Readiness controls whether a process should receive new traffic; liveness answers whether restarting it may help.
Spring readiness during termination: stop routing before stopping dependencies
Withdraw traffic in order
An instance about to stop should become unavailable to routing before its database pool or worker resources are torn down. Otherwise a load balancer can send a new receipt command into a half-closed application. Spring's availability state and Actuator health groups provide a place to expose that decision, but the platform's probe interval and ingress drain delay determine when traffic actually stops.
The existing HTTP test forces a test dependency DOWN and sees readiness return 503 while liveness remains 200. That does not test a termination event. External database trouble should not automatically turn liveness into failure; repeated restarts can increase the outage.
Measure the routing lag
A release test needs the real platform: withdraw readiness, timestamp the final routed request, then allow in-flight work to finish under the stop budget. Record errors across old and new instances while the rollout occurs. A loopback GET against one instance cannot show what the ingress did.
Keep the health response narrow. The security fixture exposes nested health paths without opening the API. Internal dependency details should remain protected, while the platform receives only the status it needs to route traffic.
Working sketch
management.endpoint.health.probes.enabled=true
# Measure platform probe and routing lag during the actual rollout.Verification boundary
ReadinessHealthGroupHttpTest checks local health groups and API access; no termination-routing test exists.
Costs and limits
No ingress, platform probe interval, SIGTERM path or multi-instance rollout is measured.
Common Mistakes
- Do not tear down a required dependency before traffic is withdrawn.
- Do not make every external outage a liveness failure.
- Do not expose full health details on a public probe path.
Read next
Spring Boot readiness health group: withdraw traffic on a required dependency failure, Spring Boot liveness versus readiness: do not restart on every dependency outage, Spring Security health probes: expose only the health path, Spring Boot graceful shutdown: finish accepted requests within a deadline.
