Set your expectations: networking is complex and the configuration you’re hoping for is particularly complex. It sounds to me like you’re looking for a split-horizon configuration where local traffic stays local but internet traffic is routed over VPN. But also you want that configuration only for specific apps.
It’s not the *arr programs that are tricky, it’s that any service you try to configure this way will be some of the hardest sysadmin work.



That looks pretty decent. Could mostly support the OP’s use-case, but also could allow sites to trade a cookie for payment, for semi-anonymous pay-for-access.