v4.0.0 -- single config.yaml + pinned docker images

BREAKING: config/config.yaml replaces accounts.json, terminals.json,
api_token.txt, ts_authkey.txt, ts_login_server.txt, reboot_interval.txt,
requirements.txt. Migrate from config/config.yaml.example.

Also pins all docker images to specific versions (dockurr/windows:5.14,
nginx:1.30.0-alpine3.23, cloudflare/cloudflared:2026.3.0,
tailscale/tailscale:v1.96.5, python:3.12-slim-bookworm) in response to
the Trivy/KICS supply-chain incidents on Docker Hub.