AWS Certificate Manager now issues public certificates over ACME through PrivateLink
AWS Certificate Manager (ACM) now supports AWS PrivateLink for issuing public certificates over ACME, AWS announced on 6 October. Requests and renewals of public TLS certificates can travel over a private network path that stays inside AWS.
How it works. After creating a managed ACME endpoint in ACM, you create a standard VPC interface endpoint to the ACM ACME service, through the VPC console, the AWS CLI or CloudFormation. Private DNS then resolves the existing ACME directory URL to that interface endpoint inside the VPC, so any ACMEv2-compatible client keeps the same configuration and directory URL. AWS says no changes to ACME clients are needed.

What goes over PrivateLink. The whole issuance flow: account creation, order creation, domain validation, finalisation and certificate retrieval. Activity stays visible in the ACM console, with CloudTrail logging and CloudWatch metrics.
Availability and cost. All commercial AWS Regions. Standard PrivateLink charges apply for interface endpoints, on top of ACM pricing.