I few things here I wanted to mention here: first, a Network Extension based VPN such as a Packet Tunnel Provider, or even a device-configured VPN, will always takes precedence over Private Relay. So any traffic that is going over the device-configured VPN or a Packet Tunnel Provider is not eligible for Private Relay. This is mentioned in the Note section out on the
Packet Tunnel Provider documentation. Next, on this point, if traffic on the system is not going through a device-configured or Network Extension VPN then it can be eligible for Private Relay.
Lastly, if there is a local network VPN that the device is not aware of, for example a VPN that is not running on the device, then the device would not be aware of this VPN and the traffic on the device would be eligible for Private Relay, unless the user disables Private Relay on that specific network.
Matt Eaton
DTS Engineering, CoreOS