Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A health endpoint that returns a count instead of a service name is not wrong by default. Whether the response is correct depends on who calls the endpoint and what they need to do with the answer. The symptom alone cannot tell you whether the count is a tally of dependencies, an aggregate of checks, a deliberate privacy choice, or a defect. The useful work is to capture the real response, identify each consumer, and decide what a public response should disclose.

What the symptom does and does not establish

Three things are unknown from the symptom: which service is answering, what the count measures, and why the endpoint is reachable without credentials. A count could be the number of healthy downstream components, the number of failed checks, the number of queued jobs, or a placeholder the framework emits when no detail is requested. Each of those has a different fix. Treat any explanation that starts with “the endpoint returns a count because” as a hypothesis until you have seen the response.

Returning a count is also not automatically safer or more useful than returning a name. A name can help an operator locate a failing service. A count can hide which component is failing. The right choice depends on the consumer, as the sections below explain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Capture the actual response before changing anything

A public API response can be inspected directly, so start with the raw HTTP exchange rather than a dashboard or a client library’s summary. Record the following for an unauthenticated request:

#1 Best Overall
Hosyond 7 Inch Touchscreen IPS DSI Display Compatible with Raspberry Pi 5/4/3, 800x480 Pixel Capacitive Screen MIPI Driver-Free Interface
  • 7 inches, 800x480 pixels, IPS type, wide viewing angle, capacitive touchscreen, enjoy smooth touch response and excellent clarity for all your Raspberry Pi projects.
  • Specially designed, simply connect to your raspberry pi's MIPI DSI interface. (No additional connections required.)
  • Fully Compatible with Raspberry Pi 5/ 4B / 3B+ / 3B / 3A+ / 2B. (No HDMI port, not compatible with any other device.)
  • Supports for Raspbian OS 2 points to zoom the page(old version), for Ubuntu/Kali/Win10 IoT (single-touch only). Support backlight brightness adjustment.
  • Easy to use, no configuration required, plug and play (for new and configuration unchanged raspberry pi systems). Instructions was provided.
  1. The full request URL, including path and any query parameters.
  2. The HTTP status code and the response headers, especially Content-Type, Cache-Control, and any authentication challenge.
  3. The complete response body, without trimming fields.
  4. The authentication state: no credentials, then a valid credential for the same route.

A basic capture with curl looks like this, using a hypothetical host:

curl -i https://health.example.com/health

Repeat the request with the authorization header your monitoring or operations tooling normally uses, and compare the two bodies field by field. If the public and authenticated responses are identical, the count is not a privacy filter. If they differ, the difference is the design question you need to answer.

Identify who the response is for

Most health endpoints serve one of four consumers, and each needs a different amount of detail. The table below uses the comparison axes that matter for this decision: consumer need, detail level, access model, and the sensitivity of what is disclosed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Hosyond 3.5 Inch 480x320 Touch Screen TFT LCD SPI Display Panel for Raspberry Pi B, B+, 2B, 3B, 3B+,4B, 5
  • 3.5 inch, 320×480 resolution, TFT LCD resistive touch screen, clear display effect and using easily with a touch pen.
  • No external power supply required.Just plug it into the Raspberry Pi board correctly and install the driver to use it. (Driver installation tutorial is provided)
  • This 3.5 inch touch screen is specially designed for Raspberry Pi, perfectly suitable for Pi5, Pi4B, Pi3B+, Pi3B, Pi2B, Pi1B (directly-pluggable).
  • Compatible with a variety of systems, such as for Raspbian system, ubuntu system, kali Linux system and so on.
  • You can get one 3.5 inch raspberry pi touch screen and one touch pen, what the important things is that the project introduction, code and tutorial is provided.We provide technical support, If you encounter any difficulties during use, please contact us first to help you solve it.
Consumer What it needs from the response Typical detail level Typical access model Sensitivity to watch
Liveness probe (orchestrator) Whether the process should be restarted Status only Internal network, often unauthenticated Low, provided the route is not reachable from the internet
Readiness probe or load balancer Whether to send traffic to this instance Status, sometimes a coarse result Internal network or public edge Low to moderate
Monitoring system Which component failed and how Component checks Authenticated or network-restricted High: dependency names, versions, hosts
Operator or on-call engineer Diagnostic detail for troubleshooting Full component diagnostics Authenticated, least privilege High
External user or partner Whether the service is available to them Status only Public Should be minimal; names of internal systems are rarely needed

If your endpoint serves an external user, a count may be the most information that user needs. If it serves a monitoring system, a count may be too little, and the monitoring team will need named components behind authentication or a network boundary.

Decide what a public response may disclose

Use this checklist to sort each field in the response:

  • Does an unauthenticated caller need this field to take an action? If not, remove it from the public response.
  • Does the field name an internal host, service, database, queue, or version? Treat it as infrastructure information and move it behind authentication or network controls.
  • Does the field contain user data, identifiers, or business logic values? Remove it from any public route.
  • Does the field help an attacker map the system more than it helps a legitimate caller? Reduce it to a status value.
  • Are error messages generic? Failure responses should not expose stack traces, dependency connection strings, or internal exception text.

Keep a minimal public signal only when an external consumer needs it. Place richer component checks behind authentication or network restrictions when they expose operational details.

Rank #3
Hosyond 5 Inch Touchscreen IPS MIPI DSI Display Compatible with Raspberry Pi 5/4/3, 800x480 Pixel Capacitive Screen Driver-Free Interface
  • 5-inch 800*480 resolution capacitive touch screen, IPS type, good viewing angle.
  • The MIPI DSI interface directly outputs, plug and play, no driver installation required.
  • As a touchscreen monitor, compatible with Raspberry Pi 5 / 4B / 3B+ / 3B / 3A+ / 2B / 1B+ / 1A+. (No HDMI. Not compatible with any other devices.)
  • Supports for Raspbian OS 2 points to zoom the page(old version), for Ubuntu/Kali/Win10 IoT (single-touch only). Support PWM backlight brightness adjustment.
  • Easy to use -> No configuration required (for new and configuration unchanged systems). Provide detailed usage documentation.

Verify behaviour across authentication states

Field filtering in a user interface is not an access control. A browser page or mobile app may hide a field, but the raw API response can still contain it. The OWASP Web Security Testing Guide describes excessive data exposure this way: “Excessive data exposure occurs when an API returns more information in its responses than the client needs to display or function.” The practical test is to compare what the client shows with what the server returns.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Send an unauthenticated request and save the full body.
  2. Send the same request with each credential type your system accepts, including a low-privilege account if one exists.
  3. Search every body for internal hostnames, IP addresses, version strings, stack fragments, identifiers, and personal data.
  4. Confirm that the server, not the client, omits fields that a given caller should not receive. Do not rely on a front-end script to hide them.
  5. Repeat the test from outside your network if the route is reachable from the internet.

How established health-check designs handle detail

Several published designs show how selective detail can work. They are models, not universal requirements, and you should adapt them to your own risk.

The CMS Health Check RFC

The CMS Health Check RFC allows a client to request named checks through a names query parameter, so a caller receives only the components it asks for. Its security guidance is direct: “For security reasons, any implementation receiving an HTTP request should only respond if the request is made over HTTPS and includes a valid security token.” This is a design requirement of that RFC. It is not a rule that applies to every health endpoint.

Rank #4
Sale
JUNEBOX 8 inch Touchscreen Monitor for Raspberry Pi 5/4/Zero 2 W (Inky)
  • 【OPEN-FRAME DESIGN, DIRECT PI MOUNTING】— No back case,no bulky enclosure:screw your Raspberry Pi 5/4B/CM4 straight onto the back — the pre-drilled mounting holes align perfectly — for a clean,integrated build. A Raspberry Pi Screen and power solution in one.Plug & play,No drivers to install,Assembly takes under 3 minutes.
  • 【8-INCH IPS Touchscreen】—The Raspberry Pi Monitor has 1280x800 resolution touchscreen which in a 16:10 ratio gives extra vertical space for code,dashboards and documents.1000:1 contrast,60Hz refresh and 72% NTSC (16.7M colors) keep gradients smooth; the 178° viewing angle and 400 cd/m² brightness keep the picture clear from any position.Software low-blue-light mode reduces eye strain during long sessions while preserving color.
  • 【10-POINT CAPACITIVE MULTI-TOUCH】— the Raspberry Pi touchscreen equipped with true 10-point touch that can lets you tap,swipe,pinch,rotate and use multi-finger gestures with fast,accurate response — smooth and instant for every interaction, from dashboards and drawing apps to map navigation and Kiosk-style Pi projects.
  • 【BUILT-IN DUAL SPEAKERS】— Two built-in speakers deliver clear audio without extra speakers or wiring — perfect for media players, retro game consoles, smart-assistant projects and video playback
  • 【SIMPLE CONNECTION FOR PI AND PC】— Raspberry Pi: HDMI for video + the included 3-pin cable for touch. Windows/Mac laptops and desktops: HDMI + Type-C for touch. When connected solely via HDMI, the standard HDMI input allows it to serve as a universal monitor for mini PCs, game consoles and other devices.

The Health Check Response Format

The Health Check Response Format uses the application/health+json media type. Its only required member is status. Optional members include version, releaseId, notes, output, checks, links, serviceId, and description. The specification says checks can carry details about downstream systems and components. A practical reading is that a public response can contain only status, while a restricted response adds checks. Whether you should include serviceId or description publicly is a decision the format leaves to you.

Open Policy Agent

The Open Policy Agent API reference describes a basic health result that reports operational status. It also documents optional checks, such as whether bundle activation or plugin state is healthy. The pattern is the same: a basic status is cheap to expose, and deeper checks are opt-in.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When the count is a defect rather than a design

Use this branch if the count appears to be accidental:

Best Value
Sale
ROADOM 10.1" Touchscreen Monitor, 1024x600 IPS Raspberry Pi Screen, HDMI
  • 【IPS 1024×600 HD Display & 178° Wide Viewing Angle】 Experience crisp, vivid visuals on this ROADOM 10.1 inch touch screen monitor featuring a sharp 1024×600 HD resolution — a significant upgrade from standard 800×480 displays. The IPS touch screen panel delivers rich colors and a wide 178° viewing angle, ensuring clear picture quality whether you're viewing head-on or from the side. This 10 inch monitor punches above its weight with 300cd/m² brightness and a 700:1 contrast ratio. For the best touch experience, remove the pre-installed screen protector
  • 【Responsive 5-Point Capacitive Touch — Plug & Play】 Enjoy swift, precise touch interactions with a rapid 3-5ms response time. This touchscreen monitor supports 5-point capacitive touch and intuitive gestures — tapping, zooming, swiping, and mouse clicks. A true plug and play touchscreen that requires no driver installation: simply connect via HDMI for video and USB Type-C for touch, and it works instantly with Windows, Linux (Raspberry Pi OS / Ubuntu / Debian), and macOS. This responsive touchscreen integrates seamlessly — no configuration headaches. Note: touch functionality is not supported on iOS systems
  • 【Made for Raspberry Pi — Pi 5/4/3/Zero & Beyond】 Built for the Raspberry Pi ecosystem, this raspberry pi touchscreen works with all Pi versions including Raspberry Pi 5, 4, 3, and Zero — an ideal raspberry pi monitor and raspberry pi display. Also compatible with Banana Pi, Retro Pi, and Octo Pi. Power your Pi and screen from one source with the included GPIO cable — a clean gpio powered screen setup. Supports Raspberry Pi OS, Noobs, Debian, Ubuntu, Kodi. Note: touch not supported on iOS / macOS. A versatile raspberry pi with screen solution for makers, tinkerers, and developers
  • 【Dual Built-in Speakers & All-in-One Protective Case】 Rich, clear audio from dual built-in 1W×2 speakers — this monitor with speaker needs no external audio. Unlike bare touchscreen display boards, ROADOM integrates the LCD panel, circuit board, and protective casing into one seamless unit. No exposed PCBs, fragile ribbon cables, or DIY headaches. This touchscreen with case and monitor with dual speakers is ready right out of the box. The spacious 10.1-inch screen gives you extra real estate for portable gaming, video streaming, and diy touchscreen projects — more room to create than cramped 7-inch displays
  • 【3 Display Modes, Versatile Stand & What You Get】 This portable touchscreen supports three display modes: Duplicate, Extend, and Second Screen Only. With a generous 10.1-inch screen, it excels as a laptop second screen for coding, a desktop second monitor for multitasking, a cctv monitor for security, or a 3d printer monitor for your workshop. The adjustable stand customizes height and tilt angle. Package includes: 10.1" monitor, HDMI & Micro-HDMI cables, USB-A to Type-C & Type-C to USB-A cables, GPIO power cable, 5V 3A power adapter, Pi mounting kit, and user manual — a complete portable hdmi monitor package
  • The count changes between identical requests with no change in system state. Check for caching, a shared proxy, or a route handler that returns a different schema under load.
  • The count is zero even when a dependency is known to be down. The aggregator may be skipping checks. Compare the output with the logs for the check runner.
  • The authenticated response contains the name, but the public response contains only a count, and the code path that builds the response changed recently. Review the commit that introduced the filter, and confirm the filter is intended.
  • Monitoring tools fail to parse the response after a deploy. Confirm the response conforms to the media type your tools expect.

Whatever the cause, change the behaviour in the server response itself, then repeat the capture steps above so the fix is verified against the raw body.

Decision rule

Keep a public health endpoint minimal: a status and nothing that identifies internal components. Move component names, dependency states, versions, and diagnostics to an authenticated or network-restricted route, and give monitoring and operators access to that route. If the current count is intentional, document what it counts and who it serves. If it is accidental, fix the server response and verify it with unauthenticated and authenticated requests. Without the endpoint contract and representative responses, no one can say which of these applies to your service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.