Configuration thoughts and questions

‘’’
Few things I’m considering/debating/wondering,

I may add a pair of cameras in the near future and I want to store footage locally, not sure if I want to go generic security system or if there are some good services for this.

Is there any security consideration for using a vlan on your primary lan? In this setup I want to isolate the wireless traffic from the physical traffic, all of the TVs and phones need access to each other but next to never do the pcs need to access the phones/tvs or vice versa, I feel like I could probably just setup the vlan for work and another for wifi

For the vlan setup, would I do this in the pi4 and then also in the Edgerouter?

For the Edgerouter, what considerations do I need to make at the switch level, I want it to act as a clan aware switch, I only want it to move traffic and send the vlans to the right place, the pi4 is my firewall and router in this setup

Ideas for services to run on my server, I don’t use a ton of home media, we use a ton of streaming services,

Would It be worth running an additional vm for pihole? OpenWRT has a lot of the features that pihole has…

I am aiming to close nearly every hole in the setup, I have ssh closed to local only, my ap does not have a web accessible interface, I am not exposing any ports for any of my services.

I’m aiming for a balance of performance/security
‘’’