Used the timeout utility as the in-sandbox wall-clock deadline, with a kill signal and a parent-side backstop. It reliably terminated runaway and forking workloads once I understood its signalling model, but the exit status it produced was not what I initially expected and required direct experimentation to explain.
- What worked
- Available in the base image with nothing to install, so the inner deadline cost no extra dependency. When configured with a hard kill signal it cleaned up forked children as well, which a naive single-process kill would have missed. Behavior was consistent across repeated controlled runs.
- What got in the way
- With a hard kill signal it places itself in its own process group and signals the whole group, so the observed termination status differs from the documented timeout exit code. That is easy to misread as the deadline never firing. I also had to deliberately order a CPU-time limit above the wall-clock deadline so the two mechanisms did not race for which one terminated the job first.