You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

TCP负载均衡器后SpringBoot服务隐藏内部API的最佳实践与方案

Spring Boot服务仅暴露指定API的最佳实践方案

针对你在TCP负载均衡器后部署Spring Boot服务,需要对外暴露指定业务API、限制Actuator等内部监控端点公开访问的需求,除了同主机部署NGINX做代理,还有以下几种实用方案:

1. 利用Spring Boot原生配置+Spring Security细粒度管控

这是最轻量化的方案,无需额外部署组件,直接通过Spring自身配置实现:

  • Actuator端点暴露控制:在application.yml里明确指定需要暴露的监控端点,避免全量暴露:
    management:
      endpoints:
        web:
          exposure:
            include: prometheus,health  # 只保留Prometheus指标和健康检查端点
          base-path: /actuator
      endpoint:
        prometheus:
          enabled: true
    
  • IP白名单限制:结合Spring Security,给Actuator端点添加IP访问限制,只允许内部监控系统(比如Prometheus)的IP段访问:
    @Configuration
    public class SecurityConfig {
        @Bean
        public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
            http.authorizeHttpRequests(auth -> auth
                    // 业务API允许外部任意访问
                    .requestMatchers("/api/**").permitAll()
                    // Actuator仅允许指定内部IP段访问
                    .requestMatchers("/actuator/**").hasIpAddress("192.168.0.0/24")
                    .anyRequest().authenticated()
            );
            return http.build();
        }
    }
    

2. 负载均衡器层面配置访问规则

如果你的TCP负载均衡器支持HTTP七层转发(比如AWS ALB、阿里云SLB七层模式、Nginx Plus),可以直接在负载均衡器上做统一管控:

  • 路由规则配置:仅将外部请求转发到/api/**等业务路径,直接拒绝所有访问/actuator/**的外部请求
  • IP白名单配置:针对/actuator/**路径,单独设置IP白名单,只允许Prometheus所在的内部IP段访问
  • 若负载均衡器仅支持TCP四层转发,可以将业务API和Actuator分别用不同端口暴露,负载均衡器仅对外开放业务API的端口,Actuator端口仅对内网开放

3. 统一API网关管控(微服务场景)

如果是微服务架构,推荐用Spring Cloud Gateway或Zuul这类统一API网关,所有外部流量都经过网关:

  • 网关仅配置业务API的路由规则,比如将/user-service/api/**转发到用户服务的对应路径,完全不配置Actuator的路由
  • Actuator端点仅允许内部监控系统通过内网直接访问服务实例,不走网关
  • 网关还能统一处理认证、限流等逻辑,实现集中式的API权限管控

示例Spring Cloud Gateway路由配置:

spring:
  cloud:
    gateway:
      routes:
        - id: user-service-api
          uri: lb://user-service
          predicates:
            - Path=/user-service/api/**
          filters:
            - StripPrefix=2

4. 主机防火墙规则限制

在每个服务主机上配置防火墙(firewalld/iptables),通过端口或IP规则限制访问:

  • 假设业务API用8080端口,Actuator用9090端口:
    • 允许所有IP访问业务端口:
      # firewalld命令
      firewall-cmd --add-port=8080/tcp --permanent
      # iptables命令
      iptables -A INPUT -p tcp --dport 8080 -j ACCEPT
      
    • 仅允许内部IP段访问Actuator端口:
      # firewalld命令
      firewall-cmd --add-rich-rule='rule family="ipv4" source address="192.168.0.0/24" port port="9090" protocol="tcp" accept' --permanent
      # iptables命令
      iptables -A INPUT -p tcp --dport 9090 -s 192.168.0.0/24 -j ACCEPT
      iptables -A INPUT -p tcp --dport 9090 -j DROP
      
    • 最后重新加载防火墙规则:
      firewall-cmd --reload
      

方案选择建议

  • 单服务场景:优先用Spring Boot原生配置+Spring Security,轻量化且无额外组件
  • 已有负载均衡器支持七层转发:优先在负载均衡器层面配置,统一管控更高效
  • 微服务场景:推荐用统一API网关,实现集中式的API权限和流量管控
  • 无法修改服务配置或负载均衡器:用主机防火墙或你原本考虑的同主机NGINX代理

内容的提问来源于stack exchange,提问作者fbailey

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 14:30:16