maintain_kubeusers: add basic expiration detection
This is going to run much slower this way, but perhaps that will
reduce API load in the process. We need basic machinery to detect
expiring certificates. In this, the expiration is noted in the config map
which is then read to determine when to run another cert creation.