VLAN and a properly configured firewall.
I have several VLANs at home. There's THINGS (802.1Q tag: 15) for the usual IoT stuff and there's SEWER (Tag: 16) for stuff that scares me even more. SERVERS, LAN, MANAGEMENT, PHONES and a few others are obvious, along with DMZ, DMZ2 and more. There's also a ROFLCOPTER VLAN (tag: 22). That's for the wife and her laptop. Her laptop sports Arch Linux and has done for about eight years now.
Anyone who wants to improve their sysadmin fu should try to please their SO first (lol, fnar). If you want to play with IoT and Home Automation etc then get it approved by the Boss. Think you can do Internets? Ask the Boss. Want to mess around with web proxies and MitM? Get the Boss to test the end experience.