Production operationshard8+ years

How does Spring Boot's graceful shutdown actually work, and what can still go wrong during a rolling deploy?

With server.shutdown: graceful set, Boot stops the embedded web server's connector from accepting new requests on shutdown, but lets in-flight requests finish, up to spring.lifecycle.timeout-per-shutdown-phase (30 seconds by default). Combined with the readiness health group flipping to REFUSING_TRAFFIC first, an orchestrator that respects readiness stops routing new traffic before the process even starts shutting down, so graceful shutdown is really the last line of defence for requests already in flight when the signal arrives, not the whole story.

The lesson behind it →