You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 3.1集成Jetty:健康检查报Invalid SNI错误求助

Spring Boot 3迁移后健康检查报Invalid SNI的解决方案

问题原因

Spring Boot 3默认集成的Jetty版本(11.x及以上)对TLS连接的SNI(服务器名称指示)校验规则进行了收紧,当编排器的健康检查请求未携带有效的SNI信息时,Jetty会直接返回400: Invalid SNI错误。而Spring Boot 2.7使用的Jetty 9.x版本对这类请求的处理更宽松,不会触发该报错。

解决方法

1. 调整Jetty的SNI校验规则

通过自定义Jetty配置类,禁用SNI检查或关闭SNI主机校验,让服务接受未携带有效SNI的请求:

import org.eclipse.jetty.server.Connector;
import org.eclipse.jetty.server.Server;
import org.eclipse.jetty.server.SslConnectionFactory;
import org.eclipse.jetty.util.ssl.SslContextFactory;
import org.springframework.boot.web.embedded.jetty.JettyServerCustomizer;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;

@Configuration
public class JettySslCustomizerConfig {
    @Bean
    public JettyServerCustomizer jettyServerCustomizer() {
        return server -> {
            for (Connector connector : server.getConnectors()) {
                SslConnectionFactory sslConnFactory = connector.getConnectionFactory(SslConnectionFactory.class);
                if (sslConnFactory != null) {
                    SslContextFactory.Server sslContextFactory = sslConnFactory.getSslContextFactory();
                    // 禁用SNI强制要求,允许无SNI的请求
                    sslContextFactory.setSniRequired(false);
                    // 可选:关闭SNI主机匹配校验
                    // sslContextFactory.setSniHostCheck(false);
                }
            }
        };
    }
}

2. 确认健康检查请求协议

检查编排器是否使用了正确的协议访问健康检查端点:

  • 如果服务配置了强制HTTPS,但编排器用HTTP请求/health,可能导致协议不匹配触发SNI相关错误,需调整编排器使用HTTPS请求,或在Spring Boot中配置同时支持HTTP和HTTPS连接器。

3. 临时降级Jetty版本(不推荐)

如果上述方案无法快速生效,可临时将Jetty版本降级到Spring Boot 2.7使用的9.x版本,但这会失去Spring Boot 3带来的版本升级收益,仅作为临时应急方案。

内容的提问来源于stack exchange,提问作者Gennadiy Kartashevskyy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 10:54:57