Skip to content
Rush Commerce
Software & Dev3 min read

Codex cloud environments: your dev setup is now a shared VM

OpenAI's Codex cloud environments give each task a persistent VM with proxy-injected network secrets. Here is what to lock down before your team shares one.

OpenAI gave Codex reusable cloud environments at DevDay today, and the dev environment just stopped living on a laptop. Codex reads your GitHub repo, drafts the install script, and publishes a shared environment. Each task then gets its own virtual machine that keeps running after you close the lid. That is useful. It also means your team's setup script, secrets and network rules now sit in one place that an agent operates.

What actually happened

Per TechCrunch, Codex cloud tasks used to spin up isolated, throwaway sandboxes. The new environments are persistent and configurable, work from a computer, phone or the cloud, and give a team a shared setup with approved settings and permissions.

SiliconANGLE has the mechanics:

  • Setup: Codex scans the repo for versions and dependencies, writes the install script, and runs startup checks. You edit it by talking to Codex.
  • Secrets: plain environment variables, plus "network secrets" — the program sees a placeholder and a proxy inserts the real value only for allowlisted domains. Shared environments can make each user supply their own credentials.
  • Network: defaults to common package registries; you can widen it.
  • Tiers: Plus runs the smallest VMs; Pro, Business and Enterprise get double the CPU and memory.
  • Limits: no GitLab or self-hosted GitHub Enterprise Server, no computer or browser use inside the environment, and task state is recoverable for 7 days after last use.

OpenAI also shipped a code review view in the ChatGPT desktop app and Codex Security Cloud, which scans GitHub repos on a schedule and prepares fixes while your machine is off.

Why Codex cloud environments matter for your business

Network secrets are the right design — use them. A key the agent can never read is a key the agent can never paste into a log, a commit or a prompt-injected web form. Move every API key you can from plain env vars to proxy-injected secrets, and keep the domain allowlist tight.

Per-user credentials beat a shared service account. If an environment is shared, make each developer bring their own tokens. When something goes wrong you want the audit log to name a person, not "codex-bot."

Review the generated setup script like code. An agent wrote it. It installs packages from the internet on a machine that holds your secrets. Pin versions, commit it, and diff it on every change.

Check the lock-in. No GitLab support, a 7-day state window and a single vendor's VM. Keep the setup script in your repo so the same environment rebuilds anywhere.

Key takeaways

  • Codex cloud environments are persistent, shared VMs that keep working when your device is offline
  • Network secrets hide real values behind a proxy that injects them only for allowlisted domains
  • Shared environments can require each user to bring their own credentials — turn that on
  • No GitLab or GitHub Enterprise Server support, no computer use inside, and 7-day task state recovery
  • Commit and review the agent-written setup script; it runs next to your secrets

A coding agent is only as safe as the box you put it in. We set up agent dev environments with scoped secrets, tight egress and a setup script that lives in your repo, not a vendor's console. See how we build agent infrastructure you own or tell us what your team runs today.

Sources: TechCrunch, SiliconANGLE.

  • #codex
  • #openai
  • #coding-agents
  • #dev-environments
  • #secrets-management
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.