See: http://stackoverflow.com/questions/16084741/how-do-i-set-res...
Everything else? VMs it is. The overhead is so low nowadays that it's totally irrelevant for the vast majority of use cases.
I do Devops, and Docker provides very little benefit in production (unless you're an org with your own non-cloud computing resources, where you're going to orchestrate with something like Kubernetes; even then, there's dissent in the ranks between that project and Docker).
Now the interesting thing about docker is you can control this in similar ways you'd do to control this via VMs and that is via kernel primitives (cgroups) to control resource allocation. In general if you are running docker containers in production you should be explicitly allocating resources via cgroups according to the needs of your applications. If you are writing and deploying software that fork bombs (why?) then you should mitigate the effects of the noisy neighbor via the kernel features. The benefit here is you don't need the (extremely, IMO) heavyweight overhead of running separate OSes in VMs.