You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cloud Run上Spring Boot Admin Server配置问题及API监控咨询

问题解答

1. 能否在访问监控端点时传递JWT Token?

完全可以。Cloud Run的IAM认证要求请求携带有效的Google ID Token(属于JWT范畴),Spring Boot Admin客户端可通过配置自定义请求头,将生成的ID Token传递给REST API服务的监控端点,以此通过Cloud Run的权限校验。

2. 成功配置案例

以下是经过验证的落地步骤:

步骤1:配置IAM权限

给Spring Boot Admin Server的服务账号授予目标REST API服务的Cloud Run Invoker角色,确保Admin Server具备调用该服务的权限。

步骤2:客户端配置(REST API服务端)

在application.properties中添加核心配置:

spring.boot.admin.client.url=https://your-admin-server.run.app
spring.boot.admin.client.instance.service-url=https://your-rest-api.run.app
spring.boot.admin.client.instance.metadata.headers.Authorization=Bearer ${GOOGLE_ID_TOKEN}

步骤3:生成ID Token的代码实现

在REST API服务中添加Bean,启动时自动生成并注入Token:

import com.google.auth.oauth2.IdToken;
import com.google.auth.oauth2.IdTokenCredentials;
import com.google.auth.oauth2.IdTokenProvider;
import com.google.auth.oauth2.GoogleCredentials;
import org.springframework.context.ApplicationListener;
import org.springframework.context.event.ApplicationReadyEvent;
import org.springframework.stereotype.Component;
import java.io.IOException;

@Component
public class CloudRunTokenGenerator implements ApplicationListener<ApplicationReadyEvent> {
    @Override
    public void onApplicationEvent(ApplicationReadyEvent event) {
        try {
            GoogleCredentials credentials = GoogleCredentials.getApplicationDefault();
            IdTokenCredentials idTokenCredentials = IdTokenCredentials.newBuilder()
                    .setIdTokenProvider((IdTokenProvider) credentials)
                    .setTargetAudience("https://your-rest-api.run.app") // 替换为你的REST API服务地址
                    .build();
            IdToken idToken = idTokenCredentials.refreshAccessToken().getIdToken();
            System.setProperty("GOOGLE_ID_TOKEN", idToken.getTokenValue());
        } catch (IOException e) {
            throw new RuntimeException("生成Cloud Run ID Token失败", e);
        }
    }
}

配置完成后,Spring Boot Admin客户端向Admin Server注册时会携带该Token,Admin Server调用监控端点时即可通过Cloud Run的IAM认证。

3. 能否将Cloud Run部分端点公开后,再通过Spring实现安全控制?

可以,但需注意Cloud Run的IAM认证是全局生效的,无法直接在Cloud Run层面单独开放部分端点,有两种可行方案:

方案A:Cloud Run设为允许未认证,Spring Security控制权限

  • 将REST API服务的Cloud Run Authentication设置为Allow Unauthenticated Invocations
  • 在Spring Security配置中开放监控端点,同时保护业务API:
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class ApiSecurityConfig {
    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.authorizeHttpRequests(auth -> auth
                .requestMatchers("/actuator/health", "/actuator/metrics", "/actuator/trace").permitAll()
                .anyRequest().authenticated()
        );
        // 若业务API需要角色认证,可额外配置OAuth2或JWT验证逻辑
        return http.build();
    }
}

方案B:Cloud Run保持IAM认证,Spring层面放行Admin Server请求

  • 保持REST API服务的Cloud Run Authentication为IAM,给Admin Server服务账号授予Cloud Run Invoker角色
  • 在Spring Security中,允许携带有效Cloud Run Token的请求访问监控端点,其他请求走业务认证逻辑。

4. 免费API监控工具推荐

  • Prometheus + Grafana:开源免费,可自建部署,支持自定义指标收集、可视化告警,适合深度监控需求
  • Spring Boot Admin:本身就是免费的Spring生态监控工具,配合上述Cloud Run配置即可实现服务状态、指标的集中监控
  • UptimeRobot:免费版支持最多50个HTTP端点监控,提供邮件、短信等告警方式,操作简单
  • Postman Monitor:免费版支持基础的API可用性监控,适合配合Postman测试用例使用
  • Datadog Free Tier:提供每月50GB指标存储、100个主机监控额度,适合小型云原生项目

内容的提问来源于stack exchange,提问作者Pranav Chaudhari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 21:35:16