Sub-scope 09 (mongo) - execution probe: what the profile's TLS and timeout policy reaches revision=a24ece9cf797f7ea647e33bf846b115208ed1ba5 generatedAt=2026-08-30T00:24:04+00:00 One temporary probe class was added, run, and removed: src/test/.../security/Ss09TlsProbe.java (@Tag mongodb-contract, hermetic) No production source was modified. PROBE profile.tlsRequired=true -> validator ACCEPTED PROBE settings Boot builds from the README's URI (spring.data.mongodb.uri, line 37): sslEnabled=false connectTimeoutMs=10000 serverSelectionTimeoutMs=30000 poolMaxSize=100 serverApi=null uuidRepresentation=UNSPECIFIED PROBE settings MongoClientSettingsFactory would build: sslEnabled=true Reading: MongoSecurityProfileValidator accepts a production profile that declares TLS required, and nothing applies that declaration to the driver, because MongoClientSettingsFactory has no caller anywhere in the repository (8.1b, 8.1e). The connect timeout, server-selection timeout, pool bounds, Stable API declaration and pinned UUID representation the profile states are equally unapplied; the values above are the driver's own defaults. Contrast (8.1c): the identical defect on the observability half - a settings-builder method with no caller - was fixed by registering a MongoClientSettingsBuilderCustomizer in MongoDriverObservabilityAutoConfiguration. The same mechanism is available here and is not used. Note (8.1b): MongoTlsLaneTest proves the SERVER enforces TLS. It builds its own settings with applyToSslSettings(ssl -> ssl.enabled(true)) by hand (line 137), so it does not exercise the path from a profile's tlsRequired flag to a TLS connection. $ git status --short | wc -l 0 exit=0 $ git status --short exit=0