Developers can't be trusted with SSH private keys. I'm stunned by how many times I've asked a developer to send their SSH public key only to see them dump their private keys on Slack, in a Pastebin, or in a Git commit or wherever.
It would be so much better if standard practice was to generate and store the private key on a smartcard or the TPM, so that the only file a clueless/careless developer could upload would be a stub.