For production software, you should
always have an upper limit on
everything.
There is always a point where you can tell in advance that it doesn't make sense to keep going. It is never sensible to literally go on forever with anything -- it can only break stuff in annoying ways when it runs into real world limitations (like financial ones in that case.)
I sound aggressive about this because it's such a common mistake. It always goes something like,
"Why does this list have to be unbounded?"
"Well, we don't want to give the user an error because it's full."
"Okay, but does it really need to support 35,246,953 instances?"
"Sure, why not?"
"How long would the main interaction with the system take if you stress it to that level?"
"Oh, I don't know, at that level it might well take 20 minutes."
"And the clients usually timeout after?..."
"5 seconds."
"Would the user rather wait for 20 minutes and then get a response that might be outdated by that time, or get an error right away?"
"They may well prefer the error at that point."
"So let's go backwards from that. Will it ever make sense to support more than 250,000 instances?"
"That corresponds to the five second timeout and then some. I guess that's fine in practise..."
It's not that hard!