Alright, so 'ipa idrange-find' returns the same values on all 6 servers.
However, ldapsearch -x -D 'cn=Directory Manager' -W -b 'cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config'
returns different results on 1 (the one where I don't get that warning with the healthcheck) The other 5 return
dnaMagicRegen: -1 dnaMaxValue: 1100 dnaNextValue: 1101 dnaScope: dc=ipa,dc=superb,dc=net dnaSharedCfgDN: cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ipa,dc=superb,dc=net dnaThreshold: 500 dnaType: uidNumber dnaType: gidNumber objectClass: top objectClass: extensibleObject
Which seems to match your blog post from 2015 about this.
Since I cannot be sure which IPA server will be used when enrolling new hosts, would it be best to try to fix this? I suppose the same can be said for when new users are added. If done manually I can be sure it will be done on the same host, but we have an internal system that also creates the user in IPA and I think that would just use whichever one is closest.