fix: push.sh staging deploys now use individual SSO identity, not shared musehub-infra
Staging authenticated via the shared, long-lived musehub-infra static IAM credential — exactly the anti-pattern Section 1 flags. Switched to the same per-operator IAM Identity Center SSO session already used for production (musehub-nonproduction profile). Verified live with a real staging deploy under SSO with zero reliance on musehub-infra.
Re-verified Section 1 (#150) end-to-end with full account access: most items that were 'needs Gabriel, cannot verify from here' are now resolved (IAM Identity Center, individual identities, root MFA, break-glass, joiner/leaver docs all landed since this doc was written). Upgraded Aaron from write to admin collaborator on musehub and muse, matching his actual co-ownership.
musehub-infra itself isn't retired yet — bootstrap-instance.sh, publish_muse_release.sh, and backfill_loop.sh still reference it/stale instance IDs; tracked as a follow-up rather than fixed in this pass.
Semantic Changes
12 symbols
Files Changed
~2
1060 in snapshot
0 comments
muse hub commit comment sha256:7ca89a509c5c90deba3aee7664f0fdaa8f58f7c5d5b7b9893262f04ac955c408 --body "your comment"
No comments yet. Be the first to start the discussion.