Hey everyone, been a deep Okta user for years, mainly for employee SSO and managing our marketing tech stack access. Recently, our engineering team led a switch to Ping Identity, specifically citing our growing Kubernetes (K8s) infrastructure as a big reason.
I'm trying to bridge my marketing ops perspective with this more infra-focused move. From my side, Okta's UI and integration gallery were fantastic for onboarding new martech tools quickly. But the devs were adamant about Ping's advantages for our K8s clusters.
Their main points were:
* **Native K8s Auth:** Ping seems to have a more streamlined path for authenticating into the Kubernetes API itself, often using something like PingFederate with the K8s OIDC connector. They said it felt less "bolted on."
* **Workload Identity:** They're exploring service-to-service auth in K8s, and Ping's approach to workload identity seemed to align better with their service mesh architecture.
* **Policy Granularity:** They needed very fine-grained access controls for different namespaces, and found Ping's policy engine more flexible for dynamic, ephemeral K8s environments.
For me, the switch meant re-learning some admin tasks and a slightly less polished UI. But I'm curious—has anyone else here, especially those managing hybrid tech stacks (marketing apps *and* containerized infra), made a similar comparison?
**Key question:** Is Ping genuinely *better* for K8s, or was it just a better fit for our specific implementation? What are the trade-offs for the non-infra use cases like application SSO?
Cheers, Henry