Service eligibility and regional restrictions
PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.
Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.
Key Takeaways
- First check that your account has Advanced → VPN in its cloud environment. Tailscale's October 6 announcement describes a gradual rollout, rather than availability for every account.
- Enable both Reusable and Ephemeral on the auth key. They allow new task machines to join and let Tailscale clean up offline temporary devices, respectively.
- Both Tailscale access rules and the Codex environment's destination-domain rules must allow the target. Tasks in a shared environment use the configured VPN identity.
- Private IPv4 subnet routes, MagicDNS and split DNS are currently supported. Internal services' fully qualified domain names must resolve to IPv4.
Which tasks benefit from private networking?
If cloud tasks need an internal company API, a private package registry or another HTTP/HTTPS service, you can add a Tailscale VPN connection to the Codex Cloud environment. This can let tasks reach existing private services without exposing them to the public internet just to give an agent access.
Tailscale writer Kevin Purdy described the built-in option on October 6, 2026, and said Codex Cloud was rolling out to paid ChatGPT plans from Plus upwards. At the time of this article's review, that did not establish that every account had the option. Check the actual cloud environment and workspace permissions first.
Why enable both Reusable and Ephemeral on the key?
In the cloud environment's Advanced settings, find VPN, choose Add and configure the Tailscale connection. OpenAI requires an auth key with both Reusable and Ephemeral enabled. Reusable lets virtual machines for subsequent tasks join the network; Ephemeral lets Tailscale automatically remove temporary devices when they go offline.
Tailscale's announcement recommends a tagged key for the agent, with access rules limiting what that identity can reach. Grant access for the agent's task rather than inheriting everything the key creator can access. Enter real keys in the connection settings, never in repositories, prompts or screenshots.
Why can a service remain unreachable after the VPN connects?
Connecting is only the first step. Tailscale access rules must allow the VPN identity to reach the target, and the Codex environment's internet settings must allow the required destination domains. A denial at either layer can block access. Enterprise workspace Agent Security requirements also continue to apply.
Suppose a task needs the fictional endpoint api.corp.example.com. Allow that necessary target in both places, then check the service's own authentication. VPN connectivity does not replace API permissions: even with a working network path, missing service credentials can still produce authentication or authorization errors.
Are MagicDNS and split DNS supported now?
Yes. Tailscale's October 6 blog post still said MagicDNS and split DNS were unavailable, but the current OpenAI cloud environment documentation opened for this article explicitly supports both, as well as private IPv4 subnet routes. Use current product documentation for configuration rather than carrying forward the older blog's DNS limitation.
MagicDNS lets you reach devices by their network names. If you need internal company DNS, configure split DNS in Tailscale's administration settings so internal-domain queries go to the relevant DNS server. OpenAI requires the service's fully qualified domain name to resolve to IPv4 and the task to be able to reach that DNS server.
Will existing tasks use the new configuration as soon as you save it?
After configuring the VPN and destination rules, save the environment, choose Publish or Republish and start a new task to check the required service. A cloud environment is reusable configuration and filesystem preparation; each new task starts its own isolated workspace from the published environment.
Existing tasks retain their own state, so a task that was already running is not a reliable check of newly published configuration. Tasks sharing an environment use its configured VPN identity. Limit that identity to the resources the team actually needs.
If a new task still fails, which layer should you check first?
Follow the symptoms. If the VPN identity is disconnected, check the connection and key first. If it is connected but the service is unreachable, check both layers of destination access rules. If an IPv4 address works but the hostname fails, focus on split DNS, reachability of the internal DNS server and whether the full hostname resolves to IPv4.
OpenAI also requires request clients to use the environment's configured HTTP/HTTPS proxy. Do not add --noproxy to curl checks to bypass it. Confirm access with an authorized request from a new task to the required service, rather than relying solely on a connected VPN status. This article did not connect a real account or private network.
Sources
Frequently Asked Questions
Is this a joint OpenAI–Tailscale integration project?
Tailscale's October 6 announcement explicitly says it was not a joint integration project and there was no special partnership agreement. What can be confirmed is that Codex Cloud offers a Tailscale connection option. Built-in support does not establish a joint launch or shared subscription entitlements.
Can I follow these steps in an older Codex Cloud environment?
Current OpenAI documentation distinguishes the new Codex Cloud environments from an older experience retained for some integrations. This guide covers the current environment with Advanced → VPN settings. If your interface differs, check the environment type and available settings before treating a missing option as a network failure.