This is exactly the issue I was screaming about for years. Finally there was a breach. If you can think it can happen.It will happen.
The day they started pushing that shit I was saying "are you fucking stupid or something"? If you don't control the entire stack you cannot assume it is not compromised. Even then, insider threat is a thing and a BIG thing at that.
Letting "devs" control deploying the framework everything runs on is one of the dumbest ideas on the planet. I would suggest it's like giving a 2 year old the control for a massive dam and they get to make it do things because they think it's funny while people downstream die.
The best of them sort of know what they are doing. The rest are "you get in my way of deploying my shit code that I don't test properly that will fuck up your entire week".