How do you change network configuration, load balancers or other external configuration in lock step with your application? Scripting by hand?
And deployments are a just small part of configuration management. How do you find out which of your applications use libz 1.2.3 (to measure CVE applicability for example)? By looking in each and every one of them?
How do you find out which application run a cron job? And which application connect to backend x without going through the load balancer?
Which application has a client certificate about to expire? How do you guarantee two applications have the same shared secret, and change it in lock step?
With configuration management all this is just a look up away. And best of all, most of this information is authoritative.
When I come somewhere new, the use of these tools instead of a directory of miscellaneous scripts is like night and day. It literally turns a two day job into a ten minute one when the environments are complex.
Docker is great for a lot of things. It enables to do daring things to your environment even if it's so complex you don't fully understand it all because you can just shuffle containers around. But I would never use it instead of configuration management.