llm-serving-default-deny admits only llm-client=true pods on 8080; without the label every dispatch timed out with 502.