> Teleport handles the auth at its entry point, so you don't need a keypair for every node in your cloud. Just one for Teleport.
From ssh(1):
-J destination
Connect to the target host by first making a ssh connection to
the jump host described by destination and then establishing a
TCP forwarding to the ultimate destination from there. Multiple
jump hops may be specified separated by comma characters. This
is a shortcut to specify a ProxyJump configuration directive.
Auth to the jump/bastion host and then have key(s) on that, or tunnel back the internal auth requests over to your desktop via ssh-agent(1) forwarding:* http://www.unixwiz.net/techtips/ssh-agent-forwarding.html#fw...
* https://www.cloudsavvyit.com/25/what-is-ssh-agent-forwarding...