that way i would not need to keep the keys in the bastion server at all.
https://www.redhat.com/sysadmin/ssh-proxy-bastion-proxyjump
https://www.redhat.com/sysadmin/ssh-proxy-bastion-proxyjump