Agent skill

Spring Boot Actuator

by giuseppe-trisciuoglio in giuseppe-trisciuoglio/developer-kit

Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

MITAuto-check: notesBackend & APIs

Install Spring Boot Actuator

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-actuator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit spring-boot-actuator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-java/skills/spring-boot-actuator .claude/skills/spring-boot-actuator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spring-boot-actuator
GitHub stars
357
Token cost
~2.2k tokens
SKILL.md length
652 words
Files
17 (incl. scripts, references, assets)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

  • Works in 6 steps: Add Actuator Dependency → Expose Required Endpoints → Secure Management Traffic → …
  • Setting up monitoring
  • SKILL.md covers Overview, When to Use, Quick Start and Instructions, plus 5 more sections
  • Calls curl and mvn

What it does

Spring Boot Actuator is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services. Use when setting up monitoring, health checks, or metrics for Spring Boot applications.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including scripts, reference files and assets (for example `references/auditing.md`, `references/cloud-foundry.md` and `references/enabling.md`).

It sits in Backend & APIs, covering Backend development and Monitoring and alerting. It works with Spring Boot. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • Setting up monitoring
  • Metrics for Spring Boot applications

Example prompts

  • “Use the spring-boot-actuator skill to provide patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured…”
  • “/spring-boot-actuator”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Bash

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Add Actuator Dependency
  2. Expose Required Endpoints
  3. Secure Management Traffic
  4. Configure Health Probes
  5. Publish Metrics and Traces
  6. Enable Diagnostics Tooling

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spring Boot Actuator loads about 2.2k tokens when it runs, and up to ~44k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 652 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~44k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 652 words, ~2,228 tokens.

Download SKILL.mdSave it as .claude/skills/spring-boot-actuator/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.
name
spring-boot-actuator
description
Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services. Use when setting up monitoring, health checks, or metrics for Spring Boot applications.
allowed-tools
Read, Write, Bash

Spring Boot Actuator Skill

Overview

  • Deliver production-ready observability for Spring Boot services using Actuator endpoints, probes, and Micrometer integration.
  • Standardize health, metrics, and diagnostics configuration while delegating deep reference material to references/.
  • Support platform requirements for secure operations, SLO reporting, and incident diagnostics.

When to Use

  • Trigger: "enable actuator endpoints" – Bootstrap Actuator for a new or existing Spring Boot service.
  • Trigger: "secure management port" – Apply Spring Security policies to protect management traffic.
  • Trigger: "configure health probes" – Define readiness and liveness groups for orchestrators.
  • Trigger: "export metrics to prometheus" – Wire Micrometer registries and tune metric exposure.
  • Trigger: "debug actuator startup" – Inspect condition evaluations and startup metrics when endpoints are missing or slow.

Quick Start

xml
<!-- Maven -->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-actuator</artifactId>
</dependency>
gradle
// Gradle
dependencies {
    implementation "org.springframework.boot:spring-boot-starter-actuator"
}

After adding the dependency, verify endpoints respond:

bash
curl http://localhost:8080/actuator/health
curl http://localhost:8080/actuator/info

Instructions

1. Add Actuator Dependency

Include spring-boot-starter-actuator in your build configuration.

Validate: Restart the service and confirm /actuator/health and /actuator/info respond with 200 OK.

2. Expose Required Endpoints
  • Set management.endpoints.web.exposure.include to the precise list or "*" for internal deployments.
  • Adjust management.endpoints.web.base-path (e.g., /management) when the default /actuator conflicts with routing.
  • Review detailed endpoint semantics in references/endpoint-reference.md.

Validate: curl http://localhost:8080/actuator returns the list of exposed endpoints.

3. Secure Management Traffic
  • Apply an isolated SecurityFilterChain using EndpointRequest.toAnyEndpoint() with role-based rules.
  • Combine management.server.port with firewall controls or service mesh policies for operator-only access.
  • Keep /actuator/health/** publicly accessible only when required; otherwise enforce authentication.

Validate: Unauthenticated requests to protected endpoints return 401 Unauthorized.

4. Configure Health Probes
  • Enable management.endpoint.health.probes.enabled=true for /health/liveness and /health/readiness.
  • Group indicators via management.endpoint.health.group.* to match platform expectations.
  • Implement custom indicators by extending HealthIndicator or ReactiveHealthContributor; sample implementations in references/examples.md#custom-health-indicator.

Validate: /actuator/health/readiness returns UP with all mandatory components before promoting to production.

5. Publish Metrics and Traces
  • Activate Micrometer exporters (Prometheus, OTLP, Wavefront, StatsD) via management.metrics.export.*.
  • Apply MeterRegistryCustomizer beans to add application, environment, and business tags for observability correlation.
  • Surface HTTP request metrics with server.observation.* configuration when using Spring Boot 3.2+.

Validate: Scrape /actuator/prometheus and confirm required meters (http.server.requests, jvm.memory.used) are present.

6. Enable Diagnostics Tooling
  • Turn on /actuator/startup (Spring Boot 3.5+) and /actuator/conditions during incident response to inspect auto-configuration decisions.
  • Register an HttpExchangeRepository (e.g., InMemoryHttpExchangeRepository) before enabling /actuator/httpexchanges for request auditing.
  • Consult references/endpoint-reference.md for endpoint behaviors and limits.

Validate: /actuator/startup and /actuator/conditions return valid JSON payloads.

Examples

Basic – Expose health and info safely
yaml
management:
  endpoints:
    web:
      exposure:
        include: "health,info"
  endpoint:
    health:
      show-details: never
Intermediate – Readiness group with custom indicator
java
@Component
public class PaymentsGatewayHealth implements HealthIndicator {

    private final PaymentsClient client;

    public PaymentsGatewayHealth(PaymentsClient client) {
        this.client = client;
    }

    @Override
    public Health health() {
        boolean reachable = client.ping();
        return reachable ? Health.up().withDetail("latencyMs", client.latency()).build()
                         : Health.down().withDetail("error", "Gateway timeout").build();
    }
}
yaml
management:
  endpoint:
    health:
      probes:
        enabled: true
      group:
        readiness:
          include: "readinessState,db,paymentsGateway"
          show-details: always
Advanced – Dedicated management port with Prometheus export
yaml
management:
  server:
    port: 9091
    ssl:
      enabled: true
  endpoints:
    web:
      exposure:
        include: "health,info,metrics,prometheus"
      base-path: "/management"
  metrics:
    export:
      prometheus:
        descriptions: true
        step: 30s
  endpoint:
    health:
      show-details: when-authorized
      roles: "ENDPOINT_ADMIN"
java
@Configuration
public class ActuatorSecurityConfig {

    @Bean
    SecurityFilterChain actuatorChain(HttpSecurity http) throws Exception {
        http.securityMatcher(EndpointRequest.toAnyEndpoint())
            .authorizeHttpRequests(c -> c
                .requestMatchers(EndpointRequest.to("health")).permitAll()
                .anyRequest().hasRole("ENDPOINT_ADMIN"))
            .httpBasic(Customizer.withDefaults());
        return http.build();
    }
}

More end-to-end samples are available in references/examples.md.

Show full SKILL.md (260 more words)Show less

Best Practices

  • Keep SKILL.md concise and rely on references/ for verbose documentation to conserve context.
  • Apply the principle of least privilege: expose only required endpoints and restrict sensitive ones.
  • Use immutable configuration via profile-specific YAML to align environments.
  • Monitor actuator traffic separately to detect scraping abuse or brute-force attempts.
  • Automate regression checks by scripting curl probes in CI/CD pipelines.

Constraints and Warnings

  • Avoid exposing /actuator/env, /actuator/configprops, /actuator/logfile, and /actuator/heapdump on public networks.
  • Do not ship custom health indicators that block event loop threads or exceed 250 ms unless absolutely necessary.
  • Ensure Actuator metrics exporters run on supported Micrometer registries; unsupported exporters require custom registry beans.
  • Maintain compatibility with Spring Boot 3.5.x conventions; older versions may lack probes and observation features.
  • Never expose actuator endpoints without authentication in production environments.
  • Health indicators should not perform expensive operations that could impact application performance.
  • Be cautious with /actuator/beans and /actuator/mappings as they reveal internal application structure.

Reference Materials

Validation Checklist

  • Confirm mvn spring-boot:run or ./gradlew bootRun exposes expected endpoints under /actuator (or custom base path).
  • Verify /actuator/health/readiness returns UP with all mandatory components before promoting to production.
  • Scrape /actuator/metrics or /actuator/prometheus to ensure required meters (http.server.requests, jvm.memory.used) are present.
  • Run security scans to validate only intended ports and endpoints are reachable from outside the trusted network.

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 16 other files (scripts, references, assets) in plugins/developer-kit-java/skills/spring-boot-actuator of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • assets/.gitkeep
  • references/auditing.md
  • references/cloud-foundry.md
  • references/enabling.md
  • references/endpoint-reference.md
  • references/endpoints.md
  • references/examples.md
  • references/http-exchanges.md
  • references/jmx.md
  • references/loggers.md
  • references/metrics.md
  • references/monitoring.md
  • references/observability.md
  • references/process-monitoring.md
  • references/tracing.md
  • scripts/.gitkeep

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

Spring Boot Actuator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spring Boot Actuator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spring Boot Actuator this skillgiuseppe-trisciuoglio/developer-kit357—~2.2kAutomated safety check: NotesMIT
Oryxos Initoryx-labs/oryxos187—~1.6kAutomated safety check: PassApache-2.0
Detecting Debug Endpointsjeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Spring Bootpiomin/claude-ai-spring-boot1.3k—~2kAutomated safety check: PassApache-2.0
Dr Jskilljdubois/dr-jskill342—~4.6kAutomated safety check: NotesApache-2.0
WxJava Integration Guidebinarywang/WxJava33k—~123Automated safety check: PassApache-2.0

Similar skills

  • Oryxos Init

    oryx-labs/oryxos

    初始化 OryxOS(或同类 JDK 21 + Spring Boot 3.x 企业级单体)的工程地基:Maven 多模块骨架、 结构化日志、Actuator + Prometheus 监控、Spring MVC + 虚拟线程、springdoc OpenAPI、 统一响应体与全局异常/错误码、Google 格式 + 阿里编码规约(Spotless + 阿里 P3C +…

    187 GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Detecting Debug Endpoints

    jeremylongshore/tons-of-skills-marketplace

    Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin…

    2.8k GitHub stars~2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Spring Boot

    piomin/claude-ai-spring-boot

    Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.

    1.3k GitHub stars~2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Dr Jskill

    jdubois/dr-jskill

    Creates Java + Spring Boot projects: Web applications, full-stack apps with Vue.js or Angular or React or vanilla JS, PostgreSQL, REST APIs, and Docker.

    342 GitHub stars~4.6k tokensUpdated 11 days ago
    Backend & APIsAuto-check: notes
  • WxJava Integration Guide

    binarywang/WxJava

    Plans a WxJava setup for Java, Spring Boot or Solon projects that call WeChat services, from module and BOM choice to config and a minimal working call.

    33k GitHub stars~123 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Grails Developer Guide

    apache/grails-core

    Guides building Grails web applications and REST APIs with GORM, controllers, services, views, plugins and Spock and Geb testing.

    2.9k GitHub stars~4.9k tokensUpdated today
    Backend & APIsAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    357 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS SDK Java V2 Secrets Manager

    giuseppe-trisciuoglio/developer-kit

    Provides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration.

    357 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check: notes

Works with

Categories

Questions about Spring Boot Actuator

What does Spring Boot Actuator do?

Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services. Spring Boot Actuator is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

When should I use Spring Boot Actuator?

Spring Boot Actuator fits situations like: setting up monitoring; metrics for Spring Boot applications.

How do I install Spring Boot Actuator in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-actuator -a claude-code`. Or copy the skill folder (plugins/developer-kit-java/skills/spring-boot-actuator in giuseppe-trisciuoglio/developer-kit) into .claude/skills/spring-boot-actuator in your project. Claude Code loads it when a task matches its description.

How do I install Spring Boot Actuator in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-actuator -a codex`. Or copy the skill folder (plugins/developer-kit-java/skills/spring-boot-actuator in giuseppe-trisciuoglio/developer-kit) into .agents/skills/spring-boot-actuator in your project. Codex loads it when a task matches its description.

Can I use Spring Boot Actuator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-actuator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spring-boot-actuator, .gemini/skills/spring-boot-actuator, .github/skills/spring-boot-actuator and .opencode/skills/spring-boot-actuator in your project.

What does Spring Boot Actuator need to run?

Going by SKILL.md and its folder, Spring Boot Actuator needs the command-line tools its instructions call (curl and mvn). Its frontmatter pre-approves these tools: Read, Write, Bash.

Does Spring Boot Actuator access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Spring Boot Actuator safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Spring Boot Actuator use?

Spring Boot Actuator is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spring Boot Actuator use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 42k tokens, read only when the agent opens those files.

What are the alternatives to Spring Boot Actuator?

Skills that share tags, products or a category with Spring Boot Actuator: Oryxos Init (oryx-labs/oryxos, 187 stars), Detecting Debug Endpoints (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Spring Boot (piomin/claude-ai-spring-boot, 1.3k stars) and Dr Jskill (jdubois/dr-jskill, 342 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spring Boot Actuator?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.