Create k8s server certs directly on ctl nodes

Related bug: https://mirantis.jira.com/browse/PROD-24174

Change-Id: I0eece9893afabe2b431de2ce050abd8bf95e759d
diff --git a/classes/cluster/sl-k8s-calico/infra/config.yml b/classes/cluster/sl-k8s-calico/infra/config.yml
index 5cf7d6c..4e98584 100644
--- a/classes/cluster/sl-k8s-calico/infra/config.yml
+++ b/classes/cluster/sl-k8s-calico/infra/config.yml
@@ -5,7 +5,6 @@
 - system.salt.master.pkg
 - system.salt.minion.ca.salt_master
 - system.salt.master.api
-- system.salt.minion.cert.k8s_server
 - system.mysql.client
 - system.mysql.client.database.grafana
 - system.reclass.storage.salt
diff --git a/classes/cluster/sl-k8s-calico/kubernetes/control.yml b/classes/cluster/sl-k8s-calico/kubernetes/control.yml
index a316fb8..bd254a5 100644
--- a/classes/cluster/sl-k8s-calico/kubernetes/control.yml
+++ b/classes/cluster/sl-k8s-calico/kubernetes/control.yml
@@ -1,5 +1,6 @@
 classes:
 - system.etcd.server.cluster
+- system.salt.minion.cert.k8s_server
 - service.kubernetes.control.cluster
 - system.haproxy.proxy.listen.kubernetes.apiserver
 - system.keepalived.cluster.instance.kube_api_server_vip