dancan254/spring-boot-skills
Spring Boot 4 skills: scaffold, JPA, Redis, Kafka/RabbitMQ, security, DevOps, testing, OTel, Spring AI RAG, MCP servers, and legacy migration.
Add OpenAPI docs and REST conventions to an existing Spring Boot 4 Maven project — SpringDoc, API versioning, ProblemDetail error schemas, DTO conventions. Use when asked to add OpenAPI or Swagger, document or version an API, or define REST conventions. Not for auth — use spring-security.
Add or update Dockerfile, docker-compose.yml, and GitHub Actions CI for an existing Spring Boot Maven project; reads the project first. Use when asked to dockerize a project, add CI or GitHub Actions, or set up DevOps. Not for security scanning — use security-hardening. Not for new projects — use spring-scaffold.
Make outbound HTTP calls resilient in an existing Spring Boot 4 Maven project — circuit breakers, retries, and timeouts with RestClient and Resilience4j, plus tests that prove failures degrade gracefully. Use when asked to add retries or a circuit breaker, call external APIs reliably, or protect against a flaky downstream. Not for inbound rate limiting — use redis-setup.
Add Apache Kafka producers and consumers to an existing Spring Boot 4 Maven project — Spring Kafka config, JSON events, dead-letter topics, Testcontainers tests, compose wiring. Use when asked to add Kafka, Kafka topics, or event streaming. If messaging is requested without naming a broker, ask Kafka or RabbitMQ first.
Migrate a Spring Boot 2.x or 3.x app to Boot 4.x (Maven or Gradle) — audit first, then OpenRewrite-led version hops with a green build per hop, covering Jakarta, Jackson 3, modular starters, and runtime-only breakages. Use when asked to upgrade or migrate Spring Boot, or fix javax imports after an upgrade. Not for new projects.
Expose an existing Spring Boot 4 Maven service as an MCP server with Spring AI — transport choice, @McpTool tools, tool hints, endpoint security, and verification with a real MCP client. Use when asked to add MCP, expose tools to an LLM or agent, or let an AI call my backend. Not for RAG — use spring-ai-rag.
Wire OpenTelemetry end to end into an existing Spring Boot 4 Maven project — OTLP export for traces, metrics, and logs, the Logback appender Boot doesn't ship, a local Grafana LGTM backend, and a runbook proving all three signals land. Use when asked to add observability or OpenTelemetry, or when logs never reach the backend.
Pentest and security-audit a running Spring Boot app — OWASP ZAP DAST scans, manual probes for auth, headers, CORS, actuator, and error leakage, and a findings report with fixes. Use when asked to pentest an app, run a DAST scan, or audit whether an app is secure end to end. Not for dependency/SBOM/image scanning — use security-hardening. Not for adding auth — use spring-security.
Add RabbitMQ producers and consumers to an existing Spring Boot 4 Maven project — Spring AMQP config, JSON messages, dead-letter exchanges, Testcontainers tests, compose wiring. Use when asked to add RabbitMQ, AMQP, or work queues. If messaging is requested without naming a broker, ask Kafka or RabbitMQ first.
Add Redis caching and rate limiting to an existing Spring Boot 4 Maven project — Spring Cache on Redis with per-cache TTLs, graceful cache failure, Redis-backed rate limiting, Testcontainers tests, compose wiring. Use when asked to add Redis, cache an endpoint or query, or rate limit an API.
Add DevSecOps checks to an existing Maven project — OWASP dependency check, secrets scanning, container image scanning, SBOM, and a security GitHub Actions workflow. Use when asked to harden a project, scan dependencies or images, add an SBOM, or set up security CI. Not for app authentication — use spring-security.
Add LLM chat to an existing Spring Boot 4 Maven project with Spring AI — ChatClient with system prompting, structured output to records, @Tool tool calling, Ollama or OpenAI. Use when asked to add an AI chat endpoint or call an LLM. Not for document Q&A — use spring-ai-rag. Not for exposing tools to agents — use mcp-server.
Add a RAG pipeline to an existing Spring Boot 4 Maven project with Spring AI — PgVector store, Ollama or OpenAI embeddings, document ingestion and chunking, a retrieval advisor, and tests proving answers are grounded. Use when asked to add RAG, semantic or vector search, embeddings, or chat with my documents. Not for MCP — use mcp-server.
Add JPA persistence to an existing Spring Boot 4 Maven project — entities, repositories, auditing, Flyway migrations, and Testcontainers integration tests. Use when asked to add a database, JPA entities or repositories, or Flyway migrations. Assumes a feature-sliced layout like spring-scaffold generates.
Scaffold a new Spring Boot 4 Maven project — feature-sliced packages, ProblemDetail error handling, Testcontainers, Dockerfile, GitHub Actions CI, AGENTS.md, and README. Opinionated: Lombok, PostgreSQL, and OpenTelemetry by default. Use when asked to create, scaffold, or bootstrap a new Spring Boot project. Not for existing projects.
Add JWT resource-server security to an existing Spring Boot 4 Maven project — security config, claim-to-role mapping, method security, and tests. Use when asked to secure an API, add JWT or OAuth2 resource server auth, or add roles and permissions. Not for dependency, secret, or image scanning — use security-hardening.
Write, repair, and modernise tests in an existing Spring Boot 4 project (Maven or Gradle) — Testcontainers 2.x, integration vs unit routing, and the Boot 4 test API (@MockitoBean, MockMvcTester, RestTestClient). Use when asked to add or fix tests, set up Testcontainers, or migrate off Testcontainers 1.x or @MockBean.