Your entry on VLAN 10 (ip access-group 101 in) actually means that you allow all traffic from 192.168.10.0 to 192.168.10/20/30.0 into VLAN 10. Since this interface will never receive traffic from 192.168.10.0 since this is the subnet of VLAN 10, the statement has no effect.
You need a single entry on each VLAN interface except Vlan 10:
ip address 192.168.xx.1 255.255.255.0
ip access-group 101 out
access-list 101 permit ip any 192.168.10.0 0.0.0.255
This means only traffic to 192.168.10.0/24 can leave VLAN20. All other traffic is denied (implicit deny at the end of the ACL).
You do not need an ACL on VLAN 10 as VLAN can send and receive to all other VLANs.
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...