The general best practice is to disable SSH on your ESXi host by default and if/when you need access, you can turn it on temporarily and disable it when you have completed your task.
For users that need to modify the default SSH configurations whether that is on the server side, client side or setting up SSH authorized keys, this was historically accomplished by manipulating the various SSH configuration files and then reloading the service, if applicable.
With the introduction of the ESXi Configuration Store in vSphere 7.0 Update 1, the process is now different with ESXi 8.0 Update 2 and later for services that requires a configuration file to run such as SSH, NTP or SNMP to name a few.