Installs Node.js and act_runner in host mode, registers the runner as the unprivileged webapp user, and wires up systemd units for the runner and the next-start service. A narrow sudoers rule lets the runner restart only webapp.service; the build/deploy itself is driven by the repo workflow.