We use lxcfs mounts through the docker cpi to ensure the containers and processes don't attempt to take more memory than they should.
Turns out, when bpm creates containers for processes, because it does not explicitly mount the information, it defaults back to the host vm information. It'd be great if processes managed by bpm in docker deployed envs maintained the memory limits that were provided to it. I can imagine this might also extend to other type of information that bpm could/should explicitly mount into the containers it is creating.