The runner isolation design listed per-build resource limits as a separate decision. With builds in containers they are one podman flag each, and the threat model's not-audited list still names resource exhaustion.
-cpus and -memory are passed to podman run only when set; unset means
uncapped rather than a default that could kill a job. bay1's drop-in sets
-cpus 3 of the host's 4, leaving a core for gitbayd and sshd during a build,
and no memory cap: the e2e suite peaks past 5GB of the 7GB, and a cap that kills
the suite is an outage, not a limit.
TestLimitArgs pins the unset-means-absent behaviour.
Ref #144