naive question: Doesn't github secret scan kind of thing wont catch this?
This is how all major players in the market recommend you set up your CI pipeline. The problem here lies in implicit trust of the pipeline configuration which is stored along with the code.
I was thinking maybe a better approach instead of CICD SSH into prod machine is to have the prod machine just listen to changes in git.