Actuator exposes application operational endpoints, and its health response must be paired with an intentional exposure and authorization policy.
Spring Boot Actuator health: public liveness without public diagnostics
This lesson uses the downloadable source kit: Java 21, Spring Boot 4.0.8 and its managed Spring Framework 7 dependencies. The version is pinned for repeatable builds.
Expose only the intended endpoints
The kit exposes health and info and allows anonymous access only to the health path. Its real HTTP test checks an UP response without component details. That is a narrow monitoring contract, not blanket permission to inspect configuration, beans or environment values.
A service being alive is different from being ready to accept a particular workload. Database reachability can influence health while the service still has a depleted pool or overloaded worker queue. Define readiness according to the admission rule used by the deployment.
Shutdown needs a bounded drain
The packaged properties request graceful server shutdown and a ten-second lifecycle phase timeout. The test context is closed after HTTP checks so its server, pool and beans do not leak into later tests.
This test verifies endpoint access and context closure; it does not simulate an orchestrator, a long-running request or a killed process. Production drain behavior needs a deployment-level test that stops admission and observes outstanding work.
Checked source
receipt.import.batch-size=32
receipt.import.timeout=5s
spring.datasource.url=jdbc:h2:mem:receipt_application
spring.datasource.username=sa
spring.datasource.password=
management.endpoints.web.exposure.include=health,info
management.endpoint.health.show-details=never
server.shutdown=graceful
spring.lifecycle.timeout-per-shutdown-phase=10sTest the boundary
Run mvn test in the source-kit directory. HttpSecurityBoundaryTest.publicHealthIsAvailableWithoutCredentials checks the behavior described here. Java excerpts belong to the named source-kit classes; they are not independent source files unless the complete class is shown.
Costs and boundaries
Health checks can call contributors whose cost depends on dependencies. Avoid exposing detailed diagnostic data publicly, and avoid treating an expensive health query as a free request path.
Common Mistakes
- Do not expose every management endpoint publicly.
- Liveness and workload readiness are different contracts.
- Graceful shutdown properties are not proof of deployment drain behavior.
Read next
Spring Security filter chain: authentication, CSRF and request order, Spring lifecycle cleanup: close container-owned resources, Java bounded executors: test saturation and rejected work.
Extend this boundary
Continue with Spring Boot metrics: bound tag values instead of tracking each receipt.
Continue with Spring delivery contracts
Continue with Spring readiness: report an unavailable dependency without forcing liveness failure.
Continue with checked worker recovery
Continue with At-least-once delivery: where Spring outbox retries can duplicate work.
Continue with checked upload and readiness
Continue with Spring Boot liveness versus readiness: do not restart on every dependency outage.
