skip to content

Externalized Configuration & Profiles

Everything about getting configuration into a Boot app: property source precedence, type-safe binding, validation, profiles, config import and secrets, environment post-processing, and IDE metadata. Config questions are practical and they separate people who have deployed from people who have only run locally.

part ofSpring Frameworkoverview, primer and where to startread it →
on this pageshow

explore

questions

page 1 of 2

What is @ConfigurationProperties and how does it differ from @Value?

level: juniorimportance: must knowfreq 78%

answer

  1. group vs single value
  2. prefix + type-safe bean
  3. @Value = one placeholder, no relaxed binding
  4. must register the bean
  5. type conversion via Binder

basics

~10 s

@ConfigurationProperties binds a whole group of external properties (from application.yml/properties/env) onto the fields of a POJO in a type-safe way. @Value injects a single property value into one field using a placeholder expression.

solid answer

~40 s

@ConfigurationProperties maps a tree of external configuration (prefixed keys from application.yml, .properties, environment variables) onto a strongly-typed Java bean, converting types and supporting nested objects, lists and maps. You bind once per group and get compile-time-friendly, testable config. @Value injects one value at a time via a SpEL/placeholder string like ${server.port}, with no relaxed binding, no nested-object support, and no built-in validation. Use @ConfigurationProperties for cohesive groups of settings (recommended by Spring Boot); use @Value for a single, occasionally-computed value. To activate a @ConfigurationProperties bean you either annotate it and register with @EnableConfigurationProperties, put @Component on it, or let @ConfigurationPropertiesScan discover it.

code

java · 22 lines
java
@ConfigurationProperties(prefix = "app.mail")
public class MailProperties {
    private String host;
    private int port = 25;
    private List<String> bcc = new ArrayList<>();

    public String getHost() { return host; }
    public void setHost(String host) { this.host = host; }
    public int getPort() { return port; }
    public void setPort(int port) { this.port = port; }
    public List<String> getBcc() { return bcc; }
    public void setBcc(List<String> bcc) { this.bcc = bcc; }
}

@Configuration
@EnableConfigurationProperties(MailProperties.class)
class MailConfig {
    @Bean
    MailSender sender(MailProperties props) {
        return new SmtpMailSender(props.getHost(), props.getPort());
    }
}

go deeper

for a junior

Know it's type-safe group binding by prefix vs @Value's single-value placeholder.

for a middle

Explain activation options and the relaxed-binding/validation/nested differences from @Value.

for a senior

Discuss the Binder, conversion service, and when each approach is architecturally appropriate.

for a principal

Frame config as a bounded, validated, testable contract; standardize on @ConfigurationProperties and metadata for the whole codebase.

## The problem it solves Applications read settings from *external configuration*: `application.properties`/`application.yml`, environment variables, command-line args, etc. Spring exposes all of these through the `Environment`. You could pull each value out one by one, but that scatters config all over the code and gives no type safety. ## @ConfigurationProperties `@ConfigurationProperties` (package `org.springframework.boot.context.properties`) binds a *group* of external properties sharing a common `prefix` onto the fields of a Java/Kotlin bean. ```java @ConfigurationProperties(prefix = "app.mail") public class MailProperties { private String host; // binds app.mail.host private int port; // binds app.mail.port private List<String> bcc; // binds app.mail.bcc[0], [1], ... // getters/setters } ``` Given: ```yaml app: mail: host: smtp.example.com port: 587 bcc: [[email protected], [email protected]] ``` Spring instantiates the bean, walks its properties, and binds each one, performing **type conversion** (String -> int, List, Duration, DataSize, enums, etc.) via the `Binder` and the `ApplicationConversionService`. ## Activating the bean A `@ConfigurationProperties` class is *not* a bean by itself. You must register it one of these ways: 1. `@EnableConfigurationProperties(MailProperties.class)` on a `@Configuration` class. 2. Put `@Component` (or `@ConfigurationProperties` on a `@Bean` factory method). 3. Use `@ConfigurationPropertiesScan` to auto-discover all `@ConfigurationProperties`-annotated classes in given packages. ## @Value contrast `@Value("${server.port}")` injects **one** value using property placeholders (and can use SpEL, e.g. `@Value("#{systemProperties['x']}")`). Differences: - **Granularity**: one value vs. a whole group. - **Relaxed binding**: `@ConfigurationProperties` supports it; `@Value` does **not** — the placeholder must match the exact property name. - **Nested/collection binding**: only `@ConfigurationProperties`. - **Validation**: `@ConfigurationProperties` supports JSR-303 `@Validated`; `@Value` does not (natively). - **Metadata**: `@ConfigurationProperties` participates in IDE metadata (`spring-configuration-metadata.json`). ## When to use which Use `@ConfigurationProperties` for cohesive configuration (recommended default in Spring Boot). Use `@Value` for a single standalone value or when you need a small SpEL computation. ## Gotchas - Forgetting to register the bean -> nothing binds, all fields null/default. - With classic (setter) binding you need setters; missing setters silently skip fields. - `@Value` cannot bind a list/map from a single property cleanly.

  • How do you make a @ConfigurationProperties class an actual Spring bean?
    Register it via @EnableConfigurationProperties(X.class), annotate it with @Component, expose it from an @Bean method, or enable @ConfigurationPropertiesScan to auto-discover it.
  • Can @Value use relaxed binding?
    No. @Value placeholders must match the exact property name; relaxed binding (kebab/camel/underscore equivalence) applies only to @ConfigurationProperties.

saying these in an interview costs you the question

  • Claiming @Value supports relaxed binding
  • Saying a @ConfigurationProperties class becomes a bean automatically without any registration
  • Thinking @Value can bind nested objects or lists like @ConfigurationProperties

context

open as a page

What does the `spring.config.import` property do, and what is the effect of the `optional:` prefix?

level: juniorimportance: must knowfreq 55%

basics

~10 s

spring.config.import tells Spring Boot to pull in extra config from another location (a file, config tree, etc.) during startup. optional: means: if that location is missing, don't fail — just skip it.

open as a page

What is the spring-boot-configuration-processor, and what does adding it to your build produce?

level: juniorimportance: must knowfreq 55%

basics

~10 s

It is a compile-time annotation processor. When you add it as a dependency, it scans your @ConfigurationProperties classes during compilation and generates META-INF/spring-configuration-metadata.json, which IDEs read to give auto-completion and docs for your properties.

open as a page

What is a Spring profile and how do you activate one?

level: juniorimportance: must knowfreq 80%

basics

~10 s

A profile is a named group of beans and config that is only active in certain environments (like dev or prod). You turn it on with the property spring.profiles.active, e.g. spring.profiles.active=dev.

open as a page

In Spring Boot, if the same property (say server.port) is set in application.properties AND passed as a command-line argument, which value wins and why?

level: juniorimportance: must knowfreq 70%

basics

~10 s

The command-line argument wins. Spring Boot reads config from many places (property sources). When a key exists in several, the higher-priority source overrides the others, and command-line arguments outrank application.properties.

open as a page

How do you make Spring Boot validate an @ConfigurationProperties class at startup with JSR-380 constraints?

level: juniorimportance: must knowfreq 45%

basics

~10 s

Put Spring's @Validated on the @ConfigurationProperties class, add constraint annotations like @NotNull or @Min on the fields, and include spring-boot-starter-validation so a Bean Validation provider (Hibernate Validator) is on the classpath.

open as a page

Explain relaxed binding: what property-name forms map to the same field?

level: middleimportance: must knowfreq 70%

basics

~10 s

Relaxed binding lets one bean field be filled from several property-name spellings — kebab-case, camelCase, snake_case, and UPPER underscore. So app.my-prop, app.myProp, app.my_prop and APP_MYPROP all bind to the same field.

open as a page

How do you register an EnvironmentPostProcessor so Spring Boot actually invokes it, and why can't it be a @Component?

level: middleimportance: must knowfreq 55%

basics

~10 s

List its fully-qualified class name in META-INF/spring.factories under the key org.springframework.boot.env.EnvironmentPostProcessor. It can't be a @Component because it runs before the application context and component scanning exist.

open as a page

How does a `configtree:` import map a directory of files to Spring properties?

level: middleimportance: must knowfreq 50%

basics

~20 s

configtree: points at a directory. Each file becomes one property: the file's path (relative to the tree root) is the property name, and the file's contents is the value. It's built for secret files mounted as volumes.

open as a page

How do profile-specific config files like application-{profile}.yaml load and override the base application.yaml?

level: middleimportance: must knowfreq 65%

basics

~10 s

Spring Boot always loads application.yaml first, then loads application-{profile}.yaml for each active profile on top of it. Values in the profile-specific file override the same keys in the base file.

open as a page

Where does Spring Boot look for application.properties/application.yml by default, in what order, and how do profile-specific files fit in?

level: middleimportance: must knowfreq 65%

basics

~10 s

By default Spring Boot searches four locations: classpath root, classpath /config, the current working directory, and a ./config folder. Locations outside the jar override packaged ones, and profile-specific files (application-{profile}.properties) override the plain file.

open as a page

What is an EnvironmentPostProcessor in Spring Boot and at what point in startup does it run?

level: juniorimportance: should knowfreq 45%

basics

~10 s

It is a Spring Boot hook that can add or change configuration properties very early in startup — while the Environment is being prepared, before the application context and any beans are created.

open as a page

Compare @ConfigurationPropertiesScan, @EnableConfigurationProperties, and @Component for registering config beans.

level: middleimportance: should knowfreq 48%

basics

~10 s

@EnableConfigurationProperties(X.class) registers specific classes. @ConfigurationPropertiesScan auto-discovers all @ConfigurationProperties classes in given packages. @Component makes one a bean via component scanning. All make the config bean available for injection; you pick one per class.

open as a page

Inside postProcessEnvironment, how do you add a PropertySource and control whether it overrides or defers to existing configuration?

level: middleimportance: should knowfreq 40%

basics

~10 s

Get environment.getPropertySources() (a MutablePropertySources) and call addFirst to make your source win over others, or addLast to act only as a fallback. You can also use addBefore/addAfter relative to a named source.

open as a page

What is additional-spring-configuration-metadata.json and when do you need it?

level: middleimportance: should knowfreq 40%

basics

~10 s

It is a hand-written file in src/main/resources/META-INF/ where you add metadata the processor cannot infer — like value hints, descriptions, or deprecations. At compile time the processor merges it into the generated spring-configuration-metadata.json.

open as a page

How do you mark a @ConfigurationProperties property as deprecated in the metadata, and what do the deprecation levels mean?

level: middleimportance: should knowfreq 30%

basics

~20 s

Annotate the getter with @DeprecatedConfigurationProperty(reason, replacement) and the processor emits a deprecation entry, so the IDE warns users. You can also declare it manually in additional-spring-configuration-metadata.json with a deprecation block having level warning or error.

open as a page

How does multi-document YAML with the profile activation property work in a single application.yaml?

level: middleimportance: should knowfreq 55%

basics

~10 s

You split one YAML file into sections with '---'. Each section can be tagged with 'spring.config.activate.on-profile: prod' so its properties only apply when that profile is active. It keeps env-specific config in one file.

open as a page

How do OS environment variables map to Spring property names (relaxed binding), and what is SPRING_APPLICATION_JSON used for?

level: middleimportance: should knowfreq 50%

basics

~20 s

Because shells only allow uppercase letters, digits, and underscores, Spring Boot uses 'relaxed binding': an env var like SPRING_DATASOURCE_URL maps to spring.datasource.url (dots become underscores, uppercased). SPRING_APPLICATION_JSON lets you inject many properties at once as a single JSON string.

open as a page

How does Spring Boot bind strings like "30s" or "10MB" to Duration and DataSize, and how do you control default units?

level: middleimportance: should knowfreq 30%

basics

~10 s

The binder's converters turn suffixed strings into java.time.Duration and org.springframework.util.unit.DataSize. Suffixes like s/m/h and B/KB/MB/GB are parsed automatically; use @DurationUnit and @DataSizeUnit to set the unit for bare numbers.

open as a page

What exactly happens at startup when a validated @ConfigurationProperties value violates a constraint?

level: middleimportance: should knowfreq 35%

basics

~20 s

Binding fails, so the bean can't be created and the Spring application context fails to start. Boot logs a formatted error naming the property, the offending value, and the reason, then the process exits non-zero.

open as a page

How does constructor binding work and how does it enable immutable @ConfigurationProperties?

level: seniorimportance: should knowfreq 55%

basics

~20 s

Bind values through the constructor instead of setters, so fields can be final and the config object is immutable. In Spring Boot 3 a single non-default constructor triggers constructor binding automatically; you no longer need setters.

open as a page

When would you use @Value with SpEL, and what are its limits versus @ConfigurationProperties?

level: seniorimportance: should knowfreq 45%

basics

~10 s

Use @Value for a single value, optionally computed with SpEL (#{...}) or defaulted (${prop:default}). Its limits: no relaxed binding, no nested/collection binding, no built-in validation, and it resolves eagerly per injection point.

open as a page

Why is logging problematic inside an EnvironmentPostProcessor, and what does Spring Boot provide to solve it?

level: seniorimportance: should knowfreq 30%

basics

~20 s

EPPs run before the logging system is fully initialized, so normal loggers may be silently dropped or misconfigured. Spring Boot lets you inject a DeferredLogFactory into the EPP constructor; its logs are buffered and replayed once logging is ready.

open as a page

How does Spring Boot bind sensitive values supplied via environment variables, and where do env vars and imported config trees sit in the property-source precedence order?

level: seniorimportance: should knowfreq 45%

basics

~20 s

An env var like SPRING_DATASOURCE_PASSWORD maps via relaxed binding to spring.datasource.password. OS environment variables sit high in precedence — above application.properties/application.yml — so they override committed defaults, which is exactly what you want for secrets.

open as a page

How do you wire Kubernetes Secrets into a Spring Boot app using config trees, and why is that preferable to putting secrets in committed config or a ConfigMap?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Mount the Secret as a volume so each key becomes a file, then spring.config.import=optional:configtree:/etc/secrets/. Spring reads the files as properties. Secrets stay out of the image, out of git, and out of ConfigMaps (which aren't encrypted).

open as a page

How do value hints and hint providers work in configuration metadata, including hints for Map keys and values?

level: seniorimportance: should knowfreq 28%

basics

~20 s

A hint entry links to a property by name and supplies either a static list of suggested values or a provider that computes suggestions dynamically (e.g. class-reference, logger-name, handle-as). For maps you target property.keys or property.values.

open as a page

What is spring.profiles.group and why would you use it?

level: seniorimportance: should knowfreq 45%

basics

~10 s

spring.profiles.group lets you define a named group of profiles so activating one profile automatically activates several others. For example, activating 'prod' can pull in 'db-prod' and 'metrics' together.

open as a page

Walk through Spring Boot's documented property-source precedence order from lowest to highest priority. Where do config files, OS env vars, SPRING_APPLICATION_JSON, and command-line args sit?

level: seniorimportance: should knowfreq 55%

basics

~20 s

Roughly, from lowest to highest: framework defaults, then application.properties/yml config files, then OS environment variables, then Java system properties, then SPRING_APPLICATION_JSON, then command-line arguments, then test overrides. Higher sources override lower ones for the same key.

open as a page

How do you cascade validation to nested @ConfigurationProperties objects, and what are the common reasons validation silently does nothing?

level: seniorimportance: should knowfreq 25%

basics

~20 s

Put @Valid on the nested field/property to cascade constraints into the child object. Validation silently does nothing when there is no validation provider on the classpath, when the class lacks Spring's @Validated, or when the nested object isn't marked @Valid.

open as a page

Design a secrets-management strategy for a Spring Boot service across local, CI, and Kubernetes prod. What are the tradeoffs of env vars vs config trees vs an external secrets manager, and how do you keep secrets from leaking through Spring's own surfaces (actuator, logs)?

level: principalimportance: should knowfreq 28%

basics

~20 s

Commit only non-secret defaults. Locally use an untracked file or env vars; in CI use masked pipeline secrets; in prod mount Kubernetes Secrets as a config tree (optional:configtree:) or pull from Vault. Lock down /actuator/env, rely on Boot's sanitizer, and never log secret values.

open as a page

showing 1–30 of 35