Cilium maintainers André Martins and Feroz Salam from Isovalent at Cisco share lessons learned securing CI/CD pipelines for open source cloud native projects. The post focuses on controlling who can trigger workflows and what actions they can perform, a critical concern for scalable, community-driven architectures. Practical techniques are presented for reducing attack surface in GitHub Actions and similar pipeline environments.