Hold update on the pods/status subresource, a grant separate from update on pods itself.
The kubelet normally owns these fields
Forge status.podIP on a Service backend pod.
The EndpointSlice controller copies the forged IP into the EndpointSlice, and kube-proxy then programs it into the dataplane
Forging the Ready condition is the weaker variant, since probe-less pods do not pick it up, so the podIP route is the reliable one
The kubelet reverts status within seconds, but kube-proxy consumes the forged state during that window.
A slow readiness probe cadence widens it
No write access to Services, Endpoints, or EndpointSlices is required
Note:
No admission control or field ownership prevents this.
The EndpointSlice adopts a forged status.podIP as written and Service traffic drops during the window, which the kubelet closes in about two seconds.

