The attack surface of a micro VM is tiny compared with that of a full Linux kernel. That's the issue.
If your complaint is that container implementations leave the hardening scope to other tools, then sure, but I would argue that's just philosophy difference between the unix approach of do one thing and do it well, and chain tools together to solve problems, and the approach of one program to rule them all.