AWS EC2实例中Spring Boot服务外部无法访问求助
Hey there! I’ve run into this exact problem dozens of times when deploying Spring Boot apps to EC2— let’s break down the most common fixes step by step:
1. Confirm Your Spring Boot App is Listening on the Right Interface
By default, Spring Boot might bind only to localhost (127.0.0.1), which means it’s only accessible from inside the instance. To fix this:
- Open your
application.propertiesorapplication.ymlfile - Add or verify this line:
This tells the app to listen on all network interfaces of the EC2 instance. Also double-check yourserver.address=0.0.0.0server.portsetting (default is 8080) to make sure you’re using the correct port in external requests.
2. Update Your EC2 Security Group Rules
This is the #1 culprit 90% of the time. AWS Security Groups act as a firewall for your instance:
- Head to the EC2 Console, select your instance, and go to the Security tab
- Click the Security Group ID linked to your instance
- In the Inbound Rules tab, click Edit inbound rules
- Add a new rule:
- Type: Custom TCP
- Port range: Enter your Spring Boot port (e.g., 8080)
- Source: For testing, use
0.0.0.0/0(allows all IPs— remember to restrict this to your specific IP later for security!)
- Save the rules and try accessing the service again.
3. Check EC2 Subnet Network ACLs
Network ACLs are a secondary subnet-level firewall. By default, they allow all inbound/outbound traffic, but if someone modified them:
- Go to the VPC Console, find your instance’s subnet, and select its Network ACL
- Verify that inbound rules allow traffic on your Spring Boot port (e.g., 8080) from your source IP
- Ensure outbound rules allow ephemeral port traffic (usually 1024-65535) to send responses back to your local machine.
4. Verify the Instance’s Local Firewall
Linux instances often have a local firewall like ufw (Ubuntu) or iptables (RHEL/CentOS):
- For Ubuntu: Run
sudo ufw statusto check if the firewall is active. If it is, allow your port with:sudo ufw allow 8080/tcp - For RHEL/CentOS: Check
iptablesrules withsudo iptables -L. If you see a rule blocking your port, add an allow rule:sudo iptables -A INPUT -p tcp --dport 8080 -j ACCEPT sudo service iptables save
5. Make Sure You’re Using the Correct Public Address
Don’t use the EC2 instance’s private IP— you need its public IPv4 address or public DNS:
- Find this in the EC2 Console’s instance details under Public IPv4 address or Public IPv4 DNS
- Test with your local machine’s curl:
curl http://<your-ec2-public-ip>:8080/hello
Quick Final Check
If all else fails, confirm your Spring Boot app is actually running on the instance. SSH into the instance and run:
ps aux | grep java
You should see your Spring Boot process listed. If not, restart the app and check for startup errors in the logs.
内容的提问来源于stack exchange,提问作者Deepak Srivathsan

