CI jobs running on trusted runners need to be able to connect to the kubestagemaster cluster in order to perform test helm deployments of mediawiki services before promotion to production (only in the ci namespace). See https://integration.wikimedia.org/ci/job/mathoid-pipeline-rehearse/38/console for an example of how the existing Jenkins CI performs this operation.
https://gitlab.wikimedia.org/repos/releng/mathoid/-/jobs/42458 shows that a CI job running on gitlab-runner1003.eqiad.wmnet (a trusted runner) cannot make a TCP connection to kubestagemaster.svc.eqiad.wmnet:6443. However the same curl command from the runner host directly does work.