I doubt this statement will stop people from trying to implement one though
Why use a VM and not a container?
Isolate VM from destroying host.