Adds a StepRunUpdater step that starts app-dono-updater after the app
container comes up: a poll loop (docker pull, compare image IDs,
recreate on change) baked into the official docker:cli image via
`sh -c`, reusing the same docker run argv as the initial container
start so the two can't drift.
Not built on Watchtower: containrrr/watchtower was archived upstream
in Dec 2025 with no maintained successor recommended for production
use, so this avoids taking on that dependency.
DownloadImageCmd and DownloadWireguardImageCmd were identical except for
the image URL. Collapse them into one DownloadImageCmd that takes the
image as a parameter, passing imageName/wireguardImageName at the call
sites.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>