We'll likely need to split out Jenkins into two instances: one with secrets that can push releases and a completely untrusted one with no secrets.