If you are afraid of being ddosed which is very unlikely. Cloudflare has free ddos protection. You can put some but not all things behind their proxy.
Also instead of making things publicly available look in to using a VPN. Wireguard with “wireguard easy” makes this very simple.
VLANs do not make you network magically more secure. But when setup correctly can increase security a load if something has already penetrated the network. But also just to streamline a network and allow or deny some parts of the network.
Grapheneos with a dedicated profile with those China apps. Dont allow the profile to run in the background. Then just use tor with snowflake or one of the many methods of tor to bypass the firewall of China.