kube: move cert-manager resources to kube.local.libsonnet

This way kubernetes consumers don't have to import anything from
cluster/, hopefully.

We also create a small abstraction for local additions for
kube.libsonnet without having to modify upstream.

Change-Id: I209095781f91c8867250a647fe944370cddd67d0
diff --git a/cluster/kube/cluster.jsonnet b/cluster/kube/cluster.jsonnet
index a0b1aed..e9e8932 100644
--- a/cluster/kube/cluster.jsonnet
+++ b/cluster/kube/cluster.jsonnet
@@ -176,7 +176,7 @@
     // Main nginx Ingress Controller
     nginx: nginx.Environment {},
     certmanager: certmanager.Environment {},
-    issuer: certmanager.ClusterIssuer("letsencrypt-prod") {
+    issuer: kube.ClusterIssuer("letsencrypt-prod") {
         spec: {
             acme: {
                 server: "https://acme-v02.api.letsencrypt.org/directory",