My personal grief with HSTS is that it pretty much requires you to have installed and trusted one random 400 CA collection or the other. If you have uninstalled/distrusted most of them, no current browser will allow you to access a HSTS enabled domain using one of those distrusted CAs.
There is no override to skip and accept an encryption-only connection. Which is what I would have gotten with HSTS as well, because without independent verification the CA system is a lot, but not the mutually trusted third party it claims to be.