spring-boot-engineer
jeffallan/claude-skills
Generates Spring Boot 3.x services, REST APIs, Spring Security 6, and reactive WebFlux endpoints for microservices.
What is spring-boot-engineer?
Specialist skill for building Spring Boot 3.x applications with layered architecture, Spring Data JPA, Spring Security 6 authentication, and reactive endpoints. Use when designing microservices, implementing REST APIs, configuring security, or setting up data access patterns in Java.
- Generate Spring Boot 3.x project structures with layered architecture (entity, repository, service, controller)
- Create REST controllers with input validation, exception handling, and proper HTTP status codes
- Implement Spring Security 6 authentication flows, OAuth2, JWT, and method-level security
- Set up Spring Data JPA repositories with custom queries and transaction management
- Configure reactive WebFlux endpoints for non-blocking request handling
- Design microservices with constructor injection and externalized configuration
How to install spring-boot-engineer
npx skills add https://github.com/jeffallan/claude-skills --skill spring-boot-engineer- Java 17 or later
- Spring Boot 3.x project (Maven or Gradle)
- Familiarity with Spring Framework concepts (dependency injection, annotations)
How to use spring-boot-engineer
- 1.Analyze your service requirements and define entity models, repositories, and API endpoints
- 2.Design the architecture including security needs, data access patterns, and cloud integration
- 3.Implement layers in order: entities, repositories, services (with constructor injection), controllers
- 4.Add Spring Security configuration and validate security rules compile and tests pass
- 5.Write unit and integration tests, run test suite and confirm all pass
- 6.Configure Actuator health checks and observability, validate `/actuator/health` returns UP
Use cases
- Building a microservice with REST endpoints, JPA persistence, and Spring Security authentication
- Implementing reactive endpoints using Spring WebFlux for high-throughput APIs
- Setting up Spring Data repositories with custom query methods and transaction boundaries
- Configuring OAuth2 or JWT-based security for API access control
- Creating global exception handlers and validation for consistent API error responses
- Backend engineers building Spring Boot microservices
- Java developers implementing REST APIs with Spring Framework
- Teams adopting Spring Security 6 and reactive patterns
- Architects designing layered Spring Boot applications
spring-boot-engineer FAQ
Always use constructor injection. Avoid @Autowired on fields. Constructor injection makes dependencies explicit, improves testability, and prevents NullPointerException.
Use @Valid on @RequestBody parameters and create a @RestControllerAdvice with @ExceptionHandler for MethodArgumentNotValidException. Return structured error responses, never stack traces.
Use @Transactional for write operations (create, update, delete) to manage commits and rollbacks. Use @Transactional(readOnly=true) for queries to optimize database behavior and signal intent.
No. Do not call .block() inside WebFlux chains. Keep reactive code fully non-blocking or use traditional Spring MVC for blocking operations.
Never store secrets in application.properties or application.yml. Use environment variables or Spring Cloud Config Server for externalized, secure configuration.
Full instructions (SKILL.md)
Source of truth, from jeffallan/claude-skills.
name: spring-boot-engineer description: Generates Spring Boot 3.x configurations, creates REST controllers, implements Spring Security 6 authentication flows, sets up Spring Data JPA repositories, and configures reactive WebFlux endpoints. Use when building Spring Boot 3.x applications, microservices, or reactive Java applications; invoke for Spring Data JPA, Spring Security 6, WebFlux, Spring Cloud integration, Java REST API design, or Microservices Java architecture. license: MIT metadata: author: https://github.com/Jeffallan version: "1.1.0" domain: backend triggers: Spring Boot, Spring Framework, Spring Cloud, Spring Security, Spring Data JPA, Spring WebFlux, Microservices Java, Java REST API, Reactive Java role: specialist scope: implementation output-format: code related-skills: java-architect, database-optimizer, microservices-architect, devops-engineer
Spring Boot Engineer
Core Workflow
- Analyze requirements — Identify service boundaries, APIs, data models, security needs
- Design architecture — Plan microservices, data access, cloud integration, security; confirm design before coding
- Implement — Create services with constructor injection and layered architecture (see Quick Start below)
- Secure — Add Spring Security, OAuth2, method security, CORS configuration; verify security rules compile and pass tests. If compilation or tests fail: review error output, fix the failing rule or configuration, and re-run before proceeding
- Test — Write unit, integration, and slice tests; run
./mvnw test(or./gradlew test) and confirm all pass before proceeding. If tests fail: review the stack trace, isolate the failing assertion or component, fix the issue, and re-run the full suite - Deploy — Configure health checks and observability via Actuator; validate
/actuator/healthreturnsUP. If health isDOWN: check thecomponentsdetail in the response, resolve the failing component (e.g., datasource, broker), and re-validate
Reference Guide
Load detailed guidance based on context:
| Topic | Reference | Load When |
|---|---|---|
| Web Layer | references/web.md | Controllers, REST APIs, validation, exception handling |
| Data Access | references/data.md | Spring Data JPA, repositories, transactions, projections |
| Security | references/security.md | Spring Security 6, OAuth2, JWT, method security |
| Cloud Native | references/cloud.md | Spring Cloud, Config, Discovery, Gateway, resilience |
| Testing | references/testing.md | @SpringBootTest, MockMvc, Testcontainers, test slices |
Quick Start — Minimal Working Structure
A standard Spring Boot feature consists of these layers. Use these as copy-paste starting points.
Entity
@Entity
@Table(name = "products")
public class Product {
@Id
@GeneratedValue(strategy = GenerationType.IDENTITY)
private Long id;
@NotBlank
private String name;
@DecimalMin("0.0")
private BigDecimal price;
// getters / setters or use @Data (Lombok)
}
Repository
public interface ProductRepository extends JpaRepository<Product, Long> {
List<Product> findByNameContainingIgnoreCase(String name);
}
Service (constructor injection)
@Service
public class ProductService {
private final ProductRepository repo;
public ProductService(ProductRepository repo) { // constructor injection — no @Autowired
this.repo = repo;
}
@Transactional(readOnly = true)
public List<Product> search(String name) {
return repo.findByNameContainingIgnoreCase(name);
}
@Transactional
public Product create(ProductRequest request) {
var product = new Product();
product.setName(request.name());
product.setPrice(request.price());
return repo.save(product);
}
}
REST Controller
@RestController
@RequestMapping("/api/v1/products")
@Validated
public class ProductController {
private final ProductService service;
public ProductController(ProductService service) {
this.service = service;
}
@GetMapping
public List<Product> search(@RequestParam(defaultValue = "") String name) {
return service.search(name);
}
@PostMapping
@ResponseStatus(HttpStatus.CREATED)
public Product create(@Valid @RequestBody ProductRequest request) {
return service.create(request);
}
}
DTO (record)
public record ProductRequest(
@NotBlank String name,
@DecimalMin("0.0") BigDecimal price
) {}
Global Exception Handler
@RestControllerAdvice
public class GlobalExceptionHandler {
@ExceptionHandler(MethodArgumentNotValidException.class)
@ResponseStatus(HttpStatus.BAD_REQUEST)
public Map<String, String> handleValidation(MethodArgumentNotValidException ex) {
return ex.getBindingResult().getFieldErrors().stream()
.collect(Collectors.toMap(FieldError::getField, FieldError::getDefaultMessage));
}
@ExceptionHandler(EntityNotFoundException.class)
@ResponseStatus(HttpStatus.NOT_FOUND)
public Map<String, String> handleNotFound(EntityNotFoundException ex) {
return Map.of("error", ex.getMessage());
}
}
Test Slice
@WebMvcTest(ProductController.class)
class ProductControllerTest {
@Autowired MockMvc mockMvc;
@MockBean ProductService service;
@Test
void createProduct_validRequest_returns201() throws Exception {
var product = new Product(); product.setName("Widget"); product.setPrice(BigDecimal.TEN);
when(service.create(any())).thenReturn(product);
mockMvc.perform(post("/api/v1/products")
.contentType(MediaType.APPLICATION_JSON)
.content("""{"name":"Widget","price":10.0}"""))
.andExpect(status().isCreated())
.andExpect(jsonPath("$.name").value("Widget"));
}
}
Constraints
MUST DO
| Rule | Correct Pattern |
|---|---|
| Constructor injection | public MyService(Dep dep) { this.dep = dep; } |
| Validate API input | @Valid @RequestBody MyRequest req on every mutating endpoint |
| Type-safe config | @ConfigurationProperties(prefix = "app") bound to a record/class |
| Appropriate stereotype | @Service for business logic, @Repository for data, @RestController for HTTP |
| Transaction scope | @Transactional on multi-step writes; @Transactional(readOnly = true) on reads |
| Hide internals | Catch domain exceptions in @RestControllerAdvice; return problem details, not stack traces |
| Externalize secrets | Use environment variables or Spring Cloud Config — never application.properties |
MUST NOT DO
- Use field injection (
@Autowiredon fields) - Skip input validation on API endpoints
- Use
@Componentwhen@Service/@Repository/@Controllerapplies - Mix blocking and reactive code (e.g., calling
.block()inside a WebFlux chain) - Store secrets or credentials in
application.properties/application.yml - Hardcode URLs, credentials, or environment-specific values
- Use deprecated Spring Boot 2.x patterns (e.g.,
WebSecurityConfigurerAdapter)
Related skills
More from jeffallan/claude-skills and the wider catalog.

sql-pro
Optimize SQL queries, design schemas, and troubleshoot database performance issues.

sre-engineer
Define SLOs, manage error budgets, and automate production reliability at scale.

swift-expert
Expert Swift development for iOS/macOS with SwiftUI, async/await, and protocol-oriented architecture.

terraform-engineer
Senior Terraform engineer for infrastructure as code across AWS, Azure, and GCP with modular design and state management.

test-master
Comprehensive testing specialist for unit, integration, E2E, performance, and security tests.

the-fool
Play devil's advocate with structured critical reasoning to stress-test ideas, plans, and decisions.