CI/CD presents a significant risk and it's not like CI/CD vendors have never had a security incident. Not to mention the unpublished access a member of their staff may have to interfer with your runners or pull your access tokens/secrets.
If an org is more comfortable having their own people assume this risk, I think the gitlab helm chart is better solution. At the same time, a small org, without the resources to properly look after this in-house, should use a SaaS vendor.