skip to content

How do the include and exclude exposure properties interact, and what does the `*` wildcard do?

level: middleimportance: should knowfreq 62%

answer

  1. include vs exclude pair per technology
  2. exclude WINS over include
  3. `*` = all *enabled* endpoints
  4. quote `*` in YAML
  5. allow-all-but pattern

basics

~10 s

include lists IDs to expose (or * for all); exclude lists IDs to hide. Exclude takes precedence over include, so include=* with exclude=env,beans exposes everything except those two.

solid answer

~30 s

Each technology (web, JMX) has an `exposure.include` and `exposure.exclude` property holding comma-separated endpoint IDs. `include` picks what's visible, `*` being a wildcard for all enabled endpoints. `exclude` removes IDs, and **exclude always wins over include** — this lets you say 'expose everything except the dangerous ones': `management.endpoints.web.exposure.include=*` plus `management.endpoints.web.exposure.exclude=env,beans,heapdump`. The wildcard must be quoted in YAML (`"*"`). Both sets operate only on *enabled* endpoints — a disabled endpoint like `shutdown` won't appear even under `include=*`. The exclude-wins rule is the key gotcha: if an ID is in both lists, it stays hidden.

code

java · 9 lines
java
// application.properties — expose everything over HTTP except the risky ones
management.endpoints.web.exposure.include=*
management.endpoints.web.exposure.exclude=env,beans,configprops,heapdump

// Result over the web:
//   /actuator/health, /actuator/metrics, /actuator/loggers ... -> reachable
//   /actuator/env, /actuator/beans, /actuator/configprops    -> 404 (exclude wins)
//   /actuator/shutdown                                        -> 404 (disabled by default,
//                                                                     '*' can't expose it)

go deeper

for a junior

Knows include adds endpoints; may not know the exclude-precedence rule.

for a middle

Must articulate exclude-wins and the allow-all-but pattern with quoted *.

for a senior

Uses exclude-precedence deliberately to shrink surface and explains the enabled-set interaction.

for a principal

Standardizes an org-wide 'expose-all-but-sensitive' policy and reasons about config drift/silent excludes.

## The two property pairs Exposure is configured per technology with two properties each: | Technology | Include | Exclude | |---|---|---| | Web | `management.endpoints.web.exposure.include` | `management.endpoints.web.exposure.exclude` | | JMX | `management.endpoints.jmx.exposure.include` | `management.endpoints.jmx.exposure.exclude` | Each holds a **comma-separated list of endpoint IDs** (e.g. `health,info,metrics`). ## The wildcard `*` `*` is a special token meaning **all endpoints**. It only ever includes/excludes endpoints that are **enabled** — it does not resurrect disabled ones. In **YAML** `*` starts an alias, so it must be quoted: ```yaml management: endpoints: web: exposure: include: "*" ``` In `.properties` files no quoting is needed: `management.endpoints.web.exposure.include=*`. ## Precedence: exclude beats include The evaluation rule is simple and important: **`exclude` takes precedence over `include`.** If an endpoint ID appears in both (directly, or via `*` in include and by name in exclude), it is **not** exposed. This enables the common 'allow-all-but' pattern: ```properties management.endpoints.web.exposure.include=* management.endpoints.web.exposure.exclude=env,beans,configprops,heapdump,threaddump ``` Here every enabled endpoint is web-reachable except the sensitive ones you listed. ## Interaction with enablement Exposure filters only over the set of **enabled** endpoints (`management.endpoint.<id>.enabled`, or the global `management.endpoints.enabled-by-default`). `shutdown` is disabled by default, so `include=*` will not expose it — you must enable it first. Conversely, enabling an endpoint does nothing for web reachability unless it is also in the include set (minus exclude). ## Web and JMX are independent The web pair and the JMX pair are evaluated separately. `web.exposure.include=*` says nothing about JMX visibility, and vice-versa. ## Gotchas - **Exclude silently wins** — a developer who adds an ID to include and later someone else lists it in exclude will see it disappear; there's no error. - **Unquoted `*` in YAML** throws a parse/alias error. - **`*` ≠ every endpoint that exists** — only enabled ones. - Whitespace in the list is trimmed, but relying on it is fragile; keep IDs tight.

  • An endpoint ID is in both include and exclude. Is it exposed?
    No. Exclude takes precedence, so it stays hidden — with no error or warning.
  • Does `include=*` expose the shutdown endpoint?
    No. `shutdown` is disabled by default and `*` only covers enabled endpoints; you must set `management.endpoint.shutdown.enabled=true` first.

saying these in an interview costs you the question

  • Claiming include wins over exclude
  • Thinking `*` exposes disabled endpoints like shutdown
  • Forgetting the wildcard must be quoted in YAML

context