Reduce privs of metrics pods where we can
Right now, they run with privileged psp, which is not a huge problem, but it is also unnecessary. That suggests we should tighten it a bit.

It probably just needs something like the default policy we aren't using.