You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Actuator无法暴露求助:多种配置尝试后仍无效

解决Spring Boot Actuator端点无法访问问题

问题场景

使用Spring Boot 2.6.6版本,配置Actuator仅暴露health端点,日志显示Exposing 1 endpoint(s) beneath base path '/actuator',但无法访问该端点,已通过Spring Security限制仅ADMIN角色可访问。

现有配置

build.gradle

implementation 'org.springframework.boot:spring-boot-starter-web'
implementation 'org.springframework.boot:spring-boot-starter-security'
implementation 'org.springframework.boot:spring-boot-starter-actuator'

application.yml

management:
  endpoint:
    health:
      show-details: always
  endpoints:
    web:
      exposure:
        include: health

Spring Security配置

@Configuration
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {

@Override
protected void configure(HttpSecurity http) throws Exception {

    http
            .authorizeRequests()
            .antMatchers("/actuator/**").hasAnyAuthority("ADMIN")
            .anyRequest().permitAll()
            .and()
            .formLogin()
            .loginPage("/login")
            .permitAll()
            .and()
            .logout()
            .permitAll();
    http.csrf().disable().headers().frameOptions().disable();
}
}

排查与解决方案

1. 确认端点访问路径

日志已明确暴露1个端点,说明/actuator/health是存在的,需确保访问路径正确:

  • 正确访问路径为 http://<服务地址>:<端口>/actuator/health,直接访问/actuator不会返回端点列表(默认未开启端点列表暴露)。

2. 验证用户权限配置

Security规则要求访问者拥有ADMIN权限,需确保登录用户确实具备该权限:

  • 若使用内存用户,需在Security配置中添加带权限的用户:
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
    auth.inMemoryAuthentication()
        .withUser("admin")
        .password("{noop}admin123") // {noop}表示明文密码,生产环境请使用BCrypt等加密方式
        .authorities("ADMIN");
}
  • 若使用数据库用户,确认用户表中权限字段值为ADMIN(权限匹配区分大小写)。

3. 调整Security规则优先级(可选)

确保Actuator的权限规则优先于其他规则,可显式指定具体端点路径:

http.authorizeRequests()
    .antMatchers("/actuator/health").hasAuthority("ADMIN")
    .anyRequest().permitAll()
    // 保留原有的formLogin、logout等配置

4. 排查自定义拦截器/过滤器干扰

若项目中有自定义拦截器或过滤器,确认它们未拦截/actuator/**路径,可临时关闭自定义组件测试是否能正常访问。

5. 开启日志排查细节

在application.yml中添加日志配置,查看端点请求的完整处理流程:

logging:
  level:
    org.springframework.boot.actuate: DEBUG
    org.springframework.security: DEBUG

内容的提问来源于stack exchange,提问作者Saranya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.26 07:45:33