Even on Cloudflare, when you enable HSTS, it gives you a warning.
Generally, I have researched and learnt that HSTS is important to get secure by forcing all communications to happen via HTTPS.
So, why is everyone still giving so many warnings? Do orgs have a lot of HTTP setup for let's say their APIs or legacy codes still supporting HTTP?
Doesn't the article give a good explanation of why it recommends caution?