The target machines then just need to put the CA cert in the authorized_keys files.
The word "just" is doing a lot of work there. You update authorized_keys every hour for your entire fleet?
It is the user machine that needs new certificate signed by the CA once the short-lived one expires.
Ahh, now you have three problems…hrm