The .app and .dmg from the Package workflow are ad-hoc signed, so Apple Silicon runs the app and TCC can remember its local network permission — you don't need to sign it yourself.
An ad-hoc signature carries no Developer ID and isn't notarized, though, so Gatekeeper still blocks a copy downloaded through a browser: it reports the app as damaged or from an unidentified developer. Once you've installed it in /Applications, clear the quarantine flag:
xattr -d com.apple.quarantine "/Applications/Fernrohr.app"
Or open it once from System Settings → Privacy & Security → Open Anyway. Builds made before signing landed still need an ad-hoc signature applied manually:
codesign --force --sign - "/Applications/Fernrohr.app"
Fernrohr requires ssh on your PATH to connect any kube context bound to an SSH tunnel — it shells out to the system OpenSSH client rather than bundling its own.
Something not covered here? Let us know, or open an issue on GitHub.