The fab pipeline needs .gitlab/configs and the two KiCad libraries, but
not kicad-ci's own nested submodules (kicad-footprint-generator,
ki-ntree) — those are footprint-generation and InvenTree tooling.
Recursive checkout pulled them and failed on an SSH gitlab.com URL
baked into older kicad-ci commits.
Gitea's per-job token is scoped to the calling repo, so cross-repo
private submodules (micromelon-kicadlibs, micromelon_3d) fail with
'Repository not found'. Callers now pass SUBMODULE_TOKEN, a PAT scoped
to read:repository, through to actions/checkout.
The previous reusable used container: jobs, which cannot work on this
runner — the kicad_auto images have no Node, so actions/checkout's post
step dies with exit 127. It had never run successfully. This replaces it
with the docker-run design that keeb debugged into working, plus the
kicad10_auto bump and the artifact-path and @v3 pinning fixes.