In Opentitan it's done with private CI, but I would avoid it due to the complexity if possible. 1. What information can't be made public? 2. Is it ok to run in public CI but don't show any log in case of error and expect the PR onwer to run it locally?