Lesson 25 / 25
A Spring Boot Review Checklist
Before shipping a service.
Questions to ask
Are dependencies injected through constructors? Are settings typed with @ConfigurationProperties and secrets external? Do controllers use DTOs, validate input and return problem details for errors? Are transactions on services, with open-in-view disabled? Are queries efficient (no N+1) and the schema managed by migrations? Are there web and data slice tests, with the main class kept minimal? Are only needed Actuator endpoints exposed and protected? Is Spring Security configured deny-by-default? Are timeouts set on outbound calls?
The checklist
Use it in code reviews.
[ ] constructor injection; small, focused services
[ ] @ConfigurationProperties; secrets from environment / secret store
[ ] DTO records; @Valid; RFC 9457 problem details for errors
[ ] @Transactional on services; spring.jpa.open-in-view=false
[ ] Flyway/Liquibase migrations; no N+1 queries
[ ] @WebMvcTest + @DataJpaTest (+ Testcontainers); minimal main class
[ ] Actuator: only needed endpoints, protected or separate port
[ ] Spring Security deny-by-default; authorisation in services
[ ] timeouts, pool sizes, virtual threads considered
[ ] one artifact promoted across environments; Boot kept up to dateAutomate the checks you can
Architecture tests (ArchUnit or Spring Modulith) can enforce layering rules in CI.
Quick check: Which item belongs on a Spring Boot review checklist?
- Expose all Actuator endpoints publicly
- Field injection everywhere
- spring.jpa.open-in-view is disabled and transactions live in services
- Return JPA entities directly from every endpoint
Answer
spring.jpa.open-in-view is disabled and transactions live in services — Explicit boundaries and safe defaults.