You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot版本升级后Actuator无法访问问题求助

Spring Boot 2.7.15 Actuator /actuator/health 无法访问排查方案

问题现象

  • 升级至Spring Boot 2.7.15后,访问/actuator/health端点提示无法访问,外部检查脚本返回exit code 6
  • 应用启动日志显示Exposing 1 endpoint(s) beneath base path '/actuator',但健康端点实际不可达
  • 已引入spring-boot-starter-actuator及相关依赖,尝试过常规方案未解决

排查与解决步骤

1. 明确配置端点暴露规则

Spring Boot 2.7.x默认仅暴露health端点,但需确认配置未被覆盖。在application.properties或application.yml中显式配置:

# 确保health端点被暴露
management.endpoints.web.exposure.include=health
# 如需显示健康检查详细信息,可开启(可选)
management.endpoint.health.show-details=always

YAML格式配置:

management:
  endpoints:
    web:
      exposure:
        include: health
  endpoint:
    health:
      show-details: always

2. 检查基础路径是否被修改

若配置了management.endpoints.web.base-path,会改变Actuator的基础路径。例如设置为/manage时,健康端点路径变为/manage/health。检查配置文件中是否有该属性,调整访问路径或恢复默认值:

# 恢复默认基础路径(若被修改过)
management.endpoints.web.base-path=/actuator

3. 清理冗余依赖

当前依赖中spring-boot-starter-actuator已包含spring-boot-actuator-autoconfigure,同时引入会导致冗余甚至冲突,移除单独的自动配置依赖:

<!-- 移除以下冗余依赖 -->
<!--
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-actuator-autoconfigure</artifactId>
</dependency>
-->

另外,spring-boot-autoconfigure已被父依赖spring-boot-starter-parent管理,无需单独指定版本引入,可考虑移除该依赖以避免版本不一致问题。

4. 确认Web环境依赖

Actuator HTTP端点仅在Web环境下生效,若项目未引入spring-boot-starter-web,需添加该依赖:

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-web</artifactId>
</dependency>

5. 放行安全拦截规则

若项目使用Spring Security或其他安全框架,需配置允许访问/actuator/health:

Spring Security 5.7+ 无配置类方式:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
public class SecurityConfig {
    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.authorizeHttpRequests(auth -> auth
                .requestMatchers("/actuator/health").permitAll()
                .anyRequest().authenticated()
        );
        return http.build();
    }
}

旧版配置类方式:

import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests()
                .antMatchers("/actuator/health").permitAll()
                .anyRequest().authenticated();
    }
}

6. 验证端点暴露状态

开启DEBUG级别日志(在application.properties中设置logging.level.org.springframework.boot.actuator=DEBUG),启动应用后查看日志,确认health端点是否被正确暴露。也可临时配置暴露actuator端点,访问/actuator查看所有已暴露端点列表:

management.endpoints.web.exposure.include=health,actuator

内容的提问来源于stack exchange,提问作者Hard Worker

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 13:05:13