"no ip routing" should do it and just work. I'd also turn off the "ip forward-protocol" and just go to a straight "no ip firewall". In essence, no-out all IP statements other than the one where you apply an address to the management VLAN and "ip default-gateway" pointing to the upstream router for management.
The only need for any ip configuration on a layer-2 switch is for the ability to connect to it and manage it via SSH / telnet / http(s).
I went ahead and flagged the "Correct Answer" on this post to make it more visible and help other members of the community find solutions more easily. If you don't feel like the answer I marked was correct, feel free to come back to this post and unmark it, and select another in its place, with the applicable buttons.