update pods/status
Overwrite a pod's status fields (conditions, podIP, phase).
Forging status.podIP makes kube-proxy program that IP into the pod's EndpointSlice, redirecting or blackholing live Service traffic until the kubelet reverts it seconds later.
Forging the Ready condition briefly drops a healthy backend from a Service or inserts an unhealthy one.
Needs only update on pods/status, not endpoint write access.
pods/proxy is unaffected, resolving the pod's real address through the kubelet.
- API Group
- (core)
- Scope
- namespaced
- Audit Level
- Request
Escalation Paths
Hold update on the pods/status subresource, a grant separate from update on pods itself.
The kubelet normally owns these fields
Forge status.podIP on a Service backend pod.
The EndpointSlice controller copies the forged IP into the EndpointSlice, and kube-proxy then programs it into the dataplane
Forging the Ready condition is the weaker variant, since probe-less pods do not pick it up, so the podIP route is the reliable one
The kubelet reverts status within seconds, but kube-proxy consumes the forged state during that window.
A slow readiness probe cadence widens it
No write access to Services, Endpoints, or EndpointSlices is required
Additional rights needed:
Note:
No admission control or field ownership prevents this.
The EndpointSlice adopts a forged status.podIP as written and Service traffic drops during the window, which the kubelet closes in about two seconds.

