spring boot 应用需正确配置 /actuator/health 端点以支持外部监控,包括显式暴露端点、设 show-details: never 保障安全与简洁响应,并按 k8s、prometheus、zabbix 等需求适配调用方式,必要时通过自定义 healthindicator 扩展业务健康检查,同时注意网络隔离与探活性能。

Spring Boot 应用通过 `/actuator/health` 端点向外部监控系统暴露存活状态,关键不是“写代码”,而是**正确配置暴露方式、响应内容和访问路径**,让监控系统(如 Prometheus、Zabbix、K8s liveness probe)能稳定、准确地判断 UP/DOWN。
确保 health 端点已启用并可公开访问
Actuator 默认只暴露 /health 和 /info,但需显式配置才能被外部调用:
- 在
application.yml中添加以下配置:
management:
endpoints:
web:
exposure:
include: health # 明确包含 health,也可用 '*' 暴露全部(生产慎用)
endpoint:
health:
show-details: never # 外部监控通常只需 status,设为 never 更安全
若使用 application.properties,对应写为:
management.endpoints.web.exposure.include=health management.endpoint.health.show-details=never
注意:show-details: never 是推荐做法——避免敏感信息(如数据库连接详情)泄露,同时保证返回体极简({"status":"UP"}),利于监控系统快速解析。
适配不同监控系统的访问路径与协议
外部系统调用时,需确认 URL 格式和协议支持:
- Kubernetes liveness/readiness probe:直接访问
http://<pod-ip>:8080/actuator/health</pod-ip>,默认 HTTP GET,状态码 200 表示 UP - Prometheus + Spring Boot Actuator + Micrometer:无需额外配置 health 端点,Prometheus 本身不拉取 health,而是通过
/actuator/metrics或自定义指标判断;但健康状态常作为告警条件(例如结合up{job="myapp"} == 0) - Zabbix 或自定义脚本:建议用 curl 测试连通性 + 状态字段,例如:
curl -s http://localhost:8080/actuator/health | jq -r '.status',预期输出UP
必要时扩展健康检查逻辑
默认 health 只检查内置组件(如 diskSpace、ping)。若业务依赖 DB、Redis、第三方 API,需添加自定义 HealthIndicator:
- 新建一个类,实现
HealthIndicator接口 - 重写
health()方法,在其中执行轻量级探测(如 DB 连接SELECT 1、RedisPING) - 返回
Health.up().withDetail(...).build()或Health.down().withException(e).build()
这样,/actuator/health 的汇总结果会自动包含你的业务依赖状态,外部监控就能真正反映“应用是否可用”,而非仅“进程是否存活”。
安全与生产注意事项
对外暴露 health 端点需兼顾可用性与安全性:
- 不要开放
show-details: always给公网或不可信网络 - 若部署在网关后,建议由网关统一做 health 探活,后端服务 health 端点仅限内网访问
- 避免在 health 检查中执行耗时操作(如全表扫描、远程大文件下载),否则会导致探活超时失败
- Spring Boot 3 起,默认要求 Actuator 端点走独立管理端口(如
management.server.port=8081),更利于网络隔离
Java免费学习笔记:立即使用
解锁 Java 大师之旅:从入门到精通的终极指南











