Using a custom certificate authority

    1. First we create the cluster folder structure in the statestore.
    2. Last, we run kops update cluster --yes, which will generate all the certificates needed, referencing the keypair called kubernetes-ca we just defined (instead of generating its own).