I’m missing a step here. I see a var called ssh, and an authorized key, but I don’t see where they’re seeing any method for the device to expose itself outside the NAT that’s in place on basically every consumer LAN.
This looks a lot more like the device fetches updates via SSH to a remote update server, and the authorized_keys entry is vestigial.