Part of #745.
reusable-check-python-package-versions.yaml's aws_account_id/aws_iam_role_name inputs still default to legacy (505071440022, GithubActions_Schema_CodeArtifact_ReadOnly). This is a PR-time existence-check optimization only, not a hard blocker on the real publish pipeline, but flip it to MCD (763944545891) once a CodeArtifact read-only role exists there.
Confirmed there's no dedicated MCD read-only role yet, and no verified evidence the publish role (codeartifact-pypi-publish-oidc-overturemaps) is an acceptable stand-in either, so don't flip until an actual read-only role is confirmed. A tracking TODO(schema#748) comment referencing this issue was added to the workflow in #747.
Part of #745.
reusable-check-python-package-versions.yaml'saws_account_id/aws_iam_role_nameinputs still default to legacy (505071440022,GithubActions_Schema_CodeArtifact_ReadOnly). This is a PR-time existence-check optimization only, not a hard blocker on the real publish pipeline, but flip it to MCD (763944545891) once a CodeArtifact read-only role exists there.Confirmed there's no dedicated MCD read-only role yet, and no verified evidence the publish role (
codeartifact-pypi-publish-oidc-overturemaps) is an acceptable stand-in either, so don't flip until an actual read-only role is confirmed. A trackingTODO(schema#748)comment referencing this issue was added to the workflow in #747.