Home / Companies / Speakeasy / Blog / Post Details
Content Deep Dive

Run a private MCP Gateway on Tailnet

Blog post from Speakeasy

Post Details
Company
Date Published
Author
Tristan Cartledge
Word Count
1,386
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

Speakeasy has introduced private network ingress for its MCP gateway through Tailscale tailnets, allowing organizations to host MCP endpoints at stable private hostnames without exposing them to the public internet. Private-only servers return 403 responses to public requests, fail closed during outages or misconfigurations, and use Tailscale identities such as users, devices, and tags in audit logs alongside tool calls. Access is governed through existing tailnet ACLs rather than separate IP allowlists, eliminating the need for fixed egress IP addresses and supporting IPv6. The integration uses Tailscale’s Kubernetes operator to provision isolated, highly available per-organization services, while an attestor verifies workloads, forwards approved MCP and OAuth paths, and attaches request identity metadata. Organizations can configure individual servers as public-only, dual-access for migration, or private-only, with setup involving a scoped Tailscale OAuth client, ACL configuration, and server exposure settings. The feature is rolling out per organization, with other overlay-network integrations planned.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 30 No monthly metrics for this publish month.
Kubernetes 5 No monthly metrics for this publish month.
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.