Experiment with two-factor-authentication for SSH access to the production cluster. Initially with a dedicated bastion host on which 2fa is enabled.
Yubikey tokens (produced by Yubico) are the most suitable selection for an authentication hardware token; they provide an open source-friendly software stack and are a proven solution.