Turn off automountServiceAccountToken for deployments that don't need it
As seen in the kas chart we are adding in !1465 (merged)
We can have the service account token not automounted for pods that don't need it.
We should go ahead and do that for the pods that aren't going to need to talk to the k8s api at all. (And probably make user configurable for the ones that can optionally use the api, like rails)