So now you have layers of:
- SSH RFC
- OpenSSH extensions to SSH
- Google extensions to OpenSSH
There's already mature CA support in OpenSSH
https://dev.to/gvelrajan/how-to-configure-and-setup-ssh-cert...
And even OpenSSH 8.2+ supports FIDO2 built-in.
Can add TOTP, FIDO2/u2f, ldap, or kerb with pam also.
Edit: or is there some ability for clients to leverage the CA to establish trusts without authorized_keys?
So now you have layers of:
- SSH RFC
- OpenSSH extensions to SSH
- Google extensions to OpenSSH