update note: - step-ca container doesn't support $PWDPATH anymore - add --password-file argument to exec