Generate namespace guardrails for build and test namespaces from the company's build size tiers: a LimitRange (defaults and per-container maximums, memory limit = request), a ResourceQuota sized for expected concurrency, and a kube-janitor rules entry that gives unannotated test environments a default TTL (a standalone janitor CronJob is available only for clusters without kube-janitor). Use after gke-cost-discovery has produced build-tiers.json, when a namespace has no LimitRange, or when test environments are left running.