How do I make use of Spring Security for securing the actuator endpoints but not interfere with any of the other application URLs? The security mechanism in our application is handled by a different framework so I would like to disable Spring Security by default and only enabled for /actuator/ endpoints.
To achieve this, I've added the following to the initialization class.
@SpringBootApplication(exclude = { SecurityAutoConfiguration.class })
With that, the Spring Security default configuration is disabled. After this, what changes do I need to make configure security for actuator endpoints?