Linux Jails (containers/vms) with Incus

that is simple. I want to reach full seggragatio between sets of apps, some apps are private, some are shared. They live in different networks.
I want to avoid, that if an app is compromissed all other apps and the host are at risk.

My layout it explained in more details over here: Network Configuration for New Instances in TrueNAS SCALE 25.04 Fangtooth - #15 by PackElend