I have a noob question. Our AWS account is set up with Control Tower, with a management account and sub-accounts for various workloads. I've set up OIDC on the management account, and then I pass the role for the various accounts into the aws.Provider constructor as assumeRole... etc. However, when I do
pulumi up
, it doesn't assume the role and it creates resources in the management account. Am I doing this right?