This allows us to replace the apiserver process during genesis with the
chart-managed version that is likely to only listen on a secure port.
* Bundle armada + tiller + insecure apiserver into a static pod
* Report aramda logs via host filesystem
NOTE: This is using an additional apiserver sidecar rather than a
`kubectl proxy` sidecar with a serviceaccount, because it's running as a
static pod.
Change-Id: I39c638020c0ad36db8d3b10c4ecb959a6642ad0e