Codex
Codex Cloud can reach your tailnet through Tailscale: tag the auth key before you connect it
Codex Cloud environments can now join your Tailscale network with a reusable, ephemeral auth key. Tag the key so cloud task VMs only reach the services you allow.
What changed
Codex Cloud environments now have a private-network option, and Tailscale is the only supported VPN provider for now. Once you add a Tailscale auth key to an environment, every cloud task VM joins your tailnet and can call internal APIs, package registries, staging services, and other HTTP or HTTPS services on your private network. Tailscale announced it on X and wrote on its blog that OpenAI built it on standard Tailscale, with no partnership or custom API.
The catch is access. Tailscale's own post warns that with default tailnet rules, a Codex VM can reach nearly everything on the network, and @vermaizer's reply sums up the practical fix: tag the auth key.
Who is affected
ChatGPT Plus and higher users who have Codex Cloud (it is still rolling out) and want cloud tasks to reach private services. Teams whose tailnet still uses the default allow-all access rules are the most exposed.
What to do now
- In the cloud environment, open Advanced, then VPN, and add Tailscale.
- In the Tailscale admin console, generate an auth key with both Reusable and Ephemeral turned on. OpenAI requires both: reusable lets each new task VM join, and ephemeral removes the VM after it goes offline.
- Add a tag to that key, such as
tag:codex, so Codex VMs pick up rules written for that tag instead of the access of whoever created the key. - Write grants that let
tag:codexreach only the services the task needs, and keep an expiry on the key. - Allow each destination in both the environment's internet-access settings and your Tailscale rules, then republish the environment and test from a new task. When testing with
curl, use the environment's configured proxy. - Plan for HTTP and HTTPS. Other TCP goes over HTTP CONNECT through
proxy:8088. UDP, ICMP, SSH, Tailscale SSH, and inbound connections to the Codex node do not work.
What is not confirmed
The two sources disagree on DNS. OpenAI's cloud environments doc says tasks can use MagicDNS and split DNS to reach private services by hostname, while Tailscale's Oct 6 blog says MagicDNS and split DNS do not work. Until that is settled, use IPv4 addresses or fully qualified hostnames that resolve to IPv4. OpenAI has not said when Codex Cloud reaches every eligible plan, or when other VPN providers will be added beyond "planned."
Sources
- OfficialOpenAI cloud environments doc (Private networking) · Oct 7, 2026
- OfficialTailscale blog: Codex Cloud shipped with Tailscale support · Oct 7, 2026
- OfficialTailscale on X · Oct 7, 2026
- Report@vermaizer reply on tagging the key · Oct 7, 2026
Get updates like this every morning
- ① Email
- ② Card on Stripe
- ③ 7 days free
Then $2/month · cancel anytime in one click