Run a private MCP Gateway on Tailnet
Blog post from Speakeasy
Speakeasy has introduced private network ingress for its MCP gateway through Tailscale tailnets, allowing organizations to host MCP endpoints at stable private hostnames without exposing them to the public internet. Private-only servers return 403 responses to public requests, fail closed during outages or misconfigurations, and use Tailscale identities such as users, devices, and tags in audit logs alongside tool calls. Access is governed through existing tailnet ACLs rather than separate IP allowlists, eliminating the need for fixed egress IP addresses and supporting IPv6. The integration uses Tailscale’s Kubernetes operator to provision isolated, highly available per-organization services, while an attestor verifies workloads, forwards approved MCP and OAuth paths, and attaches request identity metadata. Organizations can configure individual servers as public-only, dual-access for migration, or private-only, with setup involving a scoped Tailscale OAuth client, ACL configuration, and server exposure settings. The feature is rolling out per organization, with other overlay-network integrations planned.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 30 | No monthly metrics for this publish month. | |||
| Kubernetes | 5 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.