To counter the avalanche of retries on different layers, I have also seen a custom header being added to all requests that are retries. Upon receiving a request with this header, the microservice would turn off its own retry logic for this request.
Having clients suspend retries altogether allows the service to come back up. Manual retries triggered from user action would be fresh requests.