Nice. The deadline argument concept is smart and not in many other implementations.
It seems there are two sides of the spectrum for secure SSH access:
+ Relatively infrequent access by limited # of people to servers which are not top targets for attacks. Solutions like the one above are great for this.
+ More frequent, more users, more sensitive servers. Close all the inbound ports, permanently. Example: https://github.com/openziti-test-kitchen/zssh (or with an integrated OIDC like KeyCloak - https://youtu.be/NZJtzSoS_g0?si=Qg6p6Hdkaq1ahefg)