Please see the comment I linked about Spectre specifically: https://news.ycombinator.com/item?id=18280156
I actually think our approach to Spectre -- focusing on preventing the observation of the side channel, rather than blocking speculation -- is likely to be more robust against Spectre variants that haven't been revealed yet. Case in point, we developed some of our core mitigations before we knew about Spectre at all.
Spectre affects containers and VMs too.