Move operational endpoints to a separate listener when the network needs it, then secure that listener as a distinct entry point.
Spring Actuator management port: separate listener, explicit access rule
A port is a routing boundary
A receipt API serves customers on one listener while an operations network reaches a second. Setting management.server.port gives Actuator its own HTTP listener; management.server.address can bind that listener to an internal interface. Neither property authenticates callers. The network must restrict reachability, and the application must still decide which principals may inspect or change operations state. Security chains and health checks have separate jobs.
Review the security back-off
An application-defined SecurityFilterChain takes control of HTTP access rules. Do not assume Spring Boot will add a protective Actuator rule after that point. Give management requests an explicit matcher and authorization policy, and test it through the actual listener. A reverse proxy that forwards the management port onto the public host can undo the intended isolation. Prefer a narrow exposure list even behind a firewall.
Test the deployment path
Probe the application listener and management listener independently from an allowed operations host and a denied client host. Confirm an unauthenticated caller cannot reach a sensitive endpoint, even if the network rule is accidentally widened. Include a startup test for conflicting port and address settings, and verify service discovery does not advertise the management listener as a customer API. Readiness may need a deliberate exception for the platform probe.
Implementation contract
management.server.port=9471
management.server.address=${MANAGEMENT_BIND_ADDRESS:127.0.0.1}
management.endpoints.web.exposure.include=health,info,prometheusCost and verification
A second listener consumes a small amount of memory and one port allocation. The main operational cost is maintaining two routing and access paths; every endpoint added to exposure expands what that path can reveal or change.
Common Mistakes
- Do not treat a separate port as authentication.
- Do not define a custom SecurityFilterChain and assume Actuator access remains automatically protected.
- Do not publish the management listener through the same public ingress without reviewing its route and credentials.
Read next
Spring Security filter chain: authentication, CSRF and request order, Spring Boot Actuator health: public liveness without public diagnostics, Spring readiness: report an unavailable dependency without forcing liveness failure, Spring Prometheus scrape endpoint: registry, exposure and label contract, Spring Actuator loggers endpoint: temporary diagnosis with guarded write access.
Related operations contract
Spring Boot SSL bundle rotation: replace certificate files with a verified handoff.
