Yeah, weird for them to do that. Managing credentials like that sucks even from an ergonomics standpoint.
In practice, it's pretty normal to use OIDC to authenticate Github Actions to AWS:
https://docs.github.com/en/actions/deployment/security-harde...