

I run a split environment. Main router is set up ‘normally’ with what other people in the house and visitors would expect.
Attached to that is a Pi running an OpenVPN client and a hostapd server that broadcasts a separate WiFi network. Iptables on the Pi are set to only ever allow Internet traffic through the VPN as a killswitch (except for OpenVPN, to prevent a chicken-egg situation), and any wifi clients connected via hostapd are routed through it.
A script occasionally changes the VPN endpoint to keep it interesting. This Pi also acts as a qbitorrent client that stores downloads to a local NAS.
It’s a best of both setup that has been stable for over 5 years now.
I have settled on Mullvad, for their simplicity and payment methods.