For some reason Spring Security requires this pattern /actuator:actuatordashboard/** to be enabled for an admin role. I found out by enabling logging for spring security:
2018-04-18 09:03:22,272 TRACE grails.plugin.springsecurity.web.access.intercept.AnnotationFilterInvocationDefinition - Requested url: /actuator/dashboard
2018-04-18 09:03:22,273 TRACE grails.plugin.springsecurity.web.access.intercept.AnnotationFilterInvocationDefinition - Resolved full controller name for controller "actuatorDashboard" and namespace "actuator" as "actuator:actuatorDashboard"
2018-04-18 09:03:22,273 TRACE grails.plugin.springsecurity.web.access.intercept.AnnotationFilterInvocationDefinition - Final url is /actuator:actuatordashboard/index
For some reason Spring Security requires this pattern
/actuator:actuatordashboard/**
to be enabled for an admin role. I found out by enabling logging for spring security: