Spring Boot配置:部分Actuator端点禁用HTTPS其余强制HTTPS
解决方案:Spring Boot 部分端点HTTP、其余HTTPS配置
针对你遇到的问题——希望让/actuator/info、/actuator/prometheus走非安全的HTTP协议,其余端点强制HTTPS,而之前的配置未生效的情况,我整理了两种可行的方案,其中第一种更推荐(隔离性更好,维护更简单):
方案一:使用独立的管理端点端口(推荐)
这种方式会让Spring Boot的Actuator端点运行在单独的HTTP端口上,主应用则保持HTTPS端口,两者完全隔离,避免冲突。
1. 调整配置文件(application.properties/application.yml)
# 主应用HTTPS配置 server.port=443 server.ssl.enabled=true server.ssl.key-store=classpath:keystore.jks server.ssl.key-store-password=xxxx # 管理端点独立配置(HTTP协议) management.server.port=8762 management.server.ssl.enabled=false # 暴露需要的端点(按需调整) management.endpoints.web.exposure.include=info,prometheus # 保持端点基础路径和主应用一致(默认就是/actuator,可省略) management.endpoints.web.base-path=/actuator
2. 分离主应用与管理端点的安全配置
之前你把两者的安全规则混在一起,导致主应用的HTTPS强制规则影响了管理端点。需要分别配置:
主应用安全配置(强制HTTPS)
import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @Configuration @EnableWebSecurity public class MainAppSecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { // 主应用所有请求强制使用HTTPS http.requiresChannel().anyRequest().requiresSecure(); // 主应用其他安全规则(如认证、授权)按需添加 http.csrf().disable() .authorizeRequests() .anyRequest().authenticated(); } }
管理端点安全配置(允许HTTP+IP限制)
用@ManagementContextConfiguration标记,专门管理Actuator的安全规则:
import org.springframework.boot.actuate.autoconfigure.security.servlet.ManagementContextConfiguration; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @ManagementContextConfiguration public class ActuatorSecurityConfig extends WebSecurityConfigurerAdapter { private final String ipRangeMain; private final String ipRangeSecond; // 注入你的IP范围配置 public ActuatorSecurityConfig(String ipRangeMain, String ipRangeSecond) { this.ipRangeMain = ipRangeMain; this.ipRangeSecond = ipRangeSecond; } @Override protected void configure(HttpSecurity http) throws Exception { // 允许HTTP访问(因为management.server已禁用SSL),同时限制IP http.csrf().disable() .authorizeRequests() .antMatchers("/actuator/**") .access("hasIpAddress('" + ipRangeMain + "') or hasIpAddress('" + ipRangeSecond + "')") .anyRequest().authenticated(); } }
3. 验证访问
负载均衡器和监控系统需要通过HTTP协议+8762端口访问Actuator端点:
http://your-server:8762/actuator/infohttp://your-server:8762/actuator/prometheus
主应用的其他路径则必须通过HTTPS访问(如https://your-server/api/**)。
方案二:同一端口下区分HTTP/HTTPS(不推荐,复杂度高)
如果必须让所有端点共享同一个端口,需要让Tomcat同时监听HTTP和HTTPS两个端口,再通过Spring Security的requiresChannel规则控制路径协议。
1. 配置文件
# HTTPS主端口 server.port=443 server.ssl.enabled=true server.ssl.key-store=classpath:keystore.jks server.ssl.key-store-password=xxxx # 额外的HTTP端口 server.http.port=8080
2. 自定义Tomcat连接器,添加HTTP端口监听
import org.springframework.boot.web.embedded.tomcat.TomcatServletWebServerFactory; import org.springframework.boot.web.server.WebServerFactoryCustomizer; import org.springframework.stereotype.Component; import org.apache.catalina.connector.Connector; @Component public class TomcatHttpConnectorConfig implements WebServerFactoryCustomizer<TomcatServletWebServerFactory> { private final Integer httpPort; public TomcatHttpConnectorConfig(@Value("${server.http.port}") Integer httpPort) { this.httpPort = httpPort; } @Override public void customize(TomcatServletWebServerFactory factory) { // 添加HTTP连接器 factory.addAdditionalTomcatConnectors(createHttpConnector()); } private Connector createHttpConnector() { Connector connector = new Connector(TomcatServletWebServerFactory.DEFAULT_PROTOCOL); connector.setPort(httpPort); connector.setScheme("http"); connector.setSecure(false); return connector; } }
3. 安全配置
import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @Configuration @EnableWebSecurity public class GlobalSecurityConfig extends WebSecurityConfigurerAdapter { private final String ipRangeMain; private final String ipRangeSecond; public GlobalSecurityConfig(String ipRangeMain, String ipRangeSecond) { this.ipRangeMain = ipRangeMain; this.ipRangeSecond = ipRangeSecond; } @Override protected void configure(HttpSecurity http) throws Exception { // 指定Actuator的两个端点允许HTTP,其余所有请求强制HTTPS http.requiresChannel() .antMatchers("/actuator/info", "/actuator/prometheus").requiresInsecure() .anyRequest().requiresSecure(); // IP限制规则 http.csrf().disable() .authorizeRequests() .antMatchers("/actuator/**") .access("hasIpAddress('" + ipRangeMain + "') or hasIpAddress('" + ipRangeSecond + "')") .anyRequest().authenticated(); } }
你之前配置失效的原因
- 端口访问错误:你设置了
management.server.port=8762但仍用主应用的HTTPS端口访问Actuator,导致触发TLS要求报错——主应用端口只支持HTTPS,独立的管理端点必须用8762端口访问。 - 安全配置混淆:在主应用的
HttpSecurity中配置/actuator走HTTP,和主应用的HTTPS强制规则冲突,必须将管理端点的安全配置单独分离到@ManagementContextConfiguration中。
内容的提问来源于stack exchange,提问作者user3611168
相关产品推荐
相关产品推荐

