A public health probe exception should match the intended Actuator health path without opening application data routes.
Spring Security health probes: expose only the health path
The source-kit matcher
ReceiptSecurity permits /actuator/health and /actuator/health/**, then requires authentication for every other request. The readiness HTTP test calls the nested readiness path without credentials and receives 200 or 503 according to the indicator. It then calls /api/receipts anonymously and receives 401. The matcher change is small, but the test checks both allowed and protected outcomes.
This does not settle whether health details should be public. The kit configures show-details=never. A deployed management port, reverse proxy or platform probe may use another exposure model. The group lesson covers status mapping; the filter-chain lesson covers matcher order and defaults.
Treat the path as operational data
Health response bodies should avoid secrets, hostnames and raw dependency errors. Allowlisting a probe endpoint does not authorize a business endpoint, even when both share one server. Check any custom Actuator base path after deployment; hard-coded matchers can drift if the endpoint moves. This test checks only the kit's default /actuator path, one nested health group and the receipt API.
Checked source
http.authorizeHttpRequests(requests -> requests
.requestMatchers("/actuator/health", "/actuator/health/**").permitAll()
.anyRequest().authenticated());Verification boundary
ReadinessHealthGroupHttpTest.failedImportStoreWithdrawsReadinessWithoutChangingLiveness and HttpSecurityBoundaryTest.apiRejectsAnonymousRequest in the downloadable Spring source kit. The excerpt is shortened; the kit contains the complete test.
Costs and limits
The test has no external gateway, custom management port or changed Actuator base path. Public health paths still consume server resources and can reveal status; rate and detail policies belong to the deployment design. No sensitive details are enabled in the kit.
Common Mistakes
- Do not permit every Actuator endpoint to expose health probes.
- Do not expose raw dependency errors in public health details.
- Do not skip an anonymous API denial assertion.
Read next
Spring Boot readiness health group: withdraw traffic on a required dependency failure, Spring Boot liveness versus readiness: do not restart on every dependency outage, Spring Security filter chain: authentication, CSRF and request order, Spring Boot Actuator health: public liveness without public diagnostics.
