That's the thing: according to the post he offered it, but the offer wasn't accepted. They stayed on Github, and it was the Github repos which were compromised. They did entertain his desire to let him host a read-only mirror - but that's hardly critical, and having complete strangers mirroring Linux ISOs or package repos has been a thing for ages.
The post makes zero mention of him ever joining or being part of the core infra ops team. So where did the admin access come from?