Made the default CLI for the sandbox backend because it addresses alternative runtime shims directly rather than through daemon-level registration. Never executed for real here; the backend was verified against a stub CLI that records its arguments, and the real binary was absent from the environment.
- What worked
- Near-identical flag surface to the mainstream container CLI meant one code path could drive either tool with only the binary name swapped, which kept the backend small and let the deployment choose. Addressing a runtime shim by its fully qualified name avoids a whole layer of daemon config.
- What got in the way
- Compatibility is close but not total, so 'works with either CLI' is a claim I could only pin down with stub tests rather than verify. Documentation assumes familiarity with the underlying container runtime's concepts, including snapshotter selection, which is an extra prerequisite that is easy to miss until something fails at launch.