You can explore this a bit further and set up some net namespaces, connect them to the host vm via a bridge device, assign them ipv6 addresses from the vm host /64 network, and then set up a default route inside each container to the /32 or /40 you're using via the vm host's address on the host local /64. It's cool to see one container on host 1 talk to another on host 2. You're basically subnetting the /40 for each host; each host is analogous to a household in 6rd, and the containers are like your devices on your lan with globally routable ipv6 addresses (except we're using a ULA prefix instead of a globally routable ipv6 prefix assigned to an ISP, so our containers are not globally addressable - whatever). I'd guess this is what the CNI thing you mention does under the hood. For others who are interested in this, it's basically combining OP's article with https://iximiuz.com/en/posts/container-networking-is-simple/ from a couple months ago.
The Teredo part was very interesting as well, I had not thought to worry about non-udp/tcp compatible intermediate systems.