In Spring Boot Actuator, what does management.endpoint.health.show-details control, and what are its three possible values?
answer
- never / when-authorized / always
- default = never (secure by default)
- when-authorized + roles property
- show-components inherits show-details
- details can leak DB/disk info
basics
~10 sIt controls how much detail /actuator/health shows. Values: never (default, only overall status), when-authorized (details shown to logged-in/authorized users), and always (details shown to everyone).
solid answer
~30 smanagement.endpoint.health.show-details decides whether the /actuator/health endpoint returns just the aggregated overall status, or also the per-contributor breakdown (component names, statuses, and detail maps like disk space or DB info). The three values are: never (the default) shows only {"status":"UP"}; always shows the full details to any caller; when-authorized shows details only to authenticated users, optionally restricted to roles listed in management.endpoint.health.roles. The default is never precisely because health details (DB URLs, disk paths, error messages) can leak sensitive infrastructure information to anonymous callers, so you must opt in.
code
yaml · 10 linesmanagement:
endpoint:
health:
show-details: when-authorized # never | when-authorized | always
roles: ADMIN # only ADMINs see the breakdown
show-components: when-authorized # optional; defaults to show-details
endpoints:
web:
exposure:
include: healthgo deeper
Know the three values and that never is the default.
Explain the security rationale and the roles property.
Contrast with show-components and describe the anonymous-vs-authenticated behavior of when-authorized.
Tie show-details to threat modeling of health-endpoint information disclosure and probe design.
**What the health endpoint returns.** Spring Boot Actuator exposes `/actuator/health`. Internally, many `HealthContributor` beans (each a `HealthIndicator`) report their own `Health` — a `Status` (UP/DOWN/etc.) plus an optional map of details (e.g. the `DiskSpaceHealthIndicator` reports free/total bytes, `DataSourceHealthIndicator` reports the validation query result). Actuator aggregates all contributor statuses into one overall status. **What show-details does.** The property `management.endpoint.health.show-details` decides how much of that is serialized in the HTTP response body: - `never` (the **default**): the response is just the overall status, e.g. `{"status":"UP"}`. No component names, no detail maps. - `always`: the full nested breakdown is returned to **every** caller, including anonymous ones — component names, each component's status, and each component's details. - `when-authorized`: details are returned **only** when the request comes from an authenticated principal. You can further require specific roles via `management.endpoint.health.roles` (a comma-separated list); if that list is set, the user must hold at least one of those roles, otherwise only the overall status is shown. **Why the default is `never`.** Health details frequently contain sensitive infrastructure data: database connection info, disk paths, broker addresses, exception messages. Exposing these to anonymous callers is an information-disclosure risk, so Spring is secure-by-default and forces you to opt in. **Related property: show-components.** `management.endpoint.health.show-components` controls whether the **names** of components are listed (without necessarily their full detail maps). If not set explicitly, it inherits the value of `show-details`. It takes the same three values (never/when-authorized/always). This lets you, for example, reveal that a `db` and `diskSpace` component exist and their statuses, while still hiding deeper detail maps — though the common case is to leave show-components unset and let it follow show-details. **Interaction with security.** `when-authorized` requires Spring Security to be present so Actuator can inspect the current `Principal`/authorities. Without a SecurityContext, `when-authorized` behaves like `never` for anonymous requests. **When to use which.** Use `never` for a health check consumed only by a load balancer / Kubernetes probe (they only need the status code / overall status). Use `when-authorized` when operators need the breakdown but you don't want anonymous exposure. Use `always` only in trusted/internal networks or non-sensitive setups.
- With show-details=when-authorized and no roles configured, who sees the details?Any authenticated user. The roles property only narrows it further — if roles is empty/unset, being authenticated is sufficient; anonymous callers still get only the overall status.
- Why is never the default rather than always?Security-by-default: component detail maps can contain sensitive infrastructure data (DB URLs, disk paths, exception text), so Spring forces an explicit opt-in before exposing them.
saying these in an interview costs you the question
- Saying the default is always (it is never)
- Thinking show-details changes the HTTP status code (it only changes the body detail)
- Believing when-authorized needs no Spring Security to evaluate the principal