Which Actuator endpoints are reachable over HTTP by default in a Spring Boot app, and how do you expose additional ones?
answer
- default web = health only
- web.exposure.include / .exclude
- `*` = all, quote it in YAML
- exposed AND enabled both required
- JMX has its own include/exclude
basics
~10 sBy default only the health endpoint is exposed over the web. To expose more, list their IDs (or * for all) in management.endpoints.web.exposure.include, e.g. include=health,info,metrics.
solid answer
~40 sSpring Boot Actuator ships built-in endpoints (health, info, metrics, env, beans, loggers, etc.), but for safety only `health` is exposed over HTTP out of the box — the rest exist but are not reachable at `/actuator/**`. You widen web exposure with the property `management.endpoints.web.exposure.include`, giving a comma-separated list of endpoint IDs, or `*` to expose them all (in YAML `*` must be quoted). Example: `management.endpoints.web.exposure.include=health,info,metrics`. JMX exposure is controlled by a separate, independent property (`management.endpoints.jmx.exposure.include`). Note that exposure and enablement are different gates: an endpoint must be enabled AND exposed to be reachable, and `info` is not exposed by default either — only `health` is.
code
java · 14 lines// application.properties
// Only `health` is reachable by default:
// GET /actuator/health -> 200
// GET /actuator/metrics -> 404 (not exposed)
// Opt extra endpoints in over HTTP:
management.endpoints.web.exposure.include=health,info,metrics,loggers
// Equivalent YAML (note the required quotes on the wildcard):
// management:
// endpoints:
// web:
// exposure:
// include: "*"go deeper
Must know: default is health-only over HTTP; widen with management.endpoints.web.exposure.include.
Should distinguish exposure from enablement and know the wildcard/YAML-quoting detail.
Frames health-only default as a security posture and reaches for explicit allow-lists over *.
Ties exposure defaults to attack surface, separate management port, and org-wide platform conventions.
## What Actuator exposure means Spring Boot **Actuator** (the `spring-boot-starter-actuator` dependency) adds production-monitoring **endpoints** — small management APIs identified by an **ID** such as `health`, `info`, `metrics`, `env`, `beans`, `loggers`, `mappings`, `threaddump`, `heapdump`, `shutdown`. Each endpoint can be surfaced over two **technologies**: - **Web (HTTP)** — reachable under the base path, default `/actuator` (e.g. `GET /actuator/health`). - **JMX** — reachable through JMX MBeans. "Exposure" is the mechanism that decides *which* endpoints are actually reachable over each technology. ## The default: health only over the web Because endpoints can leak sensitive data (config, environment variables, bean graph, heap dumps), Spring Boot is conservative: **by default only the `health` endpoint is exposed over HTTP**. Every other endpoint is registered in the context but returns 404 over the web until you opt it in. (Older tutorials sometimes say `health` and `info` — current Spring Boot exposes only `health` by default over the web.) ## Controlling web exposure Two properties per technology: - `management.endpoints.web.exposure.include` — comma-separated list of endpoint IDs to expose. Special value `*` means *all* endpoints. - `management.endpoints.web.exposure.exclude` — IDs to hide; **exclude wins over include**. Examples: ```properties # expose three specific endpoints over HTTP management.endpoints.web.exposure.include=health,info,metrics # expose everything management.endpoints.web.exposure.include=* ``` In **YAML** the wildcard is a reserved character and must be quoted: `include: "*"`. ## Two independent gates: enabled vs exposed Exposure is not the same as **enablement** (`management.endpoint.<id>.enabled`). An endpoint is reachable only if it is BOTH *enabled* AND *exposed*. Almost all endpoints are enabled by default; `shutdown` is the notable exception (disabled by default). So `include=*` still will not surface `shutdown` unless you also enable it. ## Web vs JMX are separate JMX has its own pair of properties (`management.endpoints.jmx.exposure.include` / `.exclude`). Changing web exposure does not change JMX exposure and vice-versa. (JMX itself is off by default in modern Spring Boot via `spring.jmx.enabled=false`.) ## Common gotchas - Adding the actuator starter does NOT automatically expose `metrics`/`env` over HTTP — only `health`. - Forgetting to quote `*` in YAML causes a parse error. - Exposing `*` in production is risky; prefer an explicit allow-list or a separate management port.
- You added the actuator starter but `/actuator/metrics` returns 404. Why?The `metrics` endpoint is enabled but not exposed over the web by default — only `health` is. Add `metrics` (or `*`) to `management.endpoints.web.exposure.include`.
- Does setting web exposure also change what's visible over JMX?No. Web and JMX have independent exposure property pairs; JMX is controlled by `management.endpoints.jmx.exposure.include/exclude`, and JMX is disabled by default in modern Spring Boot.
saying these in an interview costs you the question
- Thinking all endpoints are exposed over HTTP as soon as you add the starter
- Believing `info` is exposed by default over the web (only `health` is)
- Confusing 'enabled' with 'exposed' — assuming enabling an endpoint makes it web-reachable