How do the include and exclude exposure properties interact, and what does the `*` wildcard do?
answer
- include vs exclude pair per technology
- exclude WINS over include
- `*` = all *enabled* endpoints
- quote `*` in YAML
- allow-all-but pattern
basics
~10 sinclude lists IDs to expose (or * for all); exclude lists IDs to hide. Exclude takes precedence over include, so include=* with exclude=env,beans exposes everything except those two.
solid answer
~30 sEach technology (web, JMX) has an `exposure.include` and `exposure.exclude` property holding comma-separated endpoint IDs. `include` picks what's visible, `*` being a wildcard for all enabled endpoints. `exclude` removes IDs, and **exclude always wins over include** — this lets you say 'expose everything except the dangerous ones': `management.endpoints.web.exposure.include=*` plus `management.endpoints.web.exposure.exclude=env,beans,heapdump`. The wildcard must be quoted in YAML (`"*"`). Both sets operate only on *enabled* endpoints — a disabled endpoint like `shutdown` won't appear even under `include=*`. The exclude-wins rule is the key gotcha: if an ID is in both lists, it stays hidden.
code
java · 9 lines// application.properties — expose everything over HTTP except the risky ones
management.endpoints.web.exposure.include=*
management.endpoints.web.exposure.exclude=env,beans,configprops,heapdump
// Result over the web:
// /actuator/health, /actuator/metrics, /actuator/loggers ... -> reachable
// /actuator/env, /actuator/beans, /actuator/configprops -> 404 (exclude wins)
// /actuator/shutdown -> 404 (disabled by default,
// '*' can't expose it)go deeper
Knows include adds endpoints; may not know the exclude-precedence rule.
Must articulate exclude-wins and the allow-all-but pattern with quoted *.
Uses exclude-precedence deliberately to shrink surface and explains the enabled-set interaction.
Standardizes an org-wide 'expose-all-but-sensitive' policy and reasons about config drift/silent excludes.
## The two property pairs Exposure is configured per technology with two properties each: | Technology | Include | Exclude | |---|---|---| | Web | `management.endpoints.web.exposure.include` | `management.endpoints.web.exposure.exclude` | | JMX | `management.endpoints.jmx.exposure.include` | `management.endpoints.jmx.exposure.exclude` | Each holds a **comma-separated list of endpoint IDs** (e.g. `health,info,metrics`). ## The wildcard `*` `*` is a special token meaning **all endpoints**. It only ever includes/excludes endpoints that are **enabled** — it does not resurrect disabled ones. In **YAML** `*` starts an alias, so it must be quoted: ```yaml management: endpoints: web: exposure: include: "*" ``` In `.properties` files no quoting is needed: `management.endpoints.web.exposure.include=*`. ## Precedence: exclude beats include The evaluation rule is simple and important: **`exclude` takes precedence over `include`.** If an endpoint ID appears in both (directly, or via `*` in include and by name in exclude), it is **not** exposed. This enables the common 'allow-all-but' pattern: ```properties management.endpoints.web.exposure.include=* management.endpoints.web.exposure.exclude=env,beans,configprops,heapdump,threaddump ``` Here every enabled endpoint is web-reachable except the sensitive ones you listed. ## Interaction with enablement Exposure filters only over the set of **enabled** endpoints (`management.endpoint.<id>.enabled`, or the global `management.endpoints.enabled-by-default`). `shutdown` is disabled by default, so `include=*` will not expose it — you must enable it first. Conversely, enabling an endpoint does nothing for web reachability unless it is also in the include set (minus exclude). ## Web and JMX are independent The web pair and the JMX pair are evaluated separately. `web.exposure.include=*` says nothing about JMX visibility, and vice-versa. ## Gotchas - **Exclude silently wins** — a developer who adds an ID to include and later someone else lists it in exclude will see it disappear; there's no error. - **Unquoted `*` in YAML** throws a parse/alias error. - **`*` ≠ every endpoint that exists** — only enabled ones. - Whitespace in the list is trimmed, but relying on it is fragile; keep IDs tight.
- An endpoint ID is in both include and exclude. Is it exposed?No. Exclude takes precedence, so it stays hidden — with no error or warning.
- Does `include=*` expose the shutdown endpoint?No. `shutdown` is disabled by default and `*` only covers enabled endpoints; you must set `management.endpoint.shutdown.enabled=true` first.
saying these in an interview costs you the question
- Claiming include wins over exclude
- Thinking `*` exposes disabled endpoints like shutdown
- Forgetting the wildcard must be quoted in YAML