Actuator & Monitoring Dependencies
Learn spring-boot-starter-actuator for health checks and metrics endpoints, and micrometer-registry-prometheus for exporting metrics to Prometheus.
Introduction
Once an application is running in production, "does it work" stops being a question you can answer by reading code — you need the application itself to report on its own health and behavior. spring-boot-starter-actuator is Spring Boot's built-in answer to that, and Micrometer's Prometheus registry is how those numbers reach an external monitoring system.
- What spring-boot-starter-actuator adds and what /actuator/health returns by default.
- How to expose additional Actuator endpoints safely through configuration.
- How to write a custom HealthIndicator for an application-specific check.
- How to export metrics in a format Prometheus can scrape with micrometer-registry-prometheus.
spring-boot-starter-actuator
Adding this starter exposes a set of operational endpoints under /actuator — health checks, application info, environment properties, and more — all without writing a single controller yourself.
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-actuator</artifactId></dependency>Click Run to see what this code prints.
By default, only /actuator/health and /actuator/info are exposed over HTTP — every other endpoint (env, beans, metrics, and dozens more) is disabled until you explicitly turn it on.
Exposing Actuator Endpoints
Which endpoints are reachable is controlled entirely through configuration, which keeps sensitive operational data (like a full list of environment variables) opt-in rather than exposed by accident.
management.endpoints.web.exposure.include=health,info,metrics,prometheusmanagement.endpoint.health.show-details=alwaysClick Run to see what this code prints.
management.endpoints.web.exposure.include=* opens every Actuator endpoint, including ones that can leak configuration secrets or even let you interact with the running JVM. In production, expose only the specific endpoints you need, and put the /actuator base path behind authentication or a separate internal-only port.
Custom Health Indicators
Beyond the built-in checks (database connectivity, disk space), you can register your own HealthIndicator bean to report on anything specific to your application — a downstream API, a message queue, a licensing check.
@Componentpublic class PaymentGatewayHealthIndicator implements HealthIndicator {
private final PaymentGatewayClient client;
public PaymentGatewayHealthIndicator(PaymentGatewayClient client) { this.client = client; }
@Override public Health health() { if (client.isReachable()) { return Health.up().withDetail("gateway", "reachable").build(); } return Health.down().withDetail("gateway", "unreachable").build(); }}Click Run to see what this code prints.
Exporting Metrics to Prometheus
Actuator alone exposes metrics in a generic JSON format at /actuator/metrics. Prometheus expects a specific plain-text exposition format instead, and io.micrometer:micrometer-registry-prometheus adds exactly that — a /actuator/prometheus endpoint Prometheus can scrape directly.
<dependency> <groupId>io.micrometer</groupId> <artifactId>micrometer-registry-prometheus</artifactId></dependency>management.endpoints.web.exposure.include=health,info,prometheusClick Run to see what this code prints.
A Prometheus server configured to scrape this endpoint on an interval builds a full time series automatically — request counts, latencies, JVM memory, and anything else Micrometer tracks — with zero custom instrumentation code needed for the built-in metrics.
scrape_configs: - job_name: 'spring-boot-app' metrics_path: '/actuator/prometheus' static_configs: - targets: ['localhost:8080']Common Mistakes
- Exposing all Actuator endpoints publicly with exposure.include=*.
- Forgetting that Actuator endpoints are unauthenticated by default unless Spring Security is added and rules are defined for /actuator/**.
- Adding micrometer-registry-prometheus but forgetting to include "prometheus" in management.endpoints.web.exposure.include, so the endpoint stays disabled.
- Treating /actuator/health as a substitute for real application logs instead of one signal among several.
Frequently Asked Questions
Micrometer is pulled in automatically by spring-boot-starter-actuator — it is the metrics facade underneath, and registries like Prometheus, Datadog, or New Relic are just different backends you plug into it.
Yes, and it is recommended in production — Actuator endpoints match normal HTTP paths, so a SecurityFilterChain rule for /actuator/** works exactly like any other endpoint.
/actuator/metrics returns a browsable JSON structure meant for humans and ad hoc lookups. /actuator/prometheus returns the same underlying data in the plain-text format Prometheus specifically expects to scrape.
Summary
spring-boot-starter-actuator turns on operational visibility with almost no code, and micrometer-registry-prometheus bridges that data into a real monitoring stack. Next, we look at how the logs those metrics complement are configured in the first place.