I don't know if userland vs kernel is the appropriate way to characterize the debate.
But yes there is a question of how unprivileged users can take advantage of the facilities cgroups offer, and how we can integrate cgroup support cleanly into containers.
Last I heard mount --bind /cgroupfs/my/group /path/to/container/cgroupfs
worked as a good approximation to what many people want.
I have not had a chance to look at it in any detail beyond that. It is nothing fundamentally hard it is just something that someone familiar with all the details needs to spend some time and to iron out.