CI should be run on - PRs - main CD should be run on - main (test environment) - tags (production environment) Tagging should be limited to certain users with the rights to deploy to production.