### profile: mgmtport
### management.server.port: 9001 / management.server.address: 127.0.0.1 / base-path: /manage

--- the application port no longer serves Actuator at all ---
  GET :8080/actuator/health                            401
  GET :8080/manage/health                              401
  GET :8080/orders/count                               200

--- the management port serves it on the new base path ---
  GET :9001/manage/health                              503
  GET :9001/actuator/health                            404
  GET :9001/orders/count                               404

  Note the last line. The management context has its own DispatcherServlet and does NOT
  see application controllers. That is the isolation you are paying for.

--- what the management context reports about itself ---
$ curl -s -u ops:ops-password http://127.0.0.1:9001/manage/diag
{
    "activeProfiles": [
        "mgmtport"
    ],
    "serverPort": "8080",
    "managementPort": "9001",
    "managementBasePath": "/manage",
    "exposureInclude": "*",
    "exposureExclude": "(none)",
    "healthShowDetails": "never",
    "exposedWebEndpointCount": 14,
    "exposedWebEndpoints": {
        "beans": [
            "GET beans"
        ],
        "conditions": [
            "GET conditions"
        ],
        "configprops": [
            "GET configprops",
            "GET configprops/{prefix}"
        ],
        "diag": [
            "GET diag"
        ],
        "env": [
            "GET env",
            "GET env/{toMatch}"
        ],
        "health": [
            "GET health",
            "GET health/{*path}"
        ],
        "info": [
            "GET info"
        ],
        "loggers": [
            "GET loggers",
            "GET loggers/{name}",
            "POST loggers/{name}"
        ],
        "mappings": [
            "GET mappings"
        ],
        "metrics": [
            "GET metrics",
            "GET metrics/{requiredMetricName}"
        ],
        "prometheus": [
            "GET prometheus"
        ],
        "sbom": [
            "GET sbom",
            "GET sbom/{id}"
        ],
        "scheduledtasks": [
            "GET scheduledtasks"
        ],
        "threaddump": [
            "GET threaddump",
            "GET threaddump"
        ]
    },
    "healthContributors": [
        "db  (DataSourceHealthIndicator)",
        "diskSpace  (DiskSpaceHealthIndicator)",
        "externalApi  (ExternalApiHealthIndicator)",
        "kafka  (KafkaHealthIndicator)",
        "livenessState  (LivenessStateHealthIndicator)",
        "ordersDatabase  (OrdersDatabaseHealthIndicator)",
        "ping  (PingHealthIndicator)",
        "readinessState  (ReadinessStateHealthIndicator)",
        "ssl  (SslHealthIndicator)"
    ]
}

--- listening sockets ---
$ ss -ltn | grep -E ':(8080|9001)'
LISTEN 0      100                     *:8080            *:*          
LISTEN 0      100    [::ffff:127.0.0.1]:9001            *:*          

  9001 is bound to 127.0.0.1 only. 8080 is bound to *. An ingress that forwards to 8080
  cannot reach Actuator no matter how the security rules are written.
