Production operationshard8+ years
How does Spring Boot's graceful shutdown actually work, and what can still go wrong during a rolling deploy?
With server.shutdown: graceful set, Boot stops the embedded web server's connector from accepting new requests on shutdown, but lets in-flight requests finish, up to spring.lifecycle.timeout-per-shutdown-phase (30 seconds by default). Combined with the readiness health group flipping to REFUSING_TRAFFIC first, an orchestrator that respects readiness stops routing new traffic before the process even starts shutting down, so graceful shutdown is really the last line of defence for requests already in flight when the signal arrives, not the whole story.
PreviousHow would you use Spring's application events to decouple two parts of a Boot application, and what are the tradeoffs against calling the other service directly?Next What does Spring Boot do by default when a controller throws an uncaught exception, and how would you replace it with your own error contract?