Replace the stale generic runner provisioning docs with an accurate description of the actual two-container setup on the Hetzner VPS. Document the nsenter pattern for running host-level commands (systemctl) from containerised CI steps, and the Caddyfile symlink contract that the reload step depends on. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>