Create a CRD that registers a conversion webhook pointing at an attacker-controlled server.
Reads or writes that require version conversion are routed through the webhook, which can read and rewrite those objects in flight.
The API server requires a CA bundle and TLS, so this needs a serving certificate the API server will accept.

