Spring Security干扰Actuator端点,如何取消/actuator/prometheus登录验证?
取消Actuator Prometheus端点的Spring Security验证
方法1:通过配置文件放行
根据你的Spring Boot版本,在application.yml或application.properties中添加对应配置:
针对Spring Boot 2.x
management: endpoints: web: exposure: include: prometheus # 确保prometheus端点暴露 security: enabled: false # 关闭Actuator整体安全验证 # 若需仅放行prometheus、保留其他端点验证,可替换为: # spring: # security: # ignored: /actuator/prometheus
针对Spring Boot 3.x
Spring Boot 3.x移除了management.security.enabled属性,需通过Spring Security的授权规则配置放行:
management: endpoints: web: exposure: include: prometheus spring: security: authorization: requests: authorize-requests: - pattern: /actuator/prometheus access: permitAll() - pattern: /** access: authenticated()
方法2:通过Java配置类自定义Security规则
创建Spring Security配置类,明确放行/actuator/prometheus路径:
Spring Boot 3.x及以上(使用SecurityFilterChain)
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .requestMatchers("/actuator/prometheus").permitAll() .anyRequest().authenticated() ); return http.build(); } }
Spring Boot 2.x(基于WebSecurityConfigurerAdapter,已弃用)
若项目仍使用旧版配置方式:
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; @Configuration public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .antMatchers("/actuator/prometheus").permitAll() .anyRequest().authenticated(); } }
注意事项
- 必须确保
prometheus端点已通过management.endpoints.web.exposure.include=prometheus配置暴露。 - 若存在其他自定义Spring Security规则,需保证
/actuator/prometheus的放行规则优先级高于其他验证规则。
内容的提问来源于stack exchange,提问作者developer
相关产品推荐
相关产品推荐

