Start here. This is the direct spoken answer to practice first.
Overview
Diagnostic endpoints can shorten an incident, but their output and write actions often expose more risk than ordinary application APIs.
I do not expose high-risk Actuator endpoints publicly. Thread dumps, heap dumps, environment and configuration views, mappings, and logger controls are limited to an authenticated operator path and preferably a private management network. I enable only what the incident process needs and treat downloaded artifacts as sensitive production data.