Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Spring Security health probes: expose only the health path

Last updated: 30 Sept 20264 min read
tutorial
IntermediateBy AITrove Editorial

A public health probe exception should match the intended Actuator health path without opening application data routes.

Download Spring source kit

The source-kit matcher

ReceiptSecurity permits /actuator/health and /actuator/health/**, then requires authentication for every other request. The readiness HTTP test calls the nested readiness path without credentials and receives 200 or 503 according to the indicator. It then calls /api/receipts anonymously and receives 401. The matcher change is small, but the test checks both allowed and protected outcomes.

This does not settle whether health details should be public. The kit configures show-details=never. A deployed management port, reverse proxy or platform probe may use another exposure model. The group lesson covers status mapping; the filter-chain lesson covers matcher order and defaults.

Treat the path as operational data

Health response bodies should avoid secrets, hostnames and raw dependency errors. Allowlisting a probe endpoint does not authorize a business endpoint, even when both share one server. Check any custom Actuator base path after deployment; hard-coded matchers can drift if the endpoint moves. This test checks only the kit's default /actuator path, one nested health group and the receipt API.

Checked source

Java
http.authorizeHttpRequests(requests -> requests
    .requestMatchers("/actuator/health", "/actuator/health/**").permitAll()
    .anyRequest().authenticated());

Verification boundary

ReadinessHealthGroupHttpTest.failedImportStoreWithdrawsReadinessWithoutChangingLiveness and HttpSecurityBoundaryTest.apiRejectsAnonymousRequest in the downloadable Spring source kit. The excerpt is shortened; the kit contains the complete test.

Costs and limits

The test has no external gateway, custom management port or changed Actuator base path. Public health paths still consume server resources and can reveal status; rate and detail policies belong to the deployment design. No sensitive details are enabled in the kit.

Common Mistakes

  • Do not permit every Actuator endpoint to expose health probes.
  • Do not expose raw dependency errors in public health details.
  • Do not skip an anonymous API denial assertion.

Read next

Spring Boot readiness health group: withdraw traffic on a required dependency failure, Spring Boot liveness versus readiness: do not restart on every dependency outage, Spring Security filter chain: authentication, CSRF and request order, Spring Boot Actuator health: public liveness without public diagnostics.

spring
spring-boot
health-probe-security
Storage details