Append a NoExecute toleration to an already-running Pod.
Tolerations are one of the few pod spec fields accepted after creation, and only as additions, so the patch appends rather than replaces
An incident responder later taints the suspect node NoExecute to evict everything running on it
The taint manager evicts every Pod without a matching toleration.
The pre-patched Pod is skipped and keeps running
A backdoor Pod outlives the exact response action meant to remove it from the node

