You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot配置:部分Actuator端点禁用HTTPS其余强制HTTPS

解决方案:Spring Boot 部分端点HTTP、其余HTTPS配置

针对你遇到的问题——希望让/actuator/info、/actuator/prometheus走非安全的HTTP协议,其余端点强制HTTPS,而之前的配置未生效的情况,我整理了两种可行的方案,其中第一种更推荐(隔离性更好,维护更简单):

方案一:使用独立的管理端点端口(推荐)

这种方式会让Spring Boot的Actuator端点运行在单独的HTTP端口上,主应用则保持HTTPS端口,两者完全隔离,避免冲突。

1. 调整配置文件(application.properties/application.yml)

# 主应用HTTPS配置
server.port=443
server.ssl.enabled=true
server.ssl.key-store=classpath:keystore.jks
server.ssl.key-store-password=xxxx

# 管理端点独立配置(HTTP协议)
management.server.port=8762
management.server.ssl.enabled=false
# 暴露需要的端点(按需调整)
management.endpoints.web.exposure.include=info,prometheus
# 保持端点基础路径和主应用一致(默认就是/actuator,可省略)
management.endpoints.web.base-path=/actuator

2. 分离主应用与管理端点的安全配置

之前你把两者的安全规则混在一起,导致主应用的HTTPS强制规则影响了管理端点。需要分别配置:

主应用安全配置(强制HTTPS)

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@Configuration
@EnableWebSecurity
public class MainAppSecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        // 主应用所有请求强制使用HTTPS
        http.requiresChannel().anyRequest().requiresSecure();
        
        // 主应用其他安全规则(如认证、授权)按需添加
        http.csrf().disable()
            .authorizeRequests()
            .anyRequest().authenticated();
    }
}

管理端点安全配置(允许HTTP+IP限制)

用@ManagementContextConfiguration标记,专门管理Actuator的安全规则:

import org.springframework.boot.actuate.autoconfigure.security.servlet.ManagementContextConfiguration;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@ManagementContextConfiguration
public class ActuatorSecurityConfig extends WebSecurityConfigurerAdapter {
    private final String ipRangeMain;
    private final String ipRangeSecond;

    // 注入你的IP范围配置
    public ActuatorSecurityConfig(String ipRangeMain, String ipRangeSecond) {
        this.ipRangeMain = ipRangeMain;
        this.ipRangeSecond = ipRangeSecond;
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        // 允许HTTP访问(因为management.server已禁用SSL),同时限制IP
        http.csrf().disable()
            .authorizeRequests()
            .antMatchers("/actuator/**")
            .access("hasIpAddress('" + ipRangeMain + "') or hasIpAddress('" + ipRangeSecond + "')")
            .anyRequest().authenticated();
    }
}

3. 验证访问

负载均衡器和监控系统需要通过HTTP协议+8762端口访问Actuator端点:

  • http://your-server:8762/actuator/info
  • http://your-server:8762/actuator/prometheus

主应用的其他路径则必须通过HTTPS访问(如https://your-server/api/**)。


方案二:同一端口下区分HTTP/HTTPS(不推荐,复杂度高)

如果必须让所有端点共享同一个端口,需要让Tomcat同时监听HTTP和HTTPS两个端口,再通过Spring Security的requiresChannel规则控制路径协议。

1. 配置文件

# HTTPS主端口
server.port=443
server.ssl.enabled=true
server.ssl.key-store=classpath:keystore.jks
server.ssl.key-store-password=xxxx

# 额外的HTTP端口
server.http.port=8080

2. 自定义Tomcat连接器,添加HTTP端口监听

import org.springframework.boot.web.embedded.tomcat.TomcatServletWebServerFactory;
import org.springframework.boot.web.server.WebServerFactoryCustomizer;
import org.springframework.stereotype.Component;
import org.apache.catalina.connector.Connector;

@Component
public class TomcatHttpConnectorConfig implements WebServerFactoryCustomizer<TomcatServletWebServerFactory> {
    private final Integer httpPort;

    public TomcatHttpConnectorConfig(@Value("${server.http.port}") Integer httpPort) {
        this.httpPort = httpPort;
    }

    @Override
    public void customize(TomcatServletWebServerFactory factory) {
        // 添加HTTP连接器
        factory.addAdditionalTomcatConnectors(createHttpConnector());
    }

    private Connector createHttpConnector() {
        Connector connector = new Connector(TomcatServletWebServerFactory.DEFAULT_PROTOCOL);
        connector.setPort(httpPort);
        connector.setScheme("http");
        connector.setSecure(false);
        return connector;
    }
}

3. 安全配置

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@Configuration
@EnableWebSecurity
public class GlobalSecurityConfig extends WebSecurityConfigurerAdapter {
    private final String ipRangeMain;
    private final String ipRangeSecond;

    public GlobalSecurityConfig(String ipRangeMain, String ipRangeSecond) {
        this.ipRangeMain = ipRangeMain;
        this.ipRangeSecond = ipRangeSecond;
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        // 指定Actuator的两个端点允许HTTP,其余所有请求强制HTTPS
        http.requiresChannel()
            .antMatchers("/actuator/info", "/actuator/prometheus").requiresInsecure()
            .anyRequest().requiresSecure();

        // IP限制规则
        http.csrf().disable()
            .authorizeRequests()
            .antMatchers("/actuator/**")
            .access("hasIpAddress('" + ipRangeMain + "') or hasIpAddress('" + ipRangeSecond + "')")
            .anyRequest().authenticated();
    }
}

你之前配置失效的原因

  1. 端口访问错误:你设置了management.server.port=8762但仍用主应用的HTTPS端口访问Actuator,导致触发TLS要求报错——主应用端口只支持HTTPS,独立的管理端点必须用8762端口访问。
  2. 安全配置混淆:在主应用的HttpSecurity中配置/actuator走HTTP,和主应用的HTTPS强制规则冲突,必须将管理端点的安全配置单独分离到@ManagementContextConfiguration中。

内容的提问来源于stack exchange,提问作者user3611168

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:01:34