Start the online CA from the pinned HSM image. Bind-mount the CA state and endpoint files instead of copying either credential set into the image.
Load the runtime variables
The final command exits with status 0 when the endpoint-file group exists.
Start the container
Docker prints the new container ID.
The command keeps the endpoint directory read-only, exposes the CA on port 9000, and grants the container only the supplementary group needed to read the endpoint files and append to the FxChlibs log.
The command does not pass a PKCS #11 PIN or endpoint password. FxChlibs reads the protected UserPass credential from the bind-mounted cryptohub.json.
Verify startup
Check the container state and CA health:
The health response is:
Inspect the startup log:
The log includes these messages:
Confirm that FxChlibs reached the intermediate key:
The output includes successful sign initialization and finalization calls. Continue to Validate the integration to issue a leaf certificate.