m/n/kubernetes: start splitting, run apiproxy

This begins the process to split the Kubernetes service into a
controller and a worker service.

First, we rename the existing service to a Controller, create a Worker
service, and make the Worker service run our new tinylb-based apiserver
loadbalancer.

We also make the roleserver aware of this change by making it spawn both
the controller and worker services according to roles.

We will move services to the Worker in follow up change requests.

Change-Id: I76e98baa0603ad5df30b5892dd69154b895b35fa
Reviewed-on: https://review.monogon.dev/c/monogon/+/1374
Reviewed-by: Lorenz Brun <lorenz@monogon.tech>
Tested-by: Jenkins CI
diff --git a/metropolis/node/kubernetes/pki/BUILD.bazel b/metropolis/node/kubernetes/pki/BUILD.bazel
index f2e4e3c..7bcc531 100644
--- a/metropolis/node/kubernetes/pki/BUILD.bazel
+++ b/metropolis/node/kubernetes/pki/BUILD.bazel
@@ -7,7 +7,6 @@
     visibility = ["//metropolis/node:__subpackages__"],
     deps = [
         "//metropolis/node",
-        "//metropolis/pkg/logtree",
         "//metropolis/pkg/pki",
         "@io_etcd_go_etcd_client_v3//:client",
         "@io_k8s_client_go//tools/clientcmd",
diff --git a/metropolis/node/kubernetes/pki/kubernetes.go b/metropolis/node/kubernetes/pki/kubernetes.go
index ef046a2..24c9c52 100644
--- a/metropolis/node/kubernetes/pki/kubernetes.go
+++ b/metropolis/node/kubernetes/pki/kubernetes.go
@@ -37,7 +37,6 @@
 	configapi "k8s.io/client-go/tools/clientcmd/api"
 
 	common "source.monogon.dev/metropolis/node"
-	"source.monogon.dev/metropolis/pkg/logtree"
 	opki "source.monogon.dev/metropolis/pkg/pki"
 )
 
@@ -95,15 +94,13 @@
 // generate Kubeconfigs from.
 type PKI struct {
 	namespace    opki.Namespace
-	logger       logtree.LeveledLogger
 	KV           clientv3.KV
 	Certificates map[KubeCertificateName]*opki.Certificate
 }
 
-func New(l logtree.LeveledLogger, kv clientv3.KV, clusterDomain string) *PKI {
+func New(kv clientv3.KV, clusterDomain string) *PKI {
 	pki := PKI{
 		namespace:    opki.Namespaced(etcdPrefix),
-		logger:       l,
 		KV:           kv,
 		Certificates: make(map[KubeCertificateName]*opki.Certificate),
 	}