docs: add multi-backend isolation design
- Add DESIGN.md documenting key architectural decisions
- Update README with isolation modes diagram and "under construction" warning
- Update ROADMAP to reflect container backend as next priority
Three isolation levels:
- none: Direct Nix execution (dev mode)
- container: OCI containers with debian-slim + seccomp (any Linux VPS)
- firecracker: MicroVMs with full isolation (bare-metal + KVM)
Auto-detection picks the best available backend.
Co-Authored-By: Claude <noreply@anthropic.com>