To be honest, with "cloud-init" and the ability for SSSD to send record updates, I could make a worthwhile cloudy deployment

To your point, people don't, but it's a perfectly viable path.

Containers/kubernetes, that's pipeline city, baby!