The fact that tensorflow takes up 12.9TiB is truly horrifying, and most of that because they use pypi's storage as a dumping ground for their pre-release packages. What a nightmare they've put on other people's shoulders.
There's a lot more checks and balances built into rust as a language, so the foot-gun opportunities are less likely - which makes it rather suitable for reliable systems programming.
And getting back to this particular case... kanidm is fast AND reliable. There's a lot of testing going on comparing it to 389 DS.
2FA on SaaS applications is free and easy, while centralising authentication is much harder - you need to manage an authentication platform instead of just using the application's own authentication.
Taken by itself the suggestion is odd, but in concert with the next entry "use password management software" it makes for a low-cost, zero management, higher security stance than not suggesting 2FA by itself. Noone should ever ignore the option to turn on 2FA.