Create secrets dir in bwrap

Since the mountpoint for the tmpfs used for playbook secrets may
itself be on a read-only bind mount inside the bubblewrap environment,
ensure that it is created before bwrap runs.

Change-Id: I493d1b33500c23d4e2c1458247345cc751757a0b
diff --git a/zuul/executor/server.py b/zuul/executor/server.py
index 1a445f1..3c1dbb0 100644
--- a/zuul/executor/server.py
+++ b/zuul/executor/server.py
@@ -256,6 +256,7 @@
         self.ansible_config = os.path.join(self.root, 'ansible.cfg')
         self.project_link = os.path.join(self.root, 'project')
         self.secrets_root = os.path.join(self.root, 'secrets')
+        os.makedirs(self.secrets_root)
         self.secrets = os.path.join(self.secrets_root, 'secrets.yaml')
         self.secrets_content = None