It's like, super detectable. You have endpoint logs for the file access, you have network logs, you have sshd logs (which contain the public key and the IP), etc.
> if you have your ssh private key on several machines, you have to remember to copy it to all those places
Your ssh key should never leave a host. That should be a policy and you should write rules to detect when that policy is being violated (check for processes accessing the file).
If you need access from N computers you should be generating N keys.
The reason rotation isn't recommended is because it leads to bad practices (people just add a '1' to their password), it's a hassle, and it can never be fast enough to meaningfully impact an attacker - once they have SSH keys it's likely they can gain persistence and C2 before your rotation takes place. Not because people reuse their passwords in multiple places.
Setting up a CA for SSH is definitely a really good practice but I think that most companies would find it far simpler to just enforce 2FA for SSH access. Still, I'd really like to see an article about how you set that up, especially if it targets smaller enterprise customers.
For others who might be interested, here's bless from Netflix:
https://github.com/Netflix/bless
edit: Oh, and just to be clear, 2FA for your SSH is not a silver bullet - even a yubikey. But it's a cheap, scalable, near-zero overhead way to protect against an attacker who's got access to your key (but not one who has access to your system, assuming an active session!).