I want to limit keys to a subset of subpaths in a subset of services Perhaps openssh principals could be used for this. In this way support for authorized_keys files can be kept.