I agree that namespaces are pretty awesome functionality for this, but I've been burnt too many times by bespoke on-host configurations to put much stock in them. Plus they only work for the single host, and do nothing about the myriad of Internet of Trash devices.
I keep all my routing complexity contained to one (virtual) machine with extensive nftables rules, that functions as the house router. It has a table with each host and the network horizon it can see. Then I create a virtual machine for each activity that needs a separate horizon.
The one thing I'm missing is some way of securing the binding of hosts to addresses. Most switches/devices don't support ethernet authentication. I could do something like fine grained VLANs and keeping track of what is connected to what, but that seems like a huge pain in the ass.