skip to content

Which Actuator endpoints are reachable over HTTP by default in a Spring Boot app, and how do you expose additional ones?

level: juniorimportance: must knowfreq 78%

answer

  1. default web = health only
  2. web.exposure.include / .exclude
  3. `*` = all, quote it in YAML
  4. exposed AND enabled both required
  5. JMX has its own include/exclude

basics

~10 s

By default only the health endpoint is exposed over the web. To expose more, list their IDs (or * for all) in management.endpoints.web.exposure.include, e.g. include=health,info,metrics.

solid answer

~40 s

Spring Boot Actuator ships built-in endpoints (health, info, metrics, env, beans, loggers, etc.), but for safety only `health` is exposed over HTTP out of the box — the rest exist but are not reachable at `/actuator/**`. You widen web exposure with the property `management.endpoints.web.exposure.include`, giving a comma-separated list of endpoint IDs, or `*` to expose them all (in YAML `*` must be quoted). Example: `management.endpoints.web.exposure.include=health,info,metrics`. JMX exposure is controlled by a separate, independent property (`management.endpoints.jmx.exposure.include`). Note that exposure and enablement are different gates: an endpoint must be enabled AND exposed to be reachable, and `info` is not exposed by default either — only `health` is.

code

java · 14 lines
java
// application.properties
// Only `health` is reachable by default:
//   GET /actuator/health  -> 200
//   GET /actuator/metrics -> 404 (not exposed)

// Opt extra endpoints in over HTTP:
management.endpoints.web.exposure.include=health,info,metrics,loggers

// Equivalent YAML (note the required quotes on the wildcard):
// management:
//   endpoints:
//     web:
//       exposure:
//         include: "*"

go deeper

for a junior

Must know: default is health-only over HTTP; widen with management.endpoints.web.exposure.include.

for a middle

Should distinguish exposure from enablement and know the wildcard/YAML-quoting detail.

for a senior

Frames health-only default as a security posture and reaches for explicit allow-lists over *.

for a principal

Ties exposure defaults to attack surface, separate management port, and org-wide platform conventions.

## What Actuator exposure means Spring Boot **Actuator** (the `spring-boot-starter-actuator` dependency) adds production-monitoring **endpoints** — small management APIs identified by an **ID** such as `health`, `info`, `metrics`, `env`, `beans`, `loggers`, `mappings`, `threaddump`, `heapdump`, `shutdown`. Each endpoint can be surfaced over two **technologies**: - **Web (HTTP)** — reachable under the base path, default `/actuator` (e.g. `GET /actuator/health`). - **JMX** — reachable through JMX MBeans. "Exposure" is the mechanism that decides *which* endpoints are actually reachable over each technology. ## The default: health only over the web Because endpoints can leak sensitive data (config, environment variables, bean graph, heap dumps), Spring Boot is conservative: **by default only the `health` endpoint is exposed over HTTP**. Every other endpoint is registered in the context but returns 404 over the web until you opt it in. (Older tutorials sometimes say `health` and `info` — current Spring Boot exposes only `health` by default over the web.) ## Controlling web exposure Two properties per technology: - `management.endpoints.web.exposure.include` — comma-separated list of endpoint IDs to expose. Special value `*` means *all* endpoints. - `management.endpoints.web.exposure.exclude` — IDs to hide; **exclude wins over include**. Examples: ```properties # expose three specific endpoints over HTTP management.endpoints.web.exposure.include=health,info,metrics # expose everything management.endpoints.web.exposure.include=* ``` In **YAML** the wildcard is a reserved character and must be quoted: `include: "*"`. ## Two independent gates: enabled vs exposed Exposure is not the same as **enablement** (`management.endpoint.<id>.enabled`). An endpoint is reachable only if it is BOTH *enabled* AND *exposed*. Almost all endpoints are enabled by default; `shutdown` is the notable exception (disabled by default). So `include=*` still will not surface `shutdown` unless you also enable it. ## Web vs JMX are separate JMX has its own pair of properties (`management.endpoints.jmx.exposure.include` / `.exclude`). Changing web exposure does not change JMX exposure and vice-versa. (JMX itself is off by default in modern Spring Boot via `spring.jmx.enabled=false`.) ## Common gotchas - Adding the actuator starter does NOT automatically expose `metrics`/`env` over HTTP — only `health`. - Forgetting to quote `*` in YAML causes a parse error. - Exposing `*` in production is risky; prefer an explicit allow-list or a separate management port.

  • You added the actuator starter but `/actuator/metrics` returns 404. Why?
    The `metrics` endpoint is enabled but not exposed over the web by default — only `health` is. Add `metrics` (or `*`) to `management.endpoints.web.exposure.include`.
  • Does setting web exposure also change what's visible over JMX?
    No. Web and JMX have independent exposure property pairs; JMX is controlled by `management.endpoints.jmx.exposure.include/exclude`, and JMX is disabled by default in modern Spring Boot.

saying these in an interview costs you the question

  • Thinking all endpoints are exposed over HTTP as soon as you add the starter
  • Believing `info` is exposed by default over the web (only `health` is)
  • Confusing 'enabled' with 'exposed' — assuming enabling an endpoint makes it web-reachable

context