Spring Boot Actuator:配置禁用后仍无法屏蔽/health端点的问题
Hey there! Let's dig into why your /health endpoint is still accessible even after setting endpoints.enabled=false and endpoints.health.enabled=false in your application.properties. This usually boils down to Spring Boot version differences or unexpected configuration overrides—here's how to fix it:
1. Check Your Spring Boot Version (Critical!)
The configuration keys for Actuator endpoints changed drastically between Spring Boot 1.x and 2.x:
- If you're on Spring Boot 2.x+: The old
endpoints.*properties are deprecated and won't work. You need to use themanagement.*prefix instead:- To block only the
/healthendpoint:management.endpoints.web.exposure.exclude=health management.health.enabled=false - To block all Actuator endpoints entirely:
management.endpoints.web.exposure.include=none management.health.enabled=false
- To block only the
- If you're on Spring Boot 1.x: Your original properties should work, but double-check if any other configuration is overriding them (see point 2 below).
2. Look for Configuration Overrides
- Check if you have profile-specific property files (like
application-dev.propertiesorapplication-prod.properties) that might be overriding the mainapplication.propertiessettings. - Verify if any custom
@Configurationclasses are manually enabling the health endpoint—for example, using@Endpoint(id = "health")or@WebEndpoint(id = "health")annotations that bypass the property settings.
3. Confirm the /health Endpoint Origin
Is the accessible /health actually the Actuator endpoint? Sometimes projects define custom /health endpoints outside of Spring Boot Actuator. To confirm:
- Check your dependencies: If you don't have
spring-boot-starter-actuatorin yourpom.xmlorbuild.gradle, the endpoint is likely custom—you'll need to disable it in your controller/endpoint code.
4. Verify Configuration Loading
To ensure your properties are being picked up correctly:
- For Spring Boot 2.x, access the
/actuator/envendpoint (if it's enabled) and search for your health-related properties to see if they're active. - Check your application startup logs for lines mentioning "health endpoint" or property loading—this can reveal if your settings are being ignored or overridden.
5. Clean and Rebuild
Sometimes stale build artifacts can cause configuration issues. Try cleaning your project (e.g., mvn clean or ./gradlew clean) and rebuilding it before restarting the application.
内容的提问来源于stack exchange,提问作者tindu edward

