You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何不通过application.properties暴露Spring Boot Actuator端点

无配置文件访问权限时Spring Boot 2.5.8编码暴露Actuator端点方案

常规通过配置文件实现的方式非常简单,只需在application.properties中添加如下配置即可:

management.endpoints.web.exposure.include=*

当你没有该配置文件的修改/访问权限时,可以通过以下两种纯编码方案实现相同效果,不需要改动任何配置文件:


方案1:启动类注入默认属性(改动最小)

这是最简便的实现方式,不需要新增额外类,直接在Spring Boot启动入口设置默认属性即可,效果和写在配置文件中完全一致:

@SpringBootApplication
public class Application {
    public static void main(String[] args) {
        SpringApplication application = new SpringApplication(Application.class);
        Properties defaultProps = new Properties();
        // 配置暴露所有web端点
        defaultProps.setProperty("management.endpoints.web.exposure.include", "*");
        // 如果需要开启默认关闭的端点(比如shutdown端点),可以追加对应配置
        // defaultProps.setProperty("management.endpoint.shutdown.enabled", "true");
        application.setDefaultProperties(defaultProps);
        application.run(args);
    }
}

这个方案适合可以直接修改应用启动类的场景,配置优先级符合Spring Boot标准规则,不会过度覆盖其他高优先级配置。


方案2:自定义EnvironmentPostProcessor(适配无法修改启动类的场景)

如果连启动类都没有修改权限,可以通过Spring Boot的环境扩展点,在容器初始化早期注入配置,优先级更高,不会被其他业务配置覆盖:

  1. 编写自定义环境处理器:
public class CustomActuatorConfigProcessor implements EnvironmentPostProcessor {
    @Override
    public void postProcessEnvironment(ConfigurableEnvironment environment, SpringApplication application) {
        Properties actuatorProps = new Properties();
        actuatorProps.setProperty("management.endpoints.web.exposure.include", "*");
        // 将自定义配置加入最高优先级属性源
        environment.getPropertySources().addFirst(
            new PropertiesPropertySource("customActuatorConfig", actuatorProps)
        );
    }
}
  1. 注册处理器:在项目的resources/META-INF/spring.factories文件中添加如下配置(文件不存在则直接新建):
org.springframework.boot.env.EnvironmentPostProcessor=com.youpackage.path.CustomActuatorConfigProcessor

额外注意

如果你的项目集成了Spring Security,还需要在安全配置中把Actuator的访问路径加入放行规则,否则端点就算成功暴露也会被权限拦截,参考配置如下:

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.authorizeRequests()
                .antMatchers("/actuator/**").permitAll()
                // 其余业务接口的权限配置按原有逻辑保留
                .anyRequest().authenticated()
                .and().csrf().disable();
    }
}

内容的提问来源于stack exchange,提问作者Igor_M

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.30 00:31:02