Part 03 · Spring Framework & Spring Boot · 3.4
Sai lầm và checklist Spring
Dùng danh sách này để phát hiện “Spring magic thinking”: câu trả lời chỉ nêu annotation nhưng không giải thích container phase, proxy call path, transaction hay resource semantics.
1. Hiểu sai nguy hiểm
Singleton bean tự động thread-safe.
Gắn
@Transactional ở đâu cũng tạo transaction, kể cả private method hoặc self-invocation.Spring Boot là “magic”, không cần hiểu conditions, proxy và application context.
Starter chính là auto-configuration hoặc BOM; có thể override/exclude dependency mà không xem dependency tree và compatibility.
Đổi mọi association sang EAGER sẽ giải quyết N+1.
ApplicationEvent là message broker có durable delivery.
Liveness nên kiểm tra mọi downstream dependency.
WebFlux hoặc virtual threads tự làm downstream và connection pool có capacity vô hạn.
2. Lỗi triển khai
- Field injection và mutable request state trong singleton.
- Controller chứa business logic hoặc expose managed entity.
- Remote call trong transaction giữ lock và connection.
- Lạm dụng
REQUIRES_NEWgây pool starvation. - OSIV che lazy loading, N+1 và boundary dữ liệu.
@Asyncdùng executor không bounded hoặc làm mất exception/context.- Expose Actuator env/config/loggers công khai.
- Cache key thiếu tenant/version hoặc invalidation không có failure policy.
- JWT chỉ kiểm signature nhưng bỏ issuer, audience, time hoặc algorithm policy.
- Tăng mọi pool cùng lúc thay vì tìm queue đầu tiên bị saturation.
3. Checklist kiến thức
- Tôi mô tả lifecycle từ bean definition đến proxied bean.
- Tôi phân biệt scope, lifecycle ownership và thread safety.
- Tôi giải thích self-invocation bằng call path.
- Tôi phân biệt Spring module, Boot starter, BOM và auto-configuration.
- Tôi đọc dependency tree, condition report và override auto-config có chủ đích.
- Tôi thiết kế custom starter có properties, conditions, back-off và ApplicationContextRunner tests.
- Tôi mô tả MVC request pipeline và đúng layer filter/interceptor/advice.
- Tôi chọn propagation, isolation, timeout và rollback rule theo use case.
- Tôi phân biệt flush với commit và managed entity với bulk DML.
- Tôi chẩn đoán N+1 bằng query evidence.
- Tôi hiểu SecurityFilterChain, object authorization, CORS và CSRF.
- Tôi thiết kế async executor, context propagation và error handling.
- Tôi phân biệt liveness/readiness và bảo vệ Actuator.
- Tôi hiểu BeanFactoryPostProcessor và BeanPostProcessor chạy ở phase nào.
- Tôi giải thích advisor ordering và transaction synchronization.
- Tôi hiểu SecurityContext và Reactor Context qua async boundary.
- Tôi phân biệt MVC, virtual threads và WebFlux theo execution model.
- Tôi debug saturation xuyên request, DB, executor và HTTP pools.
4. Definition of Done
- Trả lời được ít nhất 37/46 câu không mở đáp án.
- Giải thích được ít nhất 10/12 scenario bằng proxy, persistence context và commit boundary.
- Hoàn thành ít nhất 6/9 lab với failure evidence.
- Có integration test dùng PostgreSQL thật cho transaction, locking hoặc query behavior.
- Có evidence về filter/security, health/readiness và graceful shutdown.
- Có benchmark hoặc saturation investigation với workload và pool metrics rõ.