skip to content

Endpoint Exposure over Web & JMX

Exposure is controlled per technology with include and exclude sets, defaulting to health only over the web, and the base path and management port can be moved. Interviewers ask about the separate management port, because it keeps operations traffic off the public listener.

part ofSpring Frameworkoverview, primer and where to startread it →
on this pageshow

questions

5

Which Actuator endpoints are reachable over HTTP by default in a Spring Boot app, and how do you expose additional ones?

level: juniorimportance: must knowfreq 78%

answer

  1. default web = health only
  2. web.exposure.include / .exclude
  3. `*` = all, quote it in YAML
  4. exposed AND enabled both required
  5. JMX has its own include/exclude

basics

~10 s

By default only the health endpoint is exposed over the web. To expose more, list their IDs (or * for all) in management.endpoints.web.exposure.include, e.g. include=health,info,metrics.

solid answer

~40 s

Spring Boot Actuator ships built-in endpoints (health, info, metrics, env, beans, loggers, etc.), but for safety only `health` is exposed over HTTP out of the box — the rest exist but are not reachable at `/actuator/**`. You widen web exposure with the property `management.endpoints.web.exposure.include`, giving a comma-separated list of endpoint IDs, or `*` to expose them all (in YAML `*` must be quoted). Example: `management.endpoints.web.exposure.include=health,info,metrics`. JMX exposure is controlled by a separate, independent property (`management.endpoints.jmx.exposure.include`). Note that exposure and enablement are different gates: an endpoint must be enabled AND exposed to be reachable, and `info` is not exposed by default either — only `health` is.

code

java · 14 lines
java
// application.properties
// Only `health` is reachable by default:
//   GET /actuator/health  -> 200
//   GET /actuator/metrics -> 404 (not exposed)

// Opt extra endpoints in over HTTP:
management.endpoints.web.exposure.include=health,info,metrics,loggers

// Equivalent YAML (note the required quotes on the wildcard):
// management:
//   endpoints:
//     web:
//       exposure:
//         include: "*"

go deeper

for a junior

Must know: default is health-only over HTTP; widen with management.endpoints.web.exposure.include.

for a middle

Should distinguish exposure from enablement and know the wildcard/YAML-quoting detail.

for a senior

Frames health-only default as a security posture and reaches for explicit allow-lists over *.

for a principal

Ties exposure defaults to attack surface, separate management port, and org-wide platform conventions.

## What Actuator exposure means Spring Boot **Actuator** (the `spring-boot-starter-actuator` dependency) adds production-monitoring **endpoints** — small management APIs identified by an **ID** such as `health`, `info`, `metrics`, `env`, `beans`, `loggers`, `mappings`, `threaddump`, `heapdump`, `shutdown`. Each endpoint can be surfaced over two **technologies**: - **Web (HTTP)** — reachable under the base path, default `/actuator` (e.g. `GET /actuator/health`). - **JMX** — reachable through JMX MBeans. "Exposure" is the mechanism that decides *which* endpoints are actually reachable over each technology. ## The default: health only over the web Because endpoints can leak sensitive data (config, environment variables, bean graph, heap dumps), Spring Boot is conservative: **by default only the `health` endpoint is exposed over HTTP**. Every other endpoint is registered in the context but returns 404 over the web until you opt it in. (Older tutorials sometimes say `health` and `info` — current Spring Boot exposes only `health` by default over the web.) ## Controlling web exposure Two properties per technology: - `management.endpoints.web.exposure.include` — comma-separated list of endpoint IDs to expose. Special value `*` means *all* endpoints. - `management.endpoints.web.exposure.exclude` — IDs to hide; **exclude wins over include**. Examples: ```properties # expose three specific endpoints over HTTP management.endpoints.web.exposure.include=health,info,metrics # expose everything management.endpoints.web.exposure.include=* ``` In **YAML** the wildcard is a reserved character and must be quoted: `include: "*"`. ## Two independent gates: enabled vs exposed Exposure is not the same as **enablement** (`management.endpoint.<id>.enabled`). An endpoint is reachable only if it is BOTH *enabled* AND *exposed*. Almost all endpoints are enabled by default; `shutdown` is the notable exception (disabled by default). So `include=*` still will not surface `shutdown` unless you also enable it. ## Web vs JMX are separate JMX has its own pair of properties (`management.endpoints.jmx.exposure.include` / `.exclude`). Changing web exposure does not change JMX exposure and vice-versa. (JMX itself is off by default in modern Spring Boot via `spring.jmx.enabled=false`.) ## Common gotchas - Adding the actuator starter does NOT automatically expose `metrics`/`env` over HTTP — only `health`. - Forgetting to quote `*` in YAML causes a parse error. - Exposing `*` in production is risky; prefer an explicit allow-list or a separate management port.

  • You added the actuator starter but `/actuator/metrics` returns 404. Why?
    The `metrics` endpoint is enabled but not exposed over the web by default — only `health` is. Add `metrics` (or `*`) to `management.endpoints.web.exposure.include`.
  • Does setting web exposure also change what's visible over JMX?
    No. Web and JMX have independent exposure property pairs; JMX is controlled by `management.endpoints.jmx.exposure.include/exclude`, and JMX is disabled by default in modern Spring Boot.

saying these in an interview costs you the question

  • Thinking all endpoints are exposed over HTTP as soon as you add the starter
  • Believing `info` is exposed by default over the web (only `health` is)
  • Confusing 'enabled' with 'exposed' — assuming enabling an endpoint makes it web-reachable

context

open as a page

Explain the difference between an endpoint being enabled and being exposed. Why does an endpoint need both?

level: middleimportance: should knowfreq 55%

basics

~20 s

Enabled means the endpoint bean is active and can do its work; exposed means it's reachable over a technology (web/JMX). An endpoint must be both to be callable. Most are enabled by default; only health is web-exposed by default.

open as a page

How do the include and exclude exposure properties interact, and what does the `*` wildcard do?

level: middleimportance: should knowfreq 62%

basics

~10 s

include lists IDs to expose (or * for all); exclude lists IDs to hide. Exclude takes precedence over include, so include=* with exclude=env,beans exposes everything except those two.

open as a page

How do you change the Actuator base path and move endpoints onto a separate management port?

level: seniorimportance: should knowfreq 48%

basics

~10 s

The default web base path is /actuator (e.g. /actuator/health). Change it with management.endpoints.web.base-path. Move Actuator to its own port with management.server.port (a different value from server.port).

open as a page

Web and JMX exposure are configured separately. Discuss the design rationale and how you'd harden exposure for a production service.

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Web and JMX each have their own include/exclude sets so you can surface an endpoint on one transport but not the other. In prod, keep web to a minimal allow-list (or a separate internal port), avoid *, and layer Spring Security on top.

open as a page