Observabilityhard5-8 years

How does Micrometer fit into Actuator's metrics, and how would you secure actuator endpoints in production?

Micrometer is a vendor-neutral metrics facade — Actuator auto-configures a MeterRegistry and instruments things like HTTP request timings, JVM memory and GC, and datasource pool usage automatically; you add a Micrometer registry implementation (Prometheus, Datadog, CloudWatch, ...) as a dependency to ship those metrics to a real backend without changing application code. On security: never expose the full actuator endpoint set to the internet — use management.endpoints.web.exposure.include as an explicit allow-list (not *), put sensitive endpoints like /env, /beans, /heapdump and /shutdown behind authentication or off the public network entirely, and consider a separate management.server.port so actuator traffic doesn't even share the app's public listener.

The lesson behind it →
More on Observability