The initial stance for JEP-229 was that we would continue to grant maintainers personal push permission in case CD did not work for whatever reason. As the system matures and we grow more confident that automated deployments will work reliably and cover every scenario, we could plan to tighten up security in this way.
To Daniel’s point, I guess the switch would be to not grant Artifactory permission to people in RPU for a CD-enabled repo, unless we wanted to add a new field to discriminate people who keep this permission for the time being from those who are maintainers and should have GH write permission but no more.
we should be able to do CD on [backport] branches