How does that work in general in production (outside of the cluster)? Do you distribute changed keys automatically to all clients and put them somewhere in /etc/ssh?
ssh-copy-id of the new keys some time before the old ones "expire", then wipe the old ones when the time comes.authorized_keys to store an imaginary expiry piece of info, then cron/systemd.timer it to periodically weed out the old ones. Which is why I said, have more accounts there. We use essential cookies to make this site work, and optional cookies to enhance your experience.