Ask HN: How does your organisation manage employee SSH keys?
I've seen a variety of approaches, ranging from
* manually deployed by an infra team in response to JIRA tickets
* checked into a repo and deployed with saltstack, along with a cronjob to sync with G-Suite so that keys would be automatically removed when people left
* SSO integration through AWS systems manager
What have you seen tried? What worked well, what didn't?