An existing configtree file can still contain a value that fails typed configuration validation.
Spring Boot configtree validation: reject a present but unsafe value
Load, bind, then validate
The local file mounted-values/relay/batch-size exists and contains 0. Boot finds the tree, binds the setting and rejects it because the relay record requires a batch size from 1 through 100. The child exits nonzero without printing a successful bound result. The absent-directory case fails earlier, before the value is read.
This distinction matters during rollout. A successful file lookup does not mean the application can safely process work. A value can be empty, malformed, out of range, or inconsistent with another setting. The fixture checks only the out-of-range integer. The typed validation lesson explains the bean constraint.
Keep the error report safe
The checked value is non-secret. A production validation failure may include the rejected value in logs, so do not use a secret property as the demonstration. A sensitive property should have a redacted diagnostic and a separate presence or format check. The source kit has no credential-bearing configtree test.
A file may also change after startup. This test does not establish runtime refresh, atomic file replacement or the behavior of a running worker during rotation.
Checked source
// mounted-values/relay/batch-size contains 0
@Min(1) @Max(100) int batchSize
// Child process exits before BOUND_BATCH is printed.Verification boundary
RelaySettingsProcessTest.invalidValueInFileTreeFailsValidation. The full fixture is in the downloadable source kit.
Common Mistakes
- Do not call a readable file a valid configuration.
- Do not include a secret value in a binding-error screenshot.
- Do not infer runtime reload from a startup validation test.
Read next
Spring Boot configtree: bind one file per property in a child JVM, Spring Boot required configtree: reject an absent directory, Spring Boot configuration validation: reject an unusable relay before work starts, Spring Boot file-tree tests: prove binding without claiming secret delivery.
