The 'dirty' machine is used for day-to-day tasks. I write code, download libraries, research things on the internet, but the machine doesn't have access to any of my production systems. In other words, if the dirty machine were to be compromised, the attacker couldn't take over my website with it.
All code is pushed to a private fork of my website, which is the 'staging' branch. A separate GitLab account and SSH identity is used so that there is a clear separation of privileges.
Then, when I'm ready to deploy to production, I turn around and log on to my secure machine. I create a merge request to merge the dirty 'staging' branch with the clean production branch. Before accepting the merge request, I thoroughly review the diff of my own code in order to make sure that an attacker didn't sneak something in without me noticing.
If I need to make minor corrections before merging (e.g. if I notice a spelling mistake at the last minute), I can commit this straight to master from the secure machine and then pull the change back down to staging afterwards.
Doing it this way does take slightly longer, but if you have both of the machines physically next to each other (but with separate peripherals and isolated network connections of course), then the security benefit massively outweighs the extra time requirement.