It seems to work as expected (screenshots attached):
HTTPS-only is enabled by default and can be switched on/off in settings
HTTPS-only kicks in before HTTPS Everywhere (which we're keeping around for now): this users can provide feedback about our goal setup (no HTTPSE) but they're not locked in if they really need to switch back to HTTPS Everywhere.