Menu

#Actuator

6 posts

Feed·
4 of 6 posts
Spring Security with Spring Boot Actuator: the authorization model that survived the incident
🖼️
0

Spring Security with Spring Boot Actuator: the authorization model that survived the incident

DEV Community·Juan Torchia·20 days ago
#EYGxHYS9
#actuator#devops#spring#security#boot#health

Locking down Actuator endpoints isn't enough. After the incident, I rebuilt the authorization model from scratch: explicit SecurityFilterChain, separate health groups, roles for /metrics and /env, and real validation with curl.…

15s
Read More
Spring Boot Actuator in Production: The Endpoints I Left Open by Accident and How I Closed Them
🖼️
0

Spring Boot Actuator in Production: The Endpoints I Left Open by Accident and How I Closed Them

DEV Community·Juan Torchia·21 days ago
#Y0XSmBh4

After publishing my Jakarta EE vs Spring Boot analysis, I audited Actuator's defaults on a backend I own and found sensitive endpoints wide open — ones I never consciously configured. Here's the hardening checklist I built afterward.

15s
Read More