Spring Boot startup time: bean-by-bean diagnosis, and one directory per post
Adds spring-boot-startup-time/, the companion project for BLOG-618: a runnable Spring Boot 4.1.1 application on JDK 25 that installs BufferingApplicationStartup and FlightRecorderApplicationStartup behind a system property, and a /diag/startup endpoint that computes step self time -- the number /actuator/startup does not give you and the one that names the actual culprits. Captured under docs/output/: the step tree sorted both ways, the same startup as JFR events, a +5000-class experiment putting 0.11 ms per scanned class on the classpath scan tax, the silent truncation a 2048-step buffer performs, and JDK 25 AOT cache timings (6.93 s to 4.82 s). Post body and metadata live in post/. Moves the existing Actuator project into actuator-in-production/ so the repository holds one directory per article; the root README is now an index.
This commit is contained in:
13
actuator-in-production/docs/output/04-heapdump-leak.txt
Normal file
13
actuator-in-production/docs/output/04-heapdump-leak.txt
Normal file
@@ -0,0 +1,13 @@
|
||||
### profiles: exposeall,open PLUS --management.endpoint.heapdump.access=unrestricted
|
||||
|
||||
$ curl -s -o /tmp/heap.hprof -w 'status=%{http_code} bytes=%{size_download} type=%{content_type}' http://localhost:8080/actuator/heapdump
|
||||
status=200 bytes=59186852 type=application/octet-stream
|
||||
|
||||
$ strings /tmp/heap.hprof | grep -c 'S3CRET-partner-credential'
|
||||
1
|
||||
$ strings /tmp/heap.hprof | grep -o 'not-a-real-password[^"]*' | head -1
|
||||
not-a-real-password-but-watch-what-/actuator/env-does-with-it!
|
||||
|
||||
/actuator/env masked both of these to ******.
|
||||
/actuator/heapdump handed over the process memory that contains them in plaintext.
|
||||
Sanitisation is a property-rendering feature. It is not a security boundary.
|
||||
Reference in New Issue
Block a user