You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 1.5.6迁移至2.0.0后Actuator配置适配咨询

Spring Boot 2.0.0 Actuator 配置适配方案(匹配1.5.6原有逻辑)

刚升级完Spring Boot 2.0的Actuator确实会懵,官方做了大幅重构,很多配置项改了名甚至换了逻辑。我帮你把原有1.5.6的配置完全映射到2.0.0,恢复你原来的访问控制规则:

一、核心配置文件替换(application.yml)

把原来的Actuator配置替换成下面的内容,每一项都对应你原来的需求:

management:
  endpoints:
    web:
      base-path: /actuator  # 完全替代1.5.x的management.context-path,保持端点根路径不变
      exposure:
        include: '*'  # 暴露所有端点,对应原来的endpoints.enabled: true(2.0默认部分敏感端点不暴露)
  endpoint:
    security:
      roles: ADMIN  # 所有端点要求ADMIN角色,对应原来的management.security.roles: ADMIN
    # 可选:如果需要健康端点显示详细信息,加上下面这行
    health:
      show-details: always
    # 可选:如果需要启用shutdown端点(默认禁用),加上下面这行
    shutdown:
      enabled: true

二、Spring Security 适配配置

2.0版本废弃了management.security.enabled,Actuator的访问权限完全交给Spring Security控制。你需要调整你的Security配置类,确保拦截Actuator路径并验证ADMIN角色:

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .authorizeRequests()
                // 拦截所有Actuator子路径,要求ADMIN角色
                .antMatchers("/actuator/**").hasRole("ADMIN")
                // 其他路径的权限规则根据你的业务需求调整
                .anyRequest().permitAll()
                .and()
            // 保持你原来的登录方式(比如表单登录)
            .formLogin()
                .and()
            .logout()
                .and()
            // Actuator的POST/PUT等请求通常不需要CSRF保护,按需开启
            .csrf().ignoringAntMatchers("/actuator/**");
    }
}

三、关键变化说明

  • 原来的management.context-path → 现在的management.endpoints.web.base-path:作用完全一致,只是命名更规范了
  • 原来的endpoints.enabled: true → 现在的management.endpoints.web.exposure.include: '*':2.0默认只暴露health和info端点,必须显式指定暴露所有端点才能和1.5.x行为一致
  • 原来的management.security.roles → 现在的management.endpoint.security.roles:全局指定所有端点需要的角色,也可以单独给某个端点配置角色(比如management.endpoint.health.roles: USER)
  • 权限控制逻辑:和1.5.x完全一致,只有已登录且拥有ADMIN角色的用户才能访问任何Actuator端点

这样配置完之后,你的Actuator就能和升级前一样正常工作了~

内容的提问来源于stack exchange,提问作者JONKI

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:30:07