What's the difference between a certificate and a public/private keys?
So you get extra security (credentials are dynamic and short -lived, and also per-user if needed) and lower maintenance because you only have the SSH CA public key to setup on all machines and that one needs less rotation/updates than public keys.
The main difference is that with an ssh key, you install the public key directly on the target host. With a certificate, you Just tell the host to trust a CA, and use that CA to sign client certificates.
This is hardly "lower maintenance" than pushing updates to the authorized_keys across servers.
Or having servers poll for such file.