Based on Parachain launch checklist:
Make yourself familiar with using srtool (or equivalent) for deterministic builds.
https://github.com/paritytech/srtool
We can use it for PROD. CI could prepare artifacts for runtime upgrades using srtool or similar.