Security as applicable to a pve environment isnt really any different than any other virtualization platform, which means any hardening policies that would be best practices generically or even specifically to another platform (eg, vmware) would be just as applicable here.
I would say this is overly broad statement. On the opposite extreme side of the spectrum, I could state that if one truly wants mitigations, layers of separation, etc. ... just forget the whole KVM (let alone LXC) and go with Xen. So platforms-wise this part differs. Of course it impacts e.g. performance.
For the rest regarding networking, that would be true, but then again if it was a serious take, the firewall needs to be on a separate hardware box. Then you could continue adding up IDS, etc. if those VMs are really exposed to the outside.
BTW What did you mean specifically about the issues with passwordless root?