: Develop, Flow, Build, and EC2 Mac as four ascending steps, with Crypt, MCP, Anka Scan, and AMI Scan named below

Which Anka Product Do You Actually Need? A Walkthrough of the Whole Lineup

Nobody shows up at a virtualization vendor wanting to read a product catalog. They show up because a laptop needs a clean macOS for tonight’s build, or because four developers have a need for four different Xcode installs, or because a security reviewer wants to know what is inside the CI image.

So we’ll break down the Veertu lineup in that order. Situation first, product second.

The full lineup

From veertu.com:

ProductOne-line description
Anka BuildOn-demand ephemeral macOS VMs on Mac cluster for enterprise iOS and macOS CI
Anka DevelopFree local macOS VMs for personal development and testing
Anka FlowReusable iOS development VMs shared across a team
AWS EC2 MacEphemeral macOS VMs on EC2 Mac instances
Anka CryptRun AI coding agents unattended in disposable macOS VMs
Anka MCPMCP server that hands AI agents Anka macOS VMs
Anka ScanCVE scanning for macOS VM images and templates
EC2 Mac AMI ScanScan EC2 Mac AMIs without launching an instance

You are one developer on a MacBook

Anka Develop is the free Anka Virtualization license for laptop hardware: MacBook, MacBook Pro, MacBook Air. You get a sandboxed guest for builds, tests, or throwaway experiments without standing up a farm.

One VM at a time; no VM suspension, no tagging, no registry CLI; and the license activates only on those laptop models.

If you are using a coding agent, you can use Anka Crypt alongside Anka Develop to run the coding agent inside an isolated macOS VM from your host.

Anka Develop supports VNC, SSH, and Anka View (if VNC is not available) for accessing the VM.

Your team shares the same iOS/macOS environment

Anka Flow licenses are for creating and working inside Anka macOS VMs on developer machines, with registry push and pull so a prepared VM is not trapped on one laptop and can instead be shared with your entire team.

Flow activates on MacBook and iMac models, a narrower hardware set than Build covers. Against Develop it adds multiple VMs, suspend (Intel path), USB support, and registry push and pull. What it will not do is join the machine to an Anka Build Cloud as a Node.

You outgrow Flow when commit volume and concurrency need a central queue of ephemeral CI VMs on dedicated or cloud Mac hosts, rather than VMs running across laptops.

You need an enterprise CI fleet

Anka Build is the Controller, Registry, and Node model. Mac hosts run Anka Virtualization as Build Nodes and cache templates and tags frequently used. The Controller queues and load-balances VM requests across them. The Registry stores Templates and Tags, allowing Nodes to pull them when needed. Plugins cover GitHub Actions, Jenkins, TeamCity, GitLab custom executor, Buildkite, and others; the license tiers datasheet carries the full feature list.

Build licenses run on all macOS hardware models, unlike laptop-only Develop and the MacBook and iMac set Flow covers. Build is also the license that joins nodes to a Cloud Controller.

Its tiers (Basic, Enterprise, Enterprise Plus) add controller auth, node groups, priority scheduling, SSO, authentication/authorization, and event logging. The tier decision is inside Build, rather than a different product, so read Build License Tiers when security or multi-team isolation enters the conversation.

You extend past Build when the Macs you want live in AWS instead of on-prem, or when security asks for CVE evidence on the images themselves.

Your Macs are in AWS

You can run either community (bring your own license) or marketplace EC2 Mac AMIs with Anka macOS Virtualization on them. Marketplace EC2 Mac AMIs with Anka in them mirror the AWS consumption model. You only pay when your instance is running. Run several macOS VMs per EC2 Mac host, pack denser CI onto instances you already pay for, and version the guest images (Packer and Ansible friendly) instead of baking every tool into the AMI. Anka on AWS EC2 Mac also avoids waiting for dedicated hosts to be released or switch to Available, which can take hours sometimes because of limited hardware availability and demand in AWS! Orchestration lines up with the same CI tools you use for Build.

Using EC2 Mac does not mean abandoning Build or Flow. You place Anka nodes on EC2 Mac hardware when that is where capacity lives.

You want AI coding agents in disposable macOS VMs

Two products show up together here.

Anka Crypt runs AI coding agents unattended in disposable macOS VMs, so an agent such as Claude or Codex are not working on your personal desktop. Anka MCP is an MCP server that lets agent clients request and manage those Anka VMs through local CLI or Controller APIs.

Reach for Crypt when the question is how much damage an agent can do. Reach for MCP when the agent tooling has to provision the VM itself. Crypt runs on Develop’s free local VMs; Build and Flow start to matter once agents need the Controller.

Security asks what is in the image

Anka Scan scans Anka macOS images and templates at rest, Intel and ARM guests alike, and reports a BOM against known CVEs. It runs inside your network, so the image never has to leave. The usual moment is just before a template goes to the Registry, or on a schedule against templates already stored there.

EC2 Mac AMI Scan covers a different artifact. When your pipeline’s source of truth is an AMI rather than an Anka template, it inspects that AMI filesystem without booting an instance from it. Use it in AMI build pipelines and recurring scans, and use Anka Scan when the artifact is an Anka VM image or template.

The decision path

  1. Solo laptop CI or local sandbox? → Anka Develop
  2. Team-shared dev VMs plus a registry, still on desks? → Anka Flow
  3. Queued ephemeral CI VMs across Mac hosts? → Anka Build
  4. Those hosts are EC2 Mac? → AWS EC2 Mac with Anka packing and orchestration
  5. Unattended coding agents need a disposable macOS? → Anka Crypt, plus Anka MCP if the agent stack speaks MCP
  6. CVE evidence on Anka templates? → Anka Scan
  7. CVE evidence on EC2 Mac AMIs without booting them? → EC2 Mac AMI Scan

License boundaries

From Licensing and the feature matrices:

DevelopFlowBuild
Multiple VMsNoYesYes
Registry push/pullNoYesYes
Join as Build Cloud NodeNoNoYes
HardwareMacBook models onlyMacBook and iMacAll macOS hardware models

Trials come from Veertu’s trial registration flow. The commercial Build tiers change Controller features, not the answer to which product family you need.

When not to climb the ladder

Stay on Develop if one local VM covers the job. Stay on Flow if the pain is shared desktop environments rather than CI concurrency. Add a Scan product when a person or an auditor asks for CVE data, and remember it does not replace Build. Add Crypt or MCP when agents become a new untrusted tenant, not because every CI farm needs them on day one.

Share this post

For Tart users looking ahead, Veertu's Anka product is still here
You may or may not have heard that the Cirrus Labs team behind Tart is shutting down Cirrus CI and abandoning Tart itself. They indicate Tart will be relicensed under a more permissive license as part of that transition, but from our experience that’s...
Read More
Screenshot 2025-01-08 at 2.16
Enterprise macOS GitHub Actions Runners with Anka
In the dynamic world of software development, a streamlined Continuous Integration (CI) pipeline is the backbone of enterprises delivering reliable and efficient products. For macOS environments, the challenges of setting up and maintaining automation...
Read More
anka2024v1-1536x768
A Year of Anka: Highlights from 2024
We’re starting a new annual tradition here at Veertu with our A Year of Anka blog posts. We want our customers to know how the product has grown over the past year and think this is a great avenue to do so. Please enjoy and happy holidays from all...
Read More
anka-or-1
Anka vs Orka in 2024
It has been several years since we made our first side by side comparison between Anka and Orka. A lot has changed, and we believe it’s important to make sure the information out there is accurate. We’ll be specifically addressing a newer...
Read More
networking-performancev1
Unlocking Superior macOS VM Network Performance: Introducing Anka's new networking mode for Apple Silicon
Large and complex enterprises using Anka have many different demands, and we have worked to continue to develop innovative technology to meet these demands. Enterprise infrastructure hardware is often on the cutting edge, and they need advanced capabilities...
Read More
gitlab-with-anka
Anka Cloud Gitlab Executor
Veertu’s Anka and the new Anka Cloud Gitlab Executor Veertu’s Anka is a suite of software tools built on the macOS virtualization platform. It enables the execution of single or multi-use macOS virtual machines (VMs) in a manner similar to Docker....
Read More
mac-scan-v1
Real-Time CVE Scanning of your macOS Build Systems
It’s common that an organization’s macOS build system will download thousands, sometimes tens of thousands of third-party dependencies every hour. When building and testing iOS applications, it typically downloads and installs third-party...
Read More
anka-on-silicon-v1
The ONLY Fully Automated Apple Silicon macOS VM Creation Solution
Starting in Anka 3.1 we announced that Anka is now able to fully automate the macOS installation processes, disabling SIP, and enabling VNC — all previously manual steps users had to perform inside o the VM. At the time of writing this article,...
Read More
anka_click
Scripting macOS UI User Actions With Anka Click
Starting in Anka 3.2, we’ve introduced a solution for scripting macOS UI user actions. You may ask, “Why would I want to do that?”. Well, often macOS configuration and applications do not have a CLI allowing you to perform certain actions...
Read More
mac-scan-fullscan-shells-v3
Real-time, continuous scan of file downloads on macOS for security vulnerabilities
Today, we are announcing the Beta availability of the Mac Scan solution. Mac Scan software runs on macOS systems (bare metal, virtual, EC2 Mac) and scans downloads in real time for security vulnerabilities. There are multiple scenarios why you would...
Read More