A deployment pipeline is a privileged production path

Whatever can deploy to production has production's power, whether or not anyone thinks of it that way.

It holds credentials that reach live systems, it runs automatically, and it is often configurable by anybody who can commit. That combination is unusual: a highly privileged actor whose instructions are editable by a wide group. Protecting production while leaving the thing that writes to production open is a common and consequential gap.

More on CI/CD security