

I did this using a POE switch to both power the cameras and also have that entire switch on a VLAN. On my OPNSense, that vlan only has permission to send or recieve packets to home assistant which is on my main LAN. They have no other access to anything including each other on the camera vlan.
Other than the initial setup, the only interaction I have with the cameras is via home assistant. This allows them to be completely isolated and still have remote access as per usual with home assistant.
My HA is using the all in one VM setup on Proxmox. I would highly recommend HA installed as a VM rather than Docker due to the ease if installing plugins. After that the above setup will keep your IOT devices nicely isolated.
This is for traefik but might help to understand the process and change it for caddy (https://youtu.be/liV3c9m_OX8)
You should have
Service.local.domain.com
For local only services (Vaultwarden) and
Service.domain.com
For external things (immich)
I’m your router / Pihole locally, you setup the above URLs to point to the IP of caddy