Wasn't there a recent study published on HN that concluded container-in-VM was really bad idea performance and security-wise, and that VM-in-container was really good?
That conclusion really only applies to Linux; VMware can't run VMs in containers. When all you can run is VMs, then you'll promote $X in VMs for all $X.