Kubetier
← Permission Reference
T2

update pods/status

Overwrite a pod's status fields (conditions, podIP, phase).

Forging status.podIP makes kube-proxy program that IP into the pod's EndpointSlice, redirecting or blackholing live Service traffic until the kubelet reverts it seconds later.

Forging the Ready condition briefly drops a healthy backend from a Service or inserts an unhealthy one.

Needs only update on pods/status, not endpoint write access.

pods/proxy is unaffected, resolving the pod's real address through the kubelet.

API Group
(core)
Scope
namespaced
Audit Level
Request

Escalation Paths

  1. Hold update on the pods/status subresource, a grant separate from update on pods itself.

    The kubelet normally owns these fields

  2. Forge status.podIP on a Service backend pod.

    The EndpointSlice controller copies the forged IP into the EndpointSlice, and kube-proxy then programs it into the dataplane

  3. Forging the Ready condition is the weaker variant, since probe-less pods do not pick it up, so the podIP route is the reliable one

  4. The kubelet reverts status within seconds, but kube-proxy consumes the forged state during that window.

    A slow readiness probe cadence widens it

  5. No write access to Services, Endpoints, or EndpointSlices is required

Additional rights needed:

none

Note:

No admission control or field ownership prevents this.

The EndpointSlice adopts a forged status.podIP as written and Service traffic drops during the window, which the kubelet closes in about two seconds.

K8s docs ↗

Included in Built-in Roles

K8s docs ↗