On my bare-metal server I use VMs to isolate certain network concerns like my mail server and my VPN (WireGuard) server. Regarding WireGuard, this was necessary because the host (Debian Buster) does not (or rather: did not) support it. Furthermore, I do not want to allow the host OS (and the services running in Docker) access to my internal networks.
My VMs are managed using libvirt/virt-manager (over SSH).