Indeed, there are other options, but a VM is the only one in which I feel safe that I do not screw up the configuration somehow. Docker can punch through a firewall, what other “obvious” settings exist in whatever lockdown option I pick?
Barring a VM escape exploit, I know that my private data is not getting exposed.