Spring Cloud
Spring Cloud
Beginner
Q1: What is Spring Cloud?
Spring Cloud is a set of tools/patterns for building distributed systems and microservices with Spring.
Q2: Why use Spring Cloud?
It provides common microservice building blocks like config, discovery, gateway, and resilience integrations.
Q3: Is Spring Cloud a replacement for Spring Boot?
No: It builds on Spring Boot.
Q4: What problem does Spring Cloud Config solve?
Centralized external configuration across multiple services/environments.
Q5: What is a Config Server?
Service that provides versioned centralized configuration to client applications.
Q6: What is a Config Client?
Application that fetches configuration from Config Server.
Q7: Why centralize configuration?
Consistency, easier changes, auditability, and reduced duplication.
Q8: What is service discovery?
Mechanism for finding service instances dynamically at runtime.
Q9: What is a service registry?
A directory where service instances register themselves.
Q10: What is Eureka?
A popular Netflix-origin service registry often used with Spring Cloud Netflix.
Q11: What is client-side load balancing?
Client chooses target service instance from discovered list.
Q12: What is Spring Cloud LoadBalancer?
Spring Cloud abstraction for client-side load balancing.
Q13: Why load balancing matters?
Distributes traffic and improves availability/scalability.
Q14: What is API Gateway?
Single entry point for routing, auth, and cross-cutting concerns at edge.
Q15: What is Spring Cloud Gateway?
Reactive API gateway for routing and filtering requests.
Q16: Why use a gateway?
Centralizes edge policies (security, rate limits, routing, observability).
Q17: What is route predicate in Gateway?
Condition deciding whether route matches a request (path, host, headers, etc.).
Q18: What is gateway filter?
Logic applied before/after request forwarding.
Q19: Example gateway filter use cases?
Authentication, header rewriting, rate limiting, logging, retries.
Q20: What is distributed configuration refresh concept?
Updating config in running services without full redeploy (when supported).
Q21: What is @RefreshScope?
Allows bean reinitialization on config refresh triggers.
Q22: What is a circuit breaker?
Pattern that stops calls to failing dependency temporarily.
Q23: Why circuit breaker is important?
Prevents cascading failures and resource exhaustion.
Q24: What is retry pattern?
Automatically retry transiently failed operations.
Q25: What is timeout pattern?
Fail operation if response takes longer than allowed threshold.
Q26: What is bulkhead pattern?
Isolate resources so one failing dependency doesn’t consume all capacity.
Q27: What is fallback?
Alternative response/path when dependency call fails.
Q28: What is Resilience4j?
Fault-tolerance library integrated with Spring Cloud ecosystem.
Q29: What is rate limiting?
Restricting request volume per key/time window.
Q30: Why use rate limiting at gateway?
Protects downstream services from overload/abuse.
Q31: What is distributed tracing?
Tracking request flow across multiple services.
Q32: Why tracing in microservices?
Helps diagnose latency and failures across service boundaries.
Q33: What is correlation ID?
Identifier propagated across calls to tie logs/events together.
Q34: What is OpenFeign?
Declarative HTTP client often used in Spring Cloud apps.
Q35: Why use Feign?
Less boilerplate for service-to-service HTTP calls.
Q36: What is service-to-service communication style?
Usually HTTP/gRPC/messaging depending architecture needs.
Q37: What is eventual consistency?
Data becomes consistent over time rather than instantly.
Q38: Why eventual consistency common in microservices?
Distributed transactions are costly/complex across services.
Q39: What is Spring Cloud Bus concept?
Broadcasts configuration/state change events across services.
Q40: What is centralized logging role in cloud systems?
Aggregates logs from all instances for querying and incident response.
Q41: What is health check endpoint?
Endpoint reporting service health status.
Q42: What are liveness and readiness?
Liveness: process alive; readiness: can serve traffic.
Q43: Why readiness checks matter?
Prevent traffic routing to not-ready instances.
Q44: What is config profile?
Environment-specific config set (dev/test/prod etc.).
Q45: What is bootstrap phase (historical concept)?
Early context for external config loading; modern approaches evolved with config data APIs.
Q46: What is fail-fast config client behavior?
Application fails startup if config server unreachable/misconfigured.
Q47: Why might fail-fast be desirable?
Avoids running with invalid/missing critical configuration.
Q48: What is discovery-first vs config-first lookup idea?
Whether config/discovery endpoints are resolved via registry or direct URI.
Q49: What is zone/region awareness concept?
Routing traffic to nearby/appropriate instances for latency/availability.
Q50: What is blue/green deployment?
Two environments with controlled traffic switch between versions.
Q51: What is canary deployment?
Gradual rollout to small traffic subset first.
Q52: What is gateway path rewriting?
Changing incoming path before forwarding to backend.
Q53: What is header propagation?
Forwarding selected headers (trace/auth/context) downstream.
Q54: What is token relay pattern?
Gateway forwards OAuth2 access token to downstream services.
Q55: What is beginner microservice anti-pattern?
Creating too many tiny services without clear boundaries.
Q56: What is service boundary?
Clear ownership of data and business capability per service.
Q57: Why keep shared libraries minimal?
Avoid tight coupling and lockstep deployments.
Q58: What is beginner resilience mistake?
Retries without timeout/backoff causing overload.
Q59: Beginner observability baseline?
Structured logs + metrics + traces with correlation IDs.
Q60: Beginner best practice?
Start simple: config, discovery, gateway, and basic resilience with clear ownership.
Intermediate
Q61: What is Config Server backend repository?
Source of properties (Git, file system, vault integrations, etc.).
Q62: Why store config in Git?
Versioning, audit trail, PR review workflow.
Q63: How is config encryption handled conceptually?
Encrypt sensitive values and decrypt in controlled runtime contexts.
Q64: What is secret management best practice?
Use dedicated secret managers, not plain-text config repos.
Q65: What is config precedence in distributed apps?
Deterministic order of property sources to resolve overrides.
Q66: What is refresh endpoint risk?
Unauthorized refresh could alter runtime behavior unexpectedly.
Q67: How secure refresh operations?
Strong authN/authZ, network restrictions, auditing.
Q68: What is Eureka self-preservation mode concept?
Registry behavior to avoid mass eviction during network instability.
Q69: Why stale registry entries are dangerous?
Clients may route traffic to dead instances.
Q70: How reduce stale discovery risks?
Appropriate lease intervals, health checks, and quick deregistration.
Q71: What is gateway global filter?
Filter applied to all routes.
Q72: Route-specific filter vs global filter?
Scoped to one route vs all routes.
Q73: What is predicate ordering concern?
Match precedence affects which route handles a request.
Q74: What is StripPrefix filter?
Removes leading path segments before forwarding.
Q75: What is RewritePath filter?
Regex-based path transformation.
Q76: What is RequestRateLimiter in Gateway?
Filter enforcing distributed rate limits per key.
Q77: What key resolver does in rate limiting?
Determines client identity key (IP, API key, user id, etc.).
Q78: What is gateway retry filter caveat?
Unsafe retries on non-idempotent methods can duplicate side effects.
Q79: Safe retry strategy at gateway?
Retry only idempotent/transient failure scenarios with bounded attempts.
Q80: What is circuit breaker filter in gateway?
Wraps routed calls with fault-tolerance behavior and optional fallback.
Q81: What is fallbackHeaders filter use?
Adds error context headers for fallback handlers.
Q82: What is forward:/ fallback pattern?
Internal forwarding to fallback endpoint.
Q83: What is Feign client customization?
Timeouts, encoders/decoders, interceptors, error decoders.
Q84: Why set Feign timeouts explicitly?
Avoid hanging threads and uncontrolled latency.
Q85: What is Feign error decoder?
Maps HTTP error responses to domain exceptions.
Q86: What is load-balanced RestTemplate/WebClient?
Client with discovery-aware instance resolution.
Q87: What is per-service resilience config?
Different timeout/retry/circuit settings per downstream dependency.
Q88: Why per-service tuning matters?
Dependencies have different latency/error profiles.
Q89: What is hedging request concept?
Sending secondary request after delay to reduce tail latency (use carefully).
Q90: What is timeout budget?
Allocating end-to-end SLA across service hops.
Q91: Why coordinate timeout budgets?
Prevents upstream waiting longer than downstream total possible completion.
Q92: What is distributed transaction challenge?
Atomic commits across services are complex and fragile.
Q93: What is saga pattern?
Sequence of local transactions with compensating actions.
Q94: Choreography vs orchestration saga?
Event-driven decentralized flow vs central coordinator.
Q95: What is outbox pattern in Spring Cloud systems?
Store events atomically with local DB changes then publish asynchronously.
Q96: Why outbox helps consistency?
Avoids dual-write race between DB commit and message publish.
Q97: What is idempotent consumer?
Consumer that safely handles duplicate messages/events.
Q98: What is deduplication key?
Unique key to detect and ignore repeated operations.
Q99: What is contract testing in microservices?
Validate API compatibility between producers and consumers.
Q100: Why contract tests matter in cloud systems?
Frequent independent deployments increase integration break risk.
Q101: What is backward-compatible API evolution?
Additive changes and controlled deprecations without breaking clients.
Q102: What is semantic versioning for APIs?
Version strategy communicating compatibility expectations.
Q103: What is gateway auth offloading?
Performing authentication at gateway before forwarding.
Q104: Can auth be only at gateway?
Usually no; downstream services still need authorization checks (defense in depth).
Q105: What is token propagation pitfall?
Losing user context across async/thread boundaries or inter-service calls.
Q106: What is mTLS between services?
Mutual TLS for strong service identity and encrypted transport.
Q107: What is service mesh relation to Spring Cloud?
Mesh can provide traffic/security features; Spring Cloud still handles app-level concerns.
Q108: What is config drift in microservices?
Services diverge unintentionally in runtime configuration.
Q109: How detect config drift?
Central audits, startup reports, policy checks, and runtime inventory.
Q110: What is observability cardinality problem?
Too many unique labels (userId/path raw) overload metrics systems.
Q111: How reduce cardinality?
Use bounded tags like route templates and status classes.
Q112: What is tracing sampling?
Recording subset of traces to control overhead.
Q113: Head-based vs tail-based sampling?
Head samples early; tail samples after seeing full trace outcome.
Q114: What is intermediate anti-pattern in Spring Cloud?
Gateway bloated with business logic.
Q115: Better gateway role?
Edge concerns only: routing, security, resilience, observability.
Q116: What is consumer timeout vs retry interplay?
Retry without shorter timeouts can multiply latency and load.
Q117: What is connection pool isolation for clients?
Separate pools per dependency to avoid noisy-neighbor exhaustion.
Q118: What is bulkhead at thread level?
Dedicated thread pools/semaphores per remote dependency.
Q119: What is partial outage handling?
Degrade gracefully with fallbacks and feature-level resilience.
Q120: What is incident triage in microservices?
Correlate logs, traces, metrics, deploy changes, and dependency health.
Q121: What is intermediate testing strategy?
Unit + component + contract + integration + resilience scenario tests.
Q122: Why include network fault simulation?
Real outages often involve latency, drops, DNS, and throttling.
Q123: What is chaos testing purpose?
Validate system resilience under controlled failure injection.
Q124: Intermediate maturity signal?
Teams can explain dependency policies: timeout, retry, breaker, fallback per call.
Q125: Intermediate best practice?
Make distributed-system assumptions explicit and test them continuously.
Advanced
Q126: What is control plane vs data plane distinction?
Control plane manages config/policies; data plane handles live request traffic.
Q127: Why separate control and data concerns?
Improves reliability, security boundaries, and operational clarity.
Q128: What is multi-region deployment challenge?
Latency, failover coordination, and data consistency across regions.
Q129: Active-active vs active-passive tradeoff?
Active-active improves availability but increases consistency/operational complexity.
Q130: What is global traffic management role?
Route users to healthy nearest regions/services.
Q131: What is split-brain risk in distributed registries?
Network partition creates conflicting cluster views.
Q132: How mitigate split-brain impacts?
Quorum strategies, health fencing, conservative failover rules.
Q133: What is cascading failure pattern?
One dependency failure propagates and overloads upstream services.
Q134: Primary defense against cascading failures?
Timeouts + circuit breakers + bulkheads + load shedding.
Q135: What is load shedding?
Dropping low-priority traffic under overload to preserve core functionality.
Q136: What is adaptive concurrency limit?
Dynamically tuning in-flight requests based on observed latency/errors.
Q137: What is brownout strategy?
Temporarily disable noncritical features during stress.
Q138: What is retry budget?
Cap total retries to prevent runaway amplification.
Q139: Why jitter in backoff is critical?
Prevents synchronized retry spikes.
Q140: What is exactly-once delivery myth?
Most systems provide at-least-once; correctness comes from idempotency design.
Q141: What is monotonic read concern with replicas?
Clients may observe older data after newer writes due to lag.
Q142: How handle read-after-write needs?
Sticky sessions, primary reads for critical paths, or version checks.
Q143: What is schema evolution in event-driven microservices?
Versioned events with backward/forward compatibility handling.
Q144: What is consumer-first compatibility rule?
Producers should evolve without breaking existing consumers.
Q145: What is anti-corruption layer in distributed architecture?
Translates external contracts into internal domain models.
Q146: Why avoid shared database across microservices?
Tight coupling, deployment lockstep, broken ownership boundaries.
Q147: What is platform engineering role for Spring Cloud?
Provide paved-road templates, policy defaults, and shared operational tooling.
Q148: What is golden path microservice template?
Preconfigured secure/observable/resilient service baseline.
Q149: What is policy-as-code in cloud platforms?
Declarative governance rules validated automatically in CI/runtime.
Q150: What is progressive delivery?
Gradual exposure of new versions using canary/feature flags.
Q151: What is shadow traffic?
Mirroring production requests to new version without affecting users.
Q152: What is SLO-driven operations?
Operating services against explicit latency/error/availability objectives.
Q153: Why error budget matters?
Guides release velocity vs reliability tradeoffs.
Q154: What is high-cardinality log cost issue?
Storage/query cost explosion and slower incident analysis.
Q155: What is secure-by-default cloud posture?
TLS everywhere, least privilege, secret rotation, audited access.
Q156: What is workload identity concept?
Service identity issued dynamically (not static long-lived secrets).
Q157: Why avoid long-lived service credentials?
Higher compromise risk and harder rotation.
Q158: What is supply-chain security relevance?
Dependencies/images/pipelines can introduce vulnerabilities at scale.
Q159: What is SBOM role?
Inventory of software components for vulnerability/compliance tracking.
Q160: What is runtime drift detection?
Detecting unauthorized/unexpected config/runtime state changes.
Q161: What is failure domain design?
Architecting boundaries so failures stay localized.
Q162: What is cell-based architecture concept?
Independent service cells reduce blast radius and improve resilience.
Q163: What is queue-based load leveling?
Buffer spikes via messaging to smooth downstream processing.
Q164: What is backpressure in distributed pipelines?
Controlling producer rate to match consumer capacity.
Q165: What is advanced gateway anti-pattern?
Single gigantic gateway team/binary bottlenecking all changes.
Q166: Better gateway organizational model?
Shared platform standards + domain-owned route governance.
Q167: What is migration strategy from monolith to Spring Cloud?
Incremental extraction by business capability with strangler pattern.
Q168: What is strangler pattern?
Gradually route functionality from old system to new services.
Q169: What is advanced testing pyramid for cloud systems?
Many unit/component tests, strong contracts, targeted E2E and resilience drills.
Q170: What is game day in operations?
Planned reliability exercise rehearsing failure scenarios and response.
Q171: What is biggest advanced Spring Cloud anti-pattern?
Adopting many distributed patterns without operational readiness/observability.
Q172: What is mature Spring Cloud architecture outcome?
Clear service boundaries, resilient communication, governed configuration, and fast recovery.
Q173: What is final reliability principle?
Design every remote call as a potential failure point.
Q174: What is final security principle?
Never trust network location—authenticate and authorize every hop.
Q175: Final maturity principle?
Spring Cloud success comes from disciplined operations, not only framework features.