Or use something like GKE where the containers should be running directly on hardware, so you only have one layer.
Doing a little research: GKE runs on https://cloud.google.com/container-optimized-os/docs/ which is designed for GCE, which runs on KVM: https://cloud.google.com/compute/docs/faq
So it looks like just Triton and Red Shift.
Disclaimer: I used to work at Red Hat, which means I like the people behind Red Shift, but that also means I hate the people behind Triton as part of the early 2000s Linux/Solaris wars.
I'm 99% sure that Google runs one VM per container because that's the only way to make it safe.
Anything else would be insane.
Hypervisors are much, much harder to break out of than a Linux container.
I'm 100% sure you are wrong. You might as well just use VMs.
Containers are not only about safety, you know.