Just some initial feedback, not even half-way through yet.
What currently happens is that the domain is created in LDAP, including the collateral OUs and roles and the likes.
It would just not have the necessary inetdomainstatus value:
query_filter = (&(objectclass=domainrelatedobject)(associateddomain=%s)(inetdomainstatus=*)(!(inetdomainstatus=deleted)))
This type of query filter may be adjusted to be the value of the bitflip though, and I've found the way to perform an LDAP query with said integer value against a bitwise.