Our problem is determining the correct default gateway for our web servers. All IP addresses are in the same subnet (VIP, interfaces, and servers). Should the servers default gateway be the L3 switch, or the CSS?
You understood this one perfectly!
You can still have a one-arm setup and not use groups to NAT the client's IP address, but you must make sure that the servers send the reply back to the CSS, and by experience I can tell you it is really difficult to control the routing on a subnet when two or more devices are able to make routing decisions.
The best way to go, and the one that would avoid you several head aches, is to configure an inline setup.