Tailscale sounds like an interesting solution, I already have wireguard vpn which runs on all my personal devices.
At the moment github is my single source of truth for pub keys so having that setup might work, I could also automate the cronjob via ansible when I setup default config on new vms
I guess it's just the way I've been using it for years and years. I've been remote working for abour a decade so I've been in places where it could have been possible to grab my keys if I'd left a laptop unlocked, not likely though.
It's a shame but it makes sense. One of the mods has ties to Reddit in London iirc. Wonder if there was pressure from up high.