Once we have set up the replacement (Kyverno pod security rules), we can drop the deprecated PodSecurityPolicy mechanism from Toolforge k8s.
Plan is:
- drop PSP controller
- drop resources from the cluster and update each account state configmap https://gitlab.wikimedia.org/repos/cloud/toolforge/maintain-kubeusers/-/merge_requests/49
- cleanup the code from maintain-kubeusers https://gitlab.wikimedia.org/repos/cloud/toolforge/maintain-kubeusers/-/merge_requests/48
- review and update privileged-psp role usage
- cleanup