The first thing to note for the core switches (which will shape a lot of the rest of the answer) is the management IP (which is primary only used by the switch to talk to the cloud) must be in the subnet to the uplink to the Internet. The management network can not use the switch as the default gateway. The management network does not use the routing table in the switch.
The default gateway of the management interface must point to the IP address of your firewall/router providing Internet access.