So the assumption here is that somehow your private key is easier to compromise than whatever secret/mechanism you use to provision certs?

Yeah not sure about that one...