You can use oauth tokens with the permissions of auth_key write to use long lived tokens to permission ephemeral nodes
It can get especially interesting when you do things like have your GitHub runners onboard themselves to Tailscale - at that point you can pretty much fully-provision isolated systems directly from GitHub Actions if you want