Part 12 · Applications

Configuration, profiles and secret boundaries

Prerequisites: 01-ecosystem

Which configuration value actually wins?

application.yml: baseline; Environment: deployment overrides; CLI / other sources: ordered inputs; Effective value: bind + validate. Connections: application.yml to Effective value (property sources); Environment to Effective value (property sources); CLI / other sources to Effective value (property sources)
The complete precedence order is documented in Boot. This diagram illustrates merging, not the whole ranked list. [S22]

Goal & mental model verified

Boot combines ordered property sources into an Environment and binds structured configuration. Later/higher-precedence sources can override earlier values. Profiles select configurations; they are not a security boundary.

[S22]

Worked example · design exercise synthesis

For pricing.timeout, define a default and an environment-specific override. Bind settings into a typed ConfigurationProperties object and validate required values instead of scattering string lookups.

[S22]

Engineering decision synthesis

Treat operational settings as external inputs and make startup fail clearly on invalid required configuration. This improves repeatability but demands disciplined deployment configuration.

[S22]

Pitfall & diagnosis synthesis

An unexpected environment variable can override a checked-in value. Logging a full configuration dump can reveal secrets; a prod profile does not protect management endpoints.

[S22]

Improve & validate synthesis

Document the effective source and precedence for critical settings. Review secrets access separately and test startup with missing, malformed and overridden values.

[S22]
Keep this: Debug the effective configuration, not just the file you edited.
Check yourself: Why might changing application.yml have no effect?

A higher-precedence source can supply the same property.

Sources & further reading

  1. [S22] Externalized configuration

    Spring project maintainers · documentation · accessed 2026-10-09 · Documentation retrieved 2026-10-09

    Supports: Property source precedence; ConfigurationProperties binding

    Read the linked section to validate the mechanism and its version-specific constraints.