{
  "certificate-authority": {
    "key": "certificate-authority",
    "arn": "arn:${Partition}:acm-pca:${Region}:${Account}:certificate-authority/${CertificateAuthorityId}",
    "conditionKeys": [
      "aws:ResourceTag/${TagKey}"
    ]
  }
}