SpringBoot是否支持可选加载端点?批量模式下能否禁用所有端点?
Hey there! Let's tackle your two Spring Boot questions clearly and practically:
1. Does Spring Boot support optionally loading endpoints?
Absolutely! Spring Boot gives you several flexible ways to control whether endpoints are loaded or exposed, depending on your needs:
Conditional bean creation for custom endpoints: Use annotations like
@ConditionalOnPropertyor@ConditionalOnProfileto only instantiate endpoint beans when specific conditions are met. For example:@Endpoint(id = "custom-status") @ConditionalOnProperty(name = "app.custom.endpoint.enabled", havingValue = "true", matchIfMissing = false) public class CustomStatusEndpoint { // Your endpoint logic here }This way, the endpoint only exists if
app.custom.endpoint.enabled=trueis set in your configuration.Fine-tune Actuator endpoint exposure: If you're using Spring Boot Actuator, you can control which endpoints are exposed via properties:
- To expose only specific endpoints:
management.endpoints.web.exposure.include=health,info - To hide all endpoints:
management.endpoints.web.exposure.exclude=* - You can also disable all Actuator endpoints by default with
management.endpoints.enabled-by-default=false, then enable only the ones you need individually.
- To expose only specific endpoints:
2. Can we run our web app in 'batch' mode without exposing any endpoints for security?
Yes, you absolutely can achieve this—here are a few robust approaches based on your use case:
Option 1: Disable the web container entirely (most secure for pure batch)
If your batch mode doesn't require any web functionality at all, set the web application type to non-web. This prevents Tomcat/Jetty/Undertow from starting up entirely, so there's no HTTP server to expose endpoints on. Add this to your application-batch.properties:
spring.main.web-application-type=NONE
Option 2: Disable all Actuator and custom endpoints
If you still need the web container but want no endpoints exposed:
- For Actuator: Disable all endpoints by default and block any exposure:
management.endpoints.enabled-by-default=false management.endpoints.web.exposure.exclude=* - For custom endpoints: Use
@ConditionalOnProfile(not = "batch")on your endpoint classes, so they're not loaded when thebatchprofile is active:@Endpoint(id = "batch-monitor") @ConditionalOnProfile(not = "batch") public class BatchMonitorEndpoint { // Endpoint logic }
Option 3: Block all endpoint access via security rules
If you can't disable endpoints entirely, use Spring Security to block all access to endpoint paths in batch mode. For example:
@Configuration @Profile("batch") public class BatchSecurityConfig { @Bean public SecurityFilterChain batchSecurityFilterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests(auth -> auth .requestMatchers("/actuator/**", "/custom-endpoints/**").denyAll() .anyRequest().denyAll() ); return http.build(); } }
This ensures even if endpoints exist, no one can access them when running in batch mode.
内容的提问来源于stack exchange,提问作者Chris Milburn

