What are the /actuator/threaddump, /actuator/heapdump and /actuator/httpexchanges endpoints, and what does each return?
answer
- threaddump = jstack over HTTP (thread states + locks)
- heapdump = binary .hprof, open in MAT/VisualVM
- httpexchanges needs an HttpExchangeRepository bean
- only health exposed by default
- add to management.endpoints.web.exposure.include
basics
~10 sThey are Spring Boot Actuator diagnostic endpoints. threaddump returns a snapshot of all JVM threads and their states, heapdump downloads a binary .hprof memory-dump file, and httpexchanges shows the most recent HTTP request/response exchanges.
solid answer
~40 sAll three are Spring Boot Actuator endpoints for live diagnostics. GET /actuator/threaddump returns a snapshot of every JVM thread (name, state, stack trace, held/waited locks) as JSON, or plain text with Accept: text/plain. GET /actuator/heapdump streams a binary HPROF (.hprof) file — a full dump of heap objects you open in a tool like Eclipse MAT or VisualVM. GET /actuator/httpexchanges lists recently captured HTTP server request/response pairs, but only works if an HttpExchangeRepository bean exists (Spring Boot no longer auto-configures one). By default only /actuator/health is exposed over HTTP; you must add the others to management.endpoints.web.exposure.include. They are sensitive — heapdump and threaddump can leak secrets — so keep them off the public internet.
code
yaml · 10 lines# application.yml — expose the diagnostic endpoints over HTTP
management:
endpoints:
web:
exposure:
include: health,threaddump,heapdump,httpexchanges
httpexchanges:
recording:
include: request-headers,response-headers,principal,remote-address
# NOTE: httpexchanges still needs an HttpExchangeRepository @Bean to appear.go deeper
Know what each endpoint returns and that they are Actuator diagnostics under /actuator.
Know the exposure model (only health by default) and that heapdump is a binary .hprof.
Know httpexchanges needs a repository bean and the httptrace→httpexchanges rename in Boot 3.
Frame the security/operational tradeoffs of exposing memory/thread state over HTTP.
## What Actuator is **Actuator** is Spring Boot's operational module (`spring-boot-starter-actuator`) that exposes management endpoints under `/actuator`. These three are the built-in *diagnostic* endpoints. ## /actuator/threaddump Backed by the `ThreadDumpEndpoint` class. A GET returns a point-in-time snapshot of every live JVM thread: - its name, - `Thread.State` (NEW, RUNNABLE, BLOCKED, WAITING, TIMED_WAITING, TERMINATED), - priority, - the full stack trace, - and lock information (which monitors/synchronizers it holds and what it is blocked/waiting on). The default response is JSON (media type `application/vnd.spring-boot.actuator.v3+json`); send header `Accept: text/plain` to get the classic `jstack`-style text. It is the equivalent of `jstack <pid>` but reachable over HTTP. Use it to diagnose hangs, deadlocks, thread-pool exhaustion, and CPU-hot loops. ## /actuator/heapdump Backed by `HeapDumpWebEndpoint`. A GET produces a **binary HPROF file** (conventionally `.hprof`) by calling the JVM's `HotSpotDiagnosticMXBean.dumpHeap(...)`. By default it captures a *live* heap dump (only reachable objects, after a full GC). The response is served as a downloadable attachment (`application/octet-stream`). - The file contains **every object on the heap** — so it is roughly the size of your used heap (hundreds of MB to GB) and includes String contents, so passwords, tokens, PII and credentials in memory are all captured. - Open it in **Eclipse Memory Analyzer (MAT)**, **VisualVM**, or **JProfiler** to find leaks / dominators. - Taking a dump triggers a **stop-the-world pause** proportional to heap size — it can freeze the app for seconds. ## /actuator/httpexchanges Backed by `HttpExchangesEndpoint`. It lists recently recorded HTTP *server* exchanges (method, URI, status, selected headers, timing). Crucially, since Spring Boot 3.0 (and effectively since 2.2) **no repository bean is auto-configured**, so the endpoint is only registered if you define an `HttpExchangeRepository` bean yourself — typically `InMemoryHttpExchangeRepository` (default capacity 100, a ring buffer, lost on restart). In Boot 2.x this endpoint was named `httptrace` with `HttpTraceRepository`; it was renamed in 3.0. You can tune what is captured via `management.httpexchanges.recording.include` (e.g. REQUEST_HEADERS, RESPONSE_HEADERS, PRINCIPAL, REMOTE_ADDRESS) and disable it with `management.httpexchanges.recording.enabled=false`. ## Exposure & security Endpoints are *enabled* by default but only `health` is *exposed over the web* by default. To reach the others over HTTP you add them to `management.endpoints.web.exposure.include` (e.g. `health,threaddump,heapdump,httpexchanges` or `*`). Because they reveal internal state (heapdump literally dumps memory), always protect them — restrict with: - Spring Security, - a separate management port, - or the fact that they are cluster-internal only. Never expose heapdump/threaddump publicly.
- Which of the three is available over HTTP by default with no configuration?None of them. By default only /actuator/health is exposed over the web; you must add threaddump/heapdump/httpexchanges to management.endpoints.web.exposure.include (and httpexchanges also needs a repository bean).
- How do you get a plain-text (jstack-style) thread dump instead of JSON?Send the request with header Accept: text/plain, e.g. curl -H 'Accept: text/plain' localhost:8080/actuator/threaddump.
saying these in an interview costs you the question
- Thinking all three endpoints are exposed over HTTP by default
- Believing heapdump returns JSON or human-readable text rather than a binary .hprof
- Assuming httpexchanges works out of the box without any bean