Container options must be runtime-portable
Hammerkit exposes a container runtime option only if it translates to every runtime hammerkit targets (Docker and Kubernetes). The initial options are shmSize and securityOpt (seccomp): shmSize maps to Docker HostConfig.ShmSize and a Kubernetes in-memory emptyDir at /dev/shm; securityOpt maps to Docker HostConfig.SecurityOpt and Kubernetes securityContext.seccompProfile.
ulimits and devices are deliberately excluded: Kubernetes has no pod/container-spec equivalent (ulimits are node/kubelet-level; host devices go through Device Plugins). Exposing them would create a Docker-only option that silently no-ops or errors on Kubernetes — violating Platform-Agnostic. Other portable options (capAdd/capDrop, privileged, sysctls, tmpfs) translate to both but are deferred until a concrete need.
Consequences
- A future Docker-only option request is rejected by this principle unless a Kubernetes translation exists.
- Removes the need for a "no Kubernetes equivalent → report explicitly" code path: every exposed option works on both runtimes.