Kubetier
  1. The external-attacher CSI sidecar reconciles VolumeAttachment objects and reads status.attached to decide whether a volume is still attached to a node

  2. Write status.attached false through the volumeattachments/status subresource.

    The same write aimed at the main resource returns success and is silently dropped

  3. Against a driver with attachRequired true the attacher restores status.attached in the same second, and a pod writing to that volume is unaffected

  4. The kubelet reads status.attached at attach and mount time, so a pod already holding the volume never re-reads it.

    Changing the object does not remove the device under a running workload

  5. spec is immutable after creation, so an attachment cannot be retargeted to another node or volume.

    Only the reported state can be corrupted

  6. Inert without a registered CSI driver running an external-attacher sidecar.

    On a cluster with no such driver, the object is reconciled by nothing

Note:

The subresource write is the only path that lands; a status patch through the main resource is dropped without error.

The attacher reconciles the flip back, so the result is a redundant attach call.

A driver whose attach is a no-op absorbs it; one doing real work may not.

K8s docs ↗