You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security干扰Actuator端点,如何取消/actuator/prometheus登录验证?

取消Actuator Prometheus端点的Spring Security验证

方法1:通过配置文件放行

根据你的Spring Boot版本,在application.yml或application.properties中添加对应配置:

针对Spring Boot 2.x

management:
  endpoints:
    web:
      exposure:
        include: prometheus # 确保prometheus端点暴露
  security:
    enabled: false # 关闭Actuator整体安全验证
# 若需仅放行prometheus、保留其他端点验证,可替换为:
# spring:
#   security:
#     ignored: /actuator/prometheus

针对Spring Boot 3.x

Spring Boot 3.x移除了management.security.enabled属性,需通过Spring Security的授权规则配置放行:

management:
  endpoints:
    web:
      exposure:
        include: prometheus
spring:
  security:
    authorization:
      requests:
        authorize-requests:
          - pattern: /actuator/prometheus
            access: permitAll()
          - pattern: /**
            access: authenticated()

方法2:通过Java配置类自定义Security规则

创建Spring Security配置类,明确放行/actuator/prometheus路径:

Spring Boot 3.x及以上(使用SecurityFilterChain)

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/actuator/prometheus").permitAll()
                .anyRequest().authenticated()
            );
        return http.build();
    }
}

Spring Boot 2.x(基于WebSecurityConfigurerAdapter,已弃用)

若项目仍使用旧版配置方式:

import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
                .antMatchers("/actuator/prometheus").permitAll()
                .anyRequest().authenticated();
    }
}

注意事项

  • 必须确保prometheus端点已通过management.endpoints.web.exposure.include=prometheus配置暴露。
  • 若存在其他自定义Spring Security规则,需保证/actuator/prometheus的放行规则优先级高于其他验证规则。

内容的提问来源于stack exchange,提问作者developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 20:35:14