It turns out that the cn=tools.mzmcbride,ou=servicegroups,dc=wikimedia,dc=org record is not present on the primary LDAP server:
$ ldapsearch -xLLL -b cn=tools.mzmcbride,ou=servicegroups,dc=wikimedia,dc=org -H ldap://ldap-rw.eqiad.wikimedia.org:389 No such object (32) Matched DN: ou=servicegroups,dc=wikimedia,dc=org
But it is present on the replica used in Cloud VPS:
$ ldapsearch -xLLL -b cn=tools.mzmcbride,ou=servicegroups,dc=wikimedia,dc=org -H ldap://ldap-ro.eqiad.wikimedia.org:389 dn: cn=tools.mzmcbride,ou=servicegroups,dc=wikimedia,dc=org objectClass: groupOfNames objectClass: posixGroup objectClass: top member: uid=mzmcbride,ou=people,dc=wikimedia,dc=org cn: tools.mzmcbride gidNumber: 51334
Attempting to delete the record directly from ldap-ro.eqiad.wikimedia.org fails (as hoped honestly):
delete member:
uid=mzmcbride,ou=people,dc=wikimedia,dc=org
modifying entry "cn=tools.mzmcbride,ou=servicegroups,dc=wikimedia,dc=org"
ldap_modify: Server is unwilling to perform (53)
additional info: operation restrictedCan some local LDAP wizard like @MoritzMuehlenhoff or @akosiaris help figure out how to re-sync ldap-ro.eqiad.wikimedia.org with ldap-rw.eqiad.wikimedia.org?