Maybe try this:
readonlyrest:
enabled: true
response_if_req_forbidden: <h1>Forbidden</h1>
access_control_rules:
- name: "ELB Check"
# actions: ["cluster:monitor/main"] <--- optionally enable this, once the headers work.
headers: ["User-Agent:ELB-HealthChecker/2.0"]
verbosity: info