CloudHSM for CA Key Storage
To use CloudHSM as the CA key store for your provisioning service:
Option A: CloudHSM-backed SPIRE CA
SPIRE server → CloudHSM via PKCS#11 plugin
(SPIRE KeyManager plugin: "aws_cloudhsm")
Option B: CloudHSM-backed ACM PCA
ACM PCA with CloudHSM backing
(Currently: ACM PCA uses AWS-managed HSMs, not customer CloudHSM)
(CloudHSM is used for self-managed CAs outside ACM PCA)
Option C: EJBCA or custom CA on EC2
Your CA software → CloudHSM via PKCS#11 for signing
Separate from ACM PCA
Key insight: If you use ACM PCA, you don't manage the HSM at all.
CloudHSM is only relevant if you're running your own CA software.