setup the newer policy preventing mgmt cluster deletion before upgrading 'cluster' unit
!3078 (merged) modified the Kyverno prevent-mgmt-cluster-delete Kyverno policies, to avoids the issue described in #1741 (closed). But to ensure that this issue does not trigger during the upgrade from Sylva 1.1.1, we need to have the policy be updated before the cluster unit is updated, which is what this MR ensures.
(I actually observed pipelines where #1741 (closed) occurs event after the merge of !3078 (merged), precisely because the new fixed policy isn't enabled yet when cluster unit starts to reconcile - https://gitlab.com/sylva-projects/sylva-core/-/jobs/8122242018#L1033)
Useful background information: units on which the cluster unit does not depend on (the case of the unit defining our policy here, before this MR) are set to depend on cluster-machines-ready and will hence reconcile after cluster unit. Code at https://gitlab.com/sylva-projects/sylva-core/-/blob/5a7d83fc612f58becd3f57c9424e4cde98446d24/charts/sylva-units/values.yaml#L250-261. By making cluster unit depend on our unit we ensure that things happen in the desired order.