Secure the Patroni REST API to prevent misuse, like the commented example [here](https://github.com/canonical/postgresql-k8s-operator/pull/26#discussion_r955963163).