anywhere you want hard isolation and only a subset of OS. especially multiple instances thereof.
so, generally at the edge (gateways, shims, protocol boundaries)