Revert "Create k8s server certs directly on ctl nodes"

This reverts commit 546660c940ac56ad2efc4a79a150c9043f200b79.

Due to this change kubernetes cluster will be broken,
as different server certificates will be created on controller nodes.
The cerificates must be equal for proper functioning

Related-bug: https://mirantis.jira.com/browse/PROD-24174

Change-Id: Ia2d1f496515daf0a5851c2373dc2fec855ac718d
diff --git a/salt/minion/cert/k8s_server.yml b/salt/minion/cert/k8s_server.yml
index 16cf2cc..603d369 100644
--- a/salt/minion/cert/k8s_server.yml
+++ b/salt/minion/cert/k8s_server.yml
@@ -6,8 +6,8 @@
           host: ${_param:salt_minion_ca_host}
           authority: ${_param:salt_minion_ca_authority}
           common_name: kubernetes-server
-          key_file: /etc/kubernetes/ssl/kubernetes-server.key
-          cert_file: /etc/kubernetes/ssl/kubernetes-server.crt
-          all_file: /etc/kubernetes/ssl/kubernetes-server.pem
+          key_file: /srv/salt/env/${_param:salt_master_base_environment}/_certs/kubernetes/kubernetes-server.key
+          cert_file: /srv/salt/env/${_param:salt_master_base_environment}/_certs/kubernetes/kubernetes-server.crt
+          all_file: /srv/salt/env/${_param:salt_master_base_environment}/_certs/kubernetes/kubernetes-server.pem
           signing_policy: cert_server
           alternative_names: IP:${_param:cluster_vip_address},IP:${_param:cluster_node01_address},IP:${_param:cluster_node02_address},IP:${_param:cluster_node03_address},IP:${_param:kubernetes_internal_api_address},DNS:kubernetes.default,DNS:kubernetes.default.svc
diff --git a/salt/minion/cert/k8s_server_single.yml b/salt/minion/cert/k8s_server_single.yml
index 7227d0f..33637e4 100644
--- a/salt/minion/cert/k8s_server_single.yml
+++ b/salt/minion/cert/k8s_server_single.yml
@@ -6,8 +6,8 @@
           host: ${_param:salt_minion_ca_host}
           authority: ${_param:salt_minion_ca_authority}
           common_name: kubernetes-server
-          key_file: /etc/kubernetes/ssl/kubernetes-server.key
-          cert_file: /etc/kubernetes/ssl/kubernetes-server.crt
-          all_file: /etc/kubernetes/ssl/kubernetes-server.pem
+          key_file: /srv/salt/env/${_param:salt_master_base_environment}/_certs/kubernetes/kubernetes-server.key
+          cert_file: /srv/salt/env/${_param:salt_master_base_environment}/_certs/kubernetes/kubernetes-server.crt
+          all_file: /srv/salt/env/${_param:salt_master_base_environment}/_certs/kubernetes/kubernetes-server.pem
           signing_policy: cert_server
           alternative_names: IP:${_param:control_address},IP:${_param:kubernetes_internal_api_address}