PrepZone Logo
PrepZone

How HTTP Reaches Your Code

Servlets, the container, and the request-response cycle that Spring Boot builds on.

Read these first

Why this matters

  • Spring Boot builds on the Servlet API — understanding the container explains why annotations like @GetMapping work and where request threads come from.
  • Production issues such as thread pool exhaustion and slow responses often trace back to servlet container behaviour, not your business logic.
  • Interviewers frequently ask how an HTTP request reaches a Java method; a clear servlet mental model separates confident answers from vague ones.

The servlet contract

Before Spring existed, Java web apps implemented jakarta.servlet.http.HttpServlet. The container calls doGet, doPost, or similar methods for each request. Your BookStore health check could have looked like this:

Java
public class HealthServlet extends HttpServlet {
    @Override
    protected void doGet(HttpServletRequest req, HttpServletResponse resp)
            throws IOException {
        resp.setContentType("application/json");
        resp.getWriter().write("{\"status\":\"UP\"}");
    }
}

Spring MVC replaces hand-written servlets with @RestController classes, but underneath Tomcat still dispatches to a DispatcherServlet — a servlet that delegates to your controllers.

Key servlet types

  • Servlet container — Embedded Tomcat in Boot; manages threads, parses HTTP, and invokes servlets.
  • HttpServletRequest — Read-only view of headers, path, query params, and body.
  • HttpServletResponse — Where you set status codes, headers, and write the response body.
  • Filter — Runs before the servlet; used for logging, compression, and security (covered later).
BrowserSends HTTP request
Servlet containerTomcat / Jetty
Your servletdoGet / doPost
BrowserReceives HTTP response
The container receives the TCP connection, parses HTTP, and delegates to your servlet code.

From URL to handler method

When a client calls GET /api/books/42, the container:

Request handling steps

  1. Accepts the TCP connection on port 8080.
  2. Parses the HTTP request line and headers.
  3. Matches the path against registered servlet mappings.
  4. Invokes DispatcherServlet.service(), which finds @GetMapping("/api/books/{id}") on BookController.
  5. Serialises the returned BookResponse to JSON and flushes the response.

The entire round trip happens on one container thread unless you explicitly go async.

Embedded Tomcat in Spring Boot

Boot ships with an embedded servlet container so you never deploy a WAR to a standalone Tomcat. Running BookStoreApplication starts Tomcat on the classpath:

Java
server:
  port: 8080
  servlet:
    context-path: /bookstore

With context-path set, every endpoint moves under /bookstore — useful when multiple services share a gateway.

Request and response headers

Headers carry metadata the container does not interpret for routing:

Java
@GetMapping("/api/books")
public List<BookSummary> listBooks(
        @RequestHeader(value = "Accept-Language", defaultValue = "en") String locale) {
    return bookService.findAll(locale);
}

Content-Type: application/json tells the client how to parse the body. Accept tells the server what format the client prefers. Spring's HttpMessageConverter handles the conversion automatically.

Thread-per-request model

Tomcat maintains a thread pool (default max 200). Each request occupies one thread for its full duration. A slow database query in BookService blocks that thread until the query completes. This is why connection pool sizing and query performance matter at the web layer.

Servlet spec vs Spring abstractions

AspectServlet layerSpring Boot equivalent
URL mappingweb.xml servlet mapping@GetMapping, @PostMapping
Request filteringFilterFilter bean or Spring Security chain
Request dataHttpServletRequest@PathVariable, @RequestBody
Response bodyManual JSON writingHttpMessageConverter + Jackson
  • URL mapping

    Servlet layerweb.xml servlet mapping
    Spring Boot equivalent@GetMapping, @PostMapping
  • Request filtering

    Servlet layerFilter
    Spring Boot equivalentFilter bean or Spring Security chain
  • Request data

    Servlet layerHttpServletRequest
    Spring Boot equivalent@PathVariable, @RequestBody
  • Response body

    Servlet layerManual JSON writing
    Spring Boot equivalentHttpMessageConverter + Jackson

You rarely touch servlets directly in Boot, but knowing they exist explains stack traces that mention DispatcherServlet and StandardWrapperValve.

Observing the flow locally

Start the BookStore app and watch Tomcat log the port:

Java
./mvnw spring-boot:run
curl -v http://127.0.0.1:8080/api/books

The -v flag prints request and response headers — the same bytes Tomcat parsed before your controller ran.

Quick recall

Everything you need if you only revisit this box.

  • A servlet container (Tomcat) parses HTTP and invokes servlet code on a thread-per-request model.
  • Spring MVC's DispatcherServlet is a servlet that maps URLs to @RestController methods.
  • Boot embeds Tomcat — no external server install or WAR deployment required.
  • HttpServletRequest and HttpServletResponse are the low-level API; Spring wraps them with annotations.
  • Thread pool exhaustion is a container-level problem caused by blocking I/O in handlers.
  • Filters run before servlets and form the basis of Spring Security's filter chain.

Test yourself

Answer these before moving on — recall is what makes it stick.