The external-attacher CSI sidecar reconciles VolumeAttachment objects and reads status.attached to decide whether a volume is still attached to a node
Write status.attached false through the volumeattachments/status subresource.
The same write aimed at the main resource returns success and is silently dropped
Against a driver with attachRequired true the attacher restores status.attached in the same second, and a pod writing to that volume is unaffected
The kubelet reads status.attached at attach and mount time, so a pod already holding the volume never re-reads it.
Changing the object does not remove the device under a running workload
spec is immutable after creation, so an attachment cannot be retargeted to another node or volume.
Only the reported state can be corrupted
Inert without a registered CSI driver running an external-attacher sidecar.
On a cluster with no such driver, the object is reconciled by nothing
Note:
The subresource write is the only path that lands; a status patch through the main resource is dropped without error.
The attacher reconciles the flip back, so the result is a redundant attach call.
A driver whose attach is a no-op absorbs it; one doing real work may not.

