spring-boot-actuator
Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services
Install / Use
npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-actuatorInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
OperationsSupported Platforms
Tags
Our assessment of spring-boot-actuator
spring-boot-actuator scores 83/100 on our quality scale, 546th of 726 Operations skills we index.
Its SKILL.md is 8.7 KB long, well organised into 19 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.
It has 353 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 26 days ago, so spring-boot-actuator is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
spring-boot-actuator compared with similar skills
All 4 of these similar skills score higher than spring-boot-actuator; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| spring-boot-actuator (this skill)by giuseppe-trisciuoglio | 83 | 353 | 26d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 14d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 14d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 15d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 15d ago | SKILL.md |
Frequently asked questions
- How do I install spring-boot-actuator?
- Run
npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-actuator. The install tabs above show the steps for each supported agent. - Which AI agents does spring-boot-actuator work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is spring-boot-actuator safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is spring-boot-actuator still maintained?
- The repository was last updated 26 days ago, so spring-boot-actuator is actively maintained.
Skill content
View source on GitHubname: spring-boot-actuator description: Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services. Use when setting up monitoring, health checks, or metrics for Spring Boot applications. allowed-tools: Read, Write, Bash
Spring Boot Actuator Skill
Overview
- Deliver production-ready observability for Spring Boot services using Actuator endpoints, probes, and Micrometer integration.
- Standardize health, metrics, and diagnostics configuration while delegating deep reference material to
references/. - Support platform requirements for secure operations, SLO reporting, and incident diagnostics.
When to Use
- Trigger: "enable actuator endpoints" – Bootstrap Actuator for a new or existing Spring Boot service.
- Trigger: "secure management port" – Apply Spring Security policies to protect management traffic.
- Trigger: "configure health probes" – Define readiness and liveness groups for orchestrators.
- Trigger: "export metrics to prometheus" – Wire Micrometer registries and tune metric exposure.
- Trigger: "debug actuator startup" – Inspect condition evaluations and startup metrics when endpoints are missing or slow.
Quick Start
<!-- Maven -->
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-actuator</artifactId>
</dependency>
// Gradle
dependencies {
implementation "org.springframework.boot:spring-boot-starter-actuator"
}
After adding the dependency, verify endpoints respond:
curl http://localhost:8080/actuator/health
curl http://localhost:8080/actuator/info
Instructions
1. Add Actuator Dependency
Include spring-boot-starter-actuator in your build configuration.
Validate: Restart the service and confirm
/actuator/healthand/actuator/inforespond with200 OK.
2. Expose Required Endpoints
- Set
management.endpoints.web.exposure.includeto the precise list or"*"for internal deployments. - Adjust
management.endpoints.web.base-path(e.g.,/management) when the default/actuatorconflicts with routing. - Review detailed endpoint semantics in
references/endpoint-reference.md.
Validate:
curl http://localhost:8080/actuatorreturns the list of exposed endpoints.
3. Secure Management Traffic
- Apply an isolated
SecurityFilterChainusingEndpointRequest.toAnyEndpoint()with role-based rules. - Combine
management.server.portwith firewall controls or service mesh policies for operator-only access. - Keep
/actuator/health/**publicly accessible only when required; otherwise enforce authentication.
Validate: Unauthenticated requests to protected endpoints return
401 Unauthorized.
4. Configure Health Probes
- Enable
management.endpoint.health.probes.enabled=truefor/health/livenessand/health/readiness. - Group indicators via
management.endpoint.health.group.*to match platform expectations. - Implement custom indicators by extending
HealthIndicatororReactiveHealthContributor; sample implementations inreferences/examples.md#custom-health-indicator.
Validate:
/actuator/health/readinessreturnsUPwith all mandatory components before promoting to production.
5. Publish Metrics and Traces
- Activate Micrometer exporters (Prometheus, OTLP, Wavefront, StatsD) via
management.metrics.export.*. - Apply
MeterRegistryCustomizerbeans to addapplication,environment, and business tags for observability correlation. - Surface HTTP request metrics with
server.observation.*configuration when using Spring Boot 3.2+.
Validate: Scrape
/actuator/prometheusand confirm required meters (http.server.requests,jvm.memory.used) are present.
6. Enable Diagnostics Tooling
- Turn on
/actuator/startup(Spring Boot 3.5+) and/actuator/conditionsduring incident response to inspect auto-configuration decisions. - Register an
HttpExchangeRepository(e.g.,InMemoryHttpExchangeRepository) before enabling/actuator/httpexchangesfor request auditing. - Consult
references/endpoint-reference.mdfor endpoint behaviors and limits.
Validate:
/actuator/startupand/actuator/conditionsreturn valid JSON payloads.
Examples
Basic – Expose health and info safely
management:
endpoints:
web:
exposure:
include: "health,info"
endpoint:
health:
show-details: never
Intermediate – Readiness group with custom indicator
@Component
public class PaymentsGatewayHealth implements HealthIndicator {
private final PaymentsClient client;
public PaymentsGatewayHealth(PaymentsClient client) {
this.client = client;
}
@Override
public Health health() {
boolean reachable = client.ping();
return reachable ? Health.up().withDetail("latencyMs", client.latency()).build()
: Health.down().withDetail("error", "Gateway timeout").build();
}
}
management:
endpoint:
health:
probes:
enabled: true
group:
readiness:
include: "readinessState,db,paymentsGateway"
show-details: always
Advanced – Dedicated management port with Prometheus export
management:
server:
port: 9091
ssl:
enabled: true
endpoints:
web:
exposure:
include: "health,info,metrics,prometheus"
base-path: "/management"
metrics:
export:
prometheus:
descriptions: true
step: 30s
endpoint:
health:
show-details: when-authorized
roles: "ENDPOINT_ADMIN"
@Configuration
public class ActuatorSecurityConfig {
@Bean
SecurityFilterChain actuatorChain(HttpSecurity http) throws Exception {
http.securityMatcher(EndpointRequest.toAnyEndpoint())
.authorizeHttpRequests(c -> c
.requestMatchers(EndpointRequest.to("health")).permitAll()
.anyRequest().hasRole("ENDPOINT_ADMIN"))
.httpBasic(Customizer.withDefaults());
return http.build();
}
}
More end-to-end samples are available in references/examples.md.
Best Practices
- Keep SKILL.md concise and rely on
references/for verbose documentation to conserve context. - Apply the principle of least privilege: expose only required endpoints and restrict sensitive ones.
- Use immutable configuration via profile-specific YAML to align environments.
- Monitor actuator traffic separately to detect scraping abuse or brute-force attempts.
- Automate regression checks by scripting
curlprobes in CI/CD pipelines.
Constraints and Warnings
- Avoid exposing
/actuator/env,/actuator/configprops,/actuator/logfile, and/actuator/heapdumpon public networks. - Do not ship custom health indicators that block event loop threads or exceed 250 ms unless absolutely necessary.
- Ensure Actuator metrics exporters run on supported Micrometer registries; unsupported exporters require custom registry beans.
- Maintain compatibility with Spring Boot 3.5.x conventions; older versions may lack probes and observation features.
- Never expose actuator endpoints without authentication in production environments.
- Health indicators should not perform expensive operations that could impact application performance.
- Be cautious with
/actuator/beansand/actuator/mappingsas they reveal internal application structure.
Reference Materials
- Endpoint quick reference
- Implementation examples
- Official documentation extract
- Auditing with Actuator
- Cloud Foundry integration
- Enabling Actuator features
- HTTP exchange recording
- JMX exposure
- Monitoring and metrics
- Logging configuration
- Metrics exporters
- Observability with Micrometer
- Process and Monitoring
- Tracing
- Scripts directory (
scripts/) reserved for future automation; no runtime dependencies today.
Validation Checklist
- Confirm
mvn spring-boot:runor./gradlew bootRunexposes expected endpoints under/actuator(or custom base path). - Verify
/actuator/health/readinessreturnsUPwith all mandatory components before promoting to production. - Scrape
/actuator/metricsor/actuator/prometheusto ensure required meters (http.server.requests,jvm.memory.used) are present. - Run security scans to validate only intended ports and endpoints are reachable from outside the trusted network.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
