Docker is not a security boundary?

[deleted]

That's defined in context, security is a spectrum with tradeoffs

OCI supports far more and has a much bigger ecosystem