Skip to content

Add Actuator health, readiness and info endpoints (#335) - #343

Merged
C0dE-l3eAkeR merged 1 commit into
developfrom
335-actuator-health
Oct 1, 2026
Merged

C0dE-l3eAkeR merged 1 commit into
developfrom
335-actuator-health

Conversation

@C0dE-l3eAkeR

@C0dE-l3eAkeR C0dE-l3eAkeR commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Closes #335

This adds Spring Boot Actuator so we can finally tell whether a running backend is alive and whether it can reach the things it depends on.

/actuator/health/liveness only reflects the JVM and is what the Docker HEALTHCHECK uses, so a database or setup-service outage never gets the container restarted in a loop. /actuator/health/readiness also checks PostgreSQL, Keycloak and the setup-service and returns 503 if any of them is unreachable. Both work without a token; /actuator/health shows the individual components only to logged-in users. /actuator/info returns the version and the git commit the instance was built from and needs a token. Nothing else is exposed.

One thing worth a look in SecurityConfiguration: the chain ends in anyRequest().permitAll() and relies on @PreAuthorize in the controllers. Actuator endpoints don't have that, so without extra rules everything exposed would have been public. I added permitAll for GET /actuator/health/** and hasRole("user") for the rest of /actuator/**.

The Keycloak and setup-service checks use their own client with a 3 s timeout, so a dead upstream shows up as DOWN instead of hanging the health endpoint. The management settings go in application.properties rather than a profile file, because the server picks its profile in a compose file that isn't in this repo. In compose, both databases and Keycloak now have health checks, and Keycloak and the backend wait for their dependencies. Keycloak's image has no curl, so its check talks to the management port through bash.

Heads-up for local setups: Keycloak keeps its data inside its own container, not in keycloak-db, which has no tables. Since the keycloak service changes here, the next docker compose up recreates that container and the realm and test users are gone, so you'll need to import the realm again. docker start on the existing containers avoids that.

I tested it with the full build (418 tests), a security test that hits the real actuator endpoints (everything except health returns 401 anonymously), and by running the jar locally. Stopping the setup-service or Keycloak flipped readiness to 503 while liveness stayed 200, and both recovered once the service was back. The image built from the Dockerfile went healthy after about 20 s.

Not included: Prometheus metrics (no scraper yet) and fixing the methodologist compose service itself, which still doesn't build as written.

The backend had no way to tell whether a running instance is up or can
reach the services it depends on.

- spring-boot-starter-actuator with only health and info exposed over
  HTTP; env, beans, heapdump and the rest stay closed.
- /actuator/health/liveness reflects the JVM only. readiness also covers
  PostgreSQL and two new indicators, keycloak (the realm's OpenID discovery
  document) and setupService (its /actuator/health), probed with their own
  3 s client so a dead upstream reports DOWN instead of hanging.
- /actuator/info reports build info and the git commit
  (git-commit-id-maven-plugin, which tolerates a missing .git).
- Anonymous callers get the status only; components need a token.
- SecurityConfiguration permits GET /actuator/health/** and requires the
  user role for every other /actuator path. The catch-all permitAll would
  otherwise have left them open, since actuator endpoints carry no
  @PreAuthorize.
- The management settings live in application.properties so they apply to
  every profile, including the one the server runs.
- Dockerfile HEALTHCHECK on liveness, so an upstream outage never gets the
  container restarted. Compose gets health checks for both databases and
  Keycloak (bash /dev/tcp against its management port, the image has no
  curl) and service_healthy ordering for Keycloak and the backend.
- README section on the endpoints and `docker compose up --wait`.

Closes #335
@C0dE-l3eAkeR C0dE-l3eAkeR self-assigned this Sep 27, 2026
@C0dE-l3eAkeR
C0dE-l3eAkeR requested a review from uiysg September 29, 2026 09:21
@C0dE-l3eAkeR
C0dE-l3eAkeR merged commit d4c872b into develop Oct 1, 2026
3 checks passed
@C0dE-l3eAkeR
C0dE-l3eAkeR deleted the 335-actuator-health branch October 1, 2026 06:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants