This ranking is very close to how I see this. Anything after Docker/Podman is out unless I absolutely need an application in which case keeping a record of dependencies is a good idea. But I want to know the work system will absolutely start in the morning hours from a deadline. Avoiding single points of failure is another way of course (ie multiple systems, OSes, backups, password managers etc).
My understanding is that sandboxing is not mandatory for Snaps, but it is for flatpaks. Some of the Snap code not being open source, and generally the technology being centralised around Canonical apparently is off-putting for some.