Digger makes it sound like it might address this:
> Digger runs terraform natively in your CI. This is: Secure, because cloud access secrets aren't shared with a third-party
From the Github+AWS demo:
> 4. Add environment variables into your Github Action Secrets (cloud keys are a requirement since digger needs to connect to your account for coordinating locks) AWS_ACCESS_KEY_ID & AWS_SECRET_ACCESS_KEY
It sure looks like AWS admin credentials are shared with Github, and also available to anything else in the diggerhq/digger action.