Best option for SSH Host Certificate with cloud-init (wrapping? transit? ..)

I responded to a similar question here last year:

If hosts are AD-joined and have Kerberos credentials, could those credentials be used to obtain the token (with the policy maxb described assigned) and use that to get the host keys signed?

jd