Spring Boot版本升级后Actuator无法访问问题求助
问题现象
- 升级至Spring Boot 2.7.15后,访问
/actuator/health端点提示无法访问,外部检查脚本返回exit code 6 - 应用启动日志显示
Exposing 1 endpoint(s) beneath base path '/actuator',但健康端点实际不可达 - 已引入
spring-boot-starter-actuator及相关依赖,尝试过常规方案未解决
排查与解决步骤
1. 明确配置端点暴露规则
Spring Boot 2.7.x默认仅暴露health端点,但需确认配置未被覆盖。在application.properties或application.yml中显式配置:
# 确保health端点被暴露 management.endpoints.web.exposure.include=health # 如需显示健康检查详细信息,可开启(可选) management.endpoint.health.show-details=always
YAML格式配置:
management: endpoints: web: exposure: include: health endpoint: health: show-details: always
2. 检查基础路径是否被修改
若配置了management.endpoints.web.base-path,会改变Actuator的基础路径。例如设置为/manage时,健康端点路径变为/manage/health。检查配置文件中是否有该属性,调整访问路径或恢复默认值:
# 恢复默认基础路径(若被修改过) management.endpoints.web.base-path=/actuator
3. 清理冗余依赖
当前依赖中spring-boot-starter-actuator已包含spring-boot-actuator-autoconfigure,同时引入会导致冗余甚至冲突,移除单独的自动配置依赖:
<!-- 移除以下冗余依赖 --> <!-- <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-actuator-autoconfigure</artifactId> </dependency> -->
另外,spring-boot-autoconfigure已被父依赖spring-boot-starter-parent管理,无需单独指定版本引入,可考虑移除该依赖以避免版本不一致问题。
4. 确认Web环境依赖
Actuator HTTP端点仅在Web环境下生效,若项目未引入spring-boot-starter-web,需添加该依赖:
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency>
5. 放行安全拦截规则
若项目使用Spring Security或其他安全框架,需配置允许访问/actuator/health:
Spring Security 5.7+ 无配置类方式:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests(auth -> auth .requestMatchers("/actuator/health").permitAll() .anyRequest().authenticated() ); return http.build(); } }
旧版配置类方式:
import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http.authorizeRequests() .antMatchers("/actuator/health").permitAll() .anyRequest().authenticated(); } }
6. 验证端点暴露状态
开启DEBUG级别日志(在application.properties中设置logging.level.org.springframework.boot.actuator=DEBUG),启动应用后查看日志,确认health端点是否被正确暴露。也可临时配置暴露actuator端点,访问/actuator查看所有已暴露端点列表:
management.endpoints.web.exposure.include=health,actuator
内容的提问来源于stack exchange,提问作者Hard Worker

