Kubetier
  1. Hold update on the pods/status subresource, a grant separate from update on pods itself.

    The kubelet normally owns these fields

  2. Forge status.podIP on a Service backend pod.

    The EndpointSlice controller copies the forged IP into the EndpointSlice, and kube-proxy then programs it into the dataplane

  3. Forging the Ready condition is the weaker variant, since probe-less pods do not pick it up, so the podIP route is the reliable one

  4. The kubelet reverts status within seconds, but kube-proxy consumes the forged state during that window.

    A slow readiness probe cadence widens it

  5. No write access to Services, Endpoints, or EndpointSlices is required

Note:

No admission control or field ownership prevents this.

The EndpointSlice adopts a forged status.podIP as written and Service traffic drops during the window, which the kubelet closes in about two seconds.

K8s docs ↗