Device recommendation + 400Mbps/1Gbps question

That is the whole purpose (at least one of the major ones) of any (smart-)managed switch, so yes - you can assign VLANs freely among the physical switch ports as needed/ desired.

Even if running OpenWrt on your managed switch isn't on your mind right now, I'd suggest looking at

and
https://svanheule.net/switches/models
to retain the option of doing so.

400 MBit/s should be doable, 1 GBit/s might be slightly more on the fence - depending on your additional requirements (e.g. VPN, SQM, PPPoE, etc.).