# A Spring Boot Review Checklist — Spring Boot

Source: https://www.skillbyai.com/en/spring-boot/p-check

> Before shipping a service.

## Questions to ask

Are dependencies injected through constructors? Are settings typed with @ConfigurationProperties and secrets external? Do controllers use DTOs, validate input and return problem details for errors? Are transactions on services, with open-in-view disabled? Are queries efficient (no N+1) and the schema managed by migrations? Are there web and data slice tests, with the main class kept minimal? Are only needed Actuator endpoints exposed and protected? Is Spring Security configured deny-by-default? Are timeouts set on outbound calls?

## The checklist

Use it in code reviews.

```text
[ ] constructor injection; small, focused services
[ ] @ConfigurationProperties; secrets from environment / secret store
[ ] DTO records; @Valid; RFC 9457 problem details for errors
[ ] @Transactional on services; spring.jpa.open-in-view=false
[ ] Flyway/Liquibase migrations; no N+1 queries
[ ] @WebMvcTest + @DataJpaTest (+ Testcontainers); minimal main class
[ ] Actuator: only needed endpoints, protected or separate port
[ ] Spring Security deny-by-default; authorisation in services
[ ] timeouts, pool sizes, virtual threads considered
[ ] one artifact promoted across environments; Boot kept up to date
```

## Automate the checks you can

Architecture tests (ArchUnit or Spring Modulith) can enforce layering rules in CI.

**Quiz:** Which item belongs on a Spring Boot review checklist?

- [ ] Expose all Actuator endpoints publicly
- [ ] Field injection everywhere
- [x] spring.jpa.open-in-view is disabled and transactions live in services
- [ ] Return JPA entities directly from every endpoint

*Answer:* spring.jpa.open-in-view is disabled and transactions live in services. Explicit boundaries and safe defaults.
