Agreed, and even things like Keycloak/FreeIPA are only partial solutions.

FreeIPA in particular is a beast to maintain, it puts kubernetes-cowboys to shame.