Optionally disabling cgroups
Would you be interested in an option to disable cgroups? This would mean that ia-sandbox could be used for sandboxing (though obviously without cgroup-based limits) without needing any administrator support to create the user-accessible cgroups.