skip to content

Actuator Endpoints & Exposure

The Actuator endpoint surface: what ships built in, the loggers and diagnostics endpoints, exposure control over web and JMX, writing your own, securing them, audit events and the info endpoint. Interviewers ask about exposure first, because a public /actuator/env leaks configuration.

part ofSpring Frameworkoverview, primer and where to startread it →
on this pageshow

explore

questions

page 1 of 2

What is the Actuator discovery index at /actuator, and how do you find out which endpoints your running app actually exposes?

level: juniorimportance: must knowfreq 45%

answer

  1. GET /actuator = HAL index
  2. _links: id -> href
  3. templated = URI template
  4. only enabled + web-exposed appear
  5. health exposed by default

basics

~10 s

GET /actuator returns a JSON document with a _links section. Each entry maps an endpoint id (like health, metrics, beans) to its URL. It's the menu of endpoints currently exposed over the web.

solid answer

~40 s

Spring Boot Actuator serves a discovery index at the base path `/actuator`. It returns a HAL-style JSON document whose `_links` object lists every web-exposed endpoint by id together with its `href` and whether it is `templated`. Only endpoints that are both enabled and web-exposed appear, so it's the authoritative runtime view of what's reachable. The catalog of standard endpoints includes `health`, `info`, `metrics`, `env`, `beans`, `mappings`, `configprops`, `conditions`, `scheduledtasks`, and `caches`, among others. `health` is exposed by default; the rest must be opted into. The index itself is what tooling and humans use to navigate; each `href` is an absolute URL you can GET directly. Templated links (like `metrics/{requiredMetricName}`) show a URI template you fill in.

code

java · 15 lines
java
// Example response body of  GET http://localhost:8080/actuator
// (only endpoints that are enabled AND web-exposed are listed)
{
  "_links": {
    "self":    { "href": "http://localhost:8080/actuator", "templated": false },
    "health":  { "href": "http://localhost:8080/actuator/health", "templated": false },
    "health-path": {
      "href": "http://localhost:8080/actuator/health/{*path}", "templated": true
    },
    "metrics": { "href": "http://localhost:8080/actuator/metrics", "templated": false },
    "metrics-requiredMetricName": {
      "href": "http://localhost:8080/actuator/metrics/{requiredMetricName}", "templated": true
    }
  }
}

go deeper

for a junior

Know that GET /actuator lists exposed endpoints via _links, and that most endpoints are off by default.

for a middle

Explain templated links and that the index reflects live enable+expose state, not the full catalog.

for a senior

Contrast web (HAL index) vs JMX (MBeans) discovery, and note base-path relocation keeps ids stable.

for a principal

Discuss the index as an ops contract across environments and why prod typically exposes a minimal subset.

**Actuator** is Spring Boot's production-monitoring subsystem. It exposes a set of HTTP (or JMX) **endpoints** under a base path, `/actuator` by default. Each endpoint has a short **id** (`health`, `metrics`, etc.). **The discovery index.** A `GET /actuator` (with no id) returns the *discovery index* — a JSON document in **HAL** style (Hypertext Application Language). Its shape is: ```json { "_links": { "self": { "href": "http://localhost:8080/actuator", "templated": false }, "health": { "href": "http://localhost:8080/actuator/health", "templated": false }, "metrics": { "href": "http://localhost:8080/actuator/metrics", "templated": false }, "metrics-requiredMetricName": { "href": "http://localhost:8080/actuator/metrics/{requiredMetricName}", "templated": true } } } ``` Key points: - **`_links`** is a map of *relation name → link object*. The relation name is essentially the endpoint id (with a suffix when an endpoint has a path-variable variant). - **`href`** is the full URL to GET. - **`templated: true`** means the `href` contains a `{placeholder}` (a URI template, e.g. `metrics/{requiredMetricName}`) that you substitute before calling. - **`self`** points back at the index. **What shows up.** An endpoint appears in the index only if it is **enabled** *and* **exposed over the web**. Exposure and enablement are configured with `management.*` properties (that configuration belongs to the Spring Boot starter/config topic, not here) — but the *effect* you observe is: by default only `health` is web-exposed, so a fresh app's index is nearly empty. Once more endpoints are exposed, they each get a `_links` entry. This makes the index the single source of truth for 'what is actually reachable right now' — more reliable than guessing from docs, because it reflects the live configuration. **The standard endpoint catalog** (the ones this leaf covers): `health` (app/dependency health), `info` (arbitrary app info), `metrics` (Micrometer metric snapshots), `env` (Spring `Environment` property sources), `beans` (the bean graph), `mappings` (request mappings), `configprops` (`@ConfigurationProperties` bound values), `conditions` (auto-configuration condition report), `scheduledtasks` (`@Scheduled` inventory), and `caches` (Spring cache inventory). Others exist (`loggers`, `threaddump`, `heapdump`, `httpexchanges`, `prometheus`, `shutdown`, `flyway`/`liquibase`) but the ones above are the core catalog. **Gotchas.** - If you changed the base path (e.g. to `/manage`), the index moves too — the *ids* stay the same, only the prefix changes. - The index is not an authentication or authorization gate; it merely lists exposed endpoints. Anything listed is callable subject to your security config. - The `templated` links can't be GET-ed as-is; you must fill the placeholder. - Under JMX (rather than web), there is no HTTP index — endpoints appear as MBeans instead. **When to use.** During debugging or ops, hitting `/actuator` first tells you exactly which endpoints are live without reading config files, which is invaluable across environments where exposure differs (dev exposes many, prod exposes few).

  • Why might /actuator/beans return 404 even though /actuator/health works?
    Because only `health` is web-exposed by default. `beans` is a valid endpoint but must be explicitly added to the web exposure set before it appears in the index and becomes reachable; otherwise you get 404.
  • What does `templated: true` mean for a link?
    The `href` contains a URI-template placeholder (e.g. `metrics/{requiredMetricName}`) that you must substitute with a real value before issuing the request; you cannot GET the templated URL verbatim.

saying these in an interview costs you the question

  • Thinking every standard endpoint is reachable by default (only health is web-exposed by default)
  • Believing the index performs authentication or hides secured endpoints
  • Trying to GET a templated href without filling the placeholder

context

open as a page

What do /actuator/health and /actuator/info return, and where does their content come from?

level: juniorimportance: must knowfreq 60%

basics

~20 s

/actuator/health reports whether the app and its dependencies are healthy, returning a status like UP or DOWN. /actuator/info returns arbitrary descriptive info (build version, git commit) contributed by the app; it is empty unless you configure contributors.

open as a page

How do you create a basic custom Actuator endpoint in Spring Boot, and what must you do before it becomes reachable over HTTP?

level: juniorimportance: must knowfreq 55%

basics

~10 s

Make a Spring bean annotated with @Endpoint(id="...") and give it a method annotated @ReadOperation. Then expose it via management.endpoints.web.exposure.include so it appears under /actuator/<id>.

open as a page

Which Actuator endpoints are reachable over HTTP by default in a Spring Boot app, and how do you expose additional ones?

level: juniorimportance: must knowfreq 78%

basics

~10 s

By default only the health endpoint is exposed over the web. To expose more, list their IDs (or * for all) in management.endpoints.web.exposure.include, e.g. include=health,info,metrics.

open as a page

What is the Actuator /actuator/info endpoint and where does its content come from?

level: juniorimportance: must knowfreq 60%

basics

~10 s

GET /actuator/info returns arbitrary application info as JSON. Spring Boot builds the response by collecting every InfoContributor bean; each one adds details like build version, git commit, or Java/OS info.

open as a page

What does the Spring Boot Actuator `loggers` endpoint let you do, and how do you use it?

level: juniorimportance: must knowfreq 55%

basics

~20 s

The /actuator/loggers endpoint shows the log levels of your application. A GET lists loggers and their levels; a POST with a JSON body like {"configuredLevel":"DEBUG"} changes a logger's level at runtime without restarting the app.

open as a page

Why do Spring Boot Actuator endpoints need to be secured, and what is exposed by default?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Actuator endpoints like /env, /configprops, /heapdump, /threaddump and /loggers reveal internal state, config values and secrets, and some let you change runtime settings. Leaving them open lets attackers read secrets or tamper. Restrict them to admins.

open as a page

How do @ReadOperation, @WriteOperation, and @DeleteOperation map to HTTP, and how are their method parameters bound?

level: middleimportance: must knowfreq 50%

basics

~10 s

@ReadOperation=GET, @WriteOperation=POST, @DeleteOperation=DELETE. Path parameters use @Selector. For a read/delete, other params come from query string; for a write, they come from the JSON request body.

open as a page

Why does /actuator/httpexchanges return nothing (or 404) even after you expose it, and how do you make it work?

level: middleimportance: must knowfreq 50%

basics

~10 s

Spring Boot doesn't auto-create the storage for it. You must define an HttpExchangeRepository bean — usually InMemoryHttpExchangeRepository — so exchanges are recorded. Without that bean the endpoint isn't registered even if you exposed it.

open as a page

How do you get build-info and git-info to appear under /actuator/info, and which beans back them?

level: middleimportance: must knowfreq 55%

basics

~20 s

Generate the metadata files at build time: the Spring Boot plugin's build-info goal creates META-INF/build-info.properties, and a git plugin creates git.properties. Spring Boot then auto-creates BuildProperties and GitProperties beans, and their contributors add build/git blocks.

open as a page

What is the difference between `configuredLevel` and `effectiveLevel` in the loggers endpoint response, and what does a null configuredLevel mean?

level: middleimportance: must knowfreq 48%

basics

~20 s

configuredLevel is the level explicitly set on that logger (can be null if nothing is set). effectiveLevel is the level actually in force after inheriting from parent loggers. A null configuredLevel means the logger inherits its level.

open as a page

How do you configure Spring Security to restrict Actuator endpoints, and what does EndpointRequest.toAnyEndpoint() do?

level: middleimportance: must knowfreq 68%

basics

~10 s

Define a SecurityFilterChain bean and use the EndpointRequest matcher instead of hardcoding /actuator paths. EndpointRequest.toAnyEndpoint() matches every actuator endpoint; require a role like hasRole('ACTUATOR_ADMIN'). You can exclude health/info so they stay public.

open as a page

What is the Spring Boot Actuator /actuator/auditevents endpoint and what does it show?

level: juniorimportance: should knowfreq 25%

basics

~20 s

It is an Actuator endpoint that exposes a list of recorded audit events — security-relevant actions like login success or failure — each with a principal (who), a type (what), a timestamp, and a data map of details.

open as a page

What are the /actuator/threaddump, /actuator/heapdump and /actuator/httpexchanges endpoints, and what does each return?

level: juniorimportance: should knowfreq 55%

basics

~10 s

They are Spring Boot Actuator diagnostic endpoints. threaddump returns a snapshot of all JVM threads and their states, heapdump downloads a binary .hprof memory-dump file, and httpexchanges shows the most recent HTTP request/response exchanges.

open as a page

How do you publish a custom audit event, and what is the structure of an AuditEvent?

level: middleimportance: should knowfreq 30%

basics

~10 s

Build an AuditEvent(principal, type, data-map), wrap it in an AuditApplicationEvent, and publish it with ApplicationEventPublisher.publishEvent(...). Spring's AuditListener stores it in the AuditEventRepository so it appears at /actuator/auditevents.

open as a page

Explain what /actuator/beans, /actuator/mappings, and /actuator/conditions each expose and when you'd reach for them.

level: middleimportance: should knowfreq 35%

basics

~20 s

/beans lists every Spring bean with its type, scope and dependencies. /mappings lists all request mappings (which URL/method routes to which handler). /conditions shows the auto-configuration report: which @Conditional auto-configs matched (were applied) and which didn't, with reasons.

open as a page

How does the /actuator/metrics endpoint work, and how do you drill into a specific metric and filter by its tags?

level: middleimportance: should knowfreq 50%

basics

~10 s

GET /actuator/metrics lists available metric names. GET /actuator/metrics/{name} (e.g. jvm.memory.used) returns that metric's current measurements plus its availableTags. Add ?tag=key:value to filter to a specific dimension.

open as a page

How does @Selector work for path parameters, and what does Match.ALL_REMAINING do?

level: middleimportance: should knowfreq 35%

basics

~10 s

@Selector binds a method parameter to a URL path segment after the endpoint id, e.g. /actuator/loggers/{name}. @Selector(match = Match.ALL_REMAINING) captures all remaining segments into a String array.

open as a page

Explain the difference between an endpoint being enabled and being exposed. Why does an endpoint need both?

level: middleimportance: should knowfreq 55%

basics

~20 s

Enabled means the endpoint bean is active and can do its work; exposed means it's reachable over a technology (web/JMX). An endpoint must be both to be callable. Most are enabled by default; only health is web-exposed by default.

open as a page

How do the include and exclude exposure properties interact, and what does the `*` wildcard do?

level: middleimportance: should knowfreq 62%

basics

~10 s

include lists IDs to expose (or * for all); exclude lists IDs to hide. Exclude takes precedence over include, so include=* with exclude=env,beans exposes everything except those two.

open as a page

What do the env, java, and os info contributors expose, and how do you turn them on?

level: middleimportance: should knowfreq 40%

basics

~10 s

EnvironmentInfoContributor publishes any properties prefixed info.* from the Spring Environment. JavaInfoContributor and OsInfoContributor add JVM and OS details. All three are disabled by default; enable them with management.info.env.enabled / .java.enabled / .os.enabled = true.

open as a page

What is InMemoryAuditEventRepository, what are its limitations, and how do you provide a custom AuditEventRepository?

level: seniorimportance: should knowfreq 22%

basics

~20 s

InMemoryAuditEventRepository is Spring's default store: a fixed-size (default 4000) in-memory circular buffer of AuditEvents. It's per-instance and lost on restart. For durability you implement the AuditEventRepository interface (add + find) backed by a database or log/SIEM and declare it as a bean.

open as a page

How does Spring Security integrate with Actuator auditing to record authentication success and failure events?

level: seniorimportance: should knowfreq 35%

basics

~20 s

Spring Security fires application events on auth success and failure. Spring Boot's AuthenticationAuditListener listens for them and converts each into an AuditEvent (type AUTHENTICATION_SUCCESS or AUTHENTICATION_FAILURE) stored in the AuditEventRepository, so they appear at /actuator/auditevents.

open as a page

Walk through what /actuator/scheduledtasks, /actuator/caches, /actuator/env, and /actuator/configprops expose, and their notable operations and behaviors.

level: seniorimportance: should knowfreq 30%

basics

~20 s

/scheduledtasks lists all @Scheduled tasks grouped by trigger type (cron/fixedRate/fixedDelay/custom). /caches lists Spring caches by cache manager, and supports DELETE to clear them. /env shows the Environment's property sources and values. /configprops shows @ConfigurationProperties beans and their bound values. env and configprops mask sensitive values by default.

open as a page

What is EndpointMediaTypes, and how do you control the media types (produces/consumes and content negotiation) of a custom web endpoint?

level: seniorimportance: should knowfreq 22%

basics

~10 s

EndpointMediaTypes lists the media types web endpoints produce and consume (default: the actuator vendor JSON types plus application/json). Per operation you set @ReadOperation(produces=...) / @WriteOperation(consumes=...), and use a Producible enum for content negotiation.

open as a page

What is the difference between @Endpoint, @WebEndpoint, and @JmxEndpoint, and how do @EndpointWebExtension / @EndpointJmxExtension fit in?

level: seniorimportance: should knowfreq 30%

basics

~10 s

@Endpoint publishes over both HTTP and JMX. @WebEndpoint is HTTP-only; @JmxEndpoint is JMX-only. @EndpointWebExtension / @EndpointJmxExtension add or override operations of an existing endpoint for just one technology.

open as a page

What exactly does GET /actuator/heapdump produce, and what operational cautions apply when triggering it?

level: seniorimportance: should knowfreq 42%

basics

~20 s

It generates and downloads a binary HPROF (.hprof) heap dump of the live JVM heap via the HotSpotDiagnosticMXBean. It's large (roughly heap size), pauses the app while dumping, and contains all in-memory data including secrets.

open as a page

How do you use /actuator/threaddump to diagnose a hang or deadlock — what fields matter and what do thread states tell you?

level: seniorimportance: should knowfreq 38%

basics

~20 s

The thread dump lists every thread with its state and stack trace. Many threads BLOCKED on the same lock, or two threads each holding a lock the other wants, points to contention or a deadlock. RUNNABLE threads stuck in the same frame suggest a hot loop.

open as a page

How do you change the Actuator base path and move endpoints onto a separate management port?

level: seniorimportance: should knowfreq 48%

basics

~10 s

The default web base path is /actuator (e.g. /actuator/health). Change it with management.endpoints.web.base-path. Move Actuator to its own port with management.server.port (a different value from server.port).

open as a page

How do you add custom data to /actuator/info by writing your own InfoContributor?

level: seniorimportance: should knowfreq 45%

basics

~10 s

Create a Spring bean implementing InfoContributor and override contribute(Info.Builder builder), calling builder.withDetail(key, value) to add fields. Because InfoEndpoint aggregates all such beans, your block is merged into the response automatically.

open as a page

showing 1–30 of 42