

Same config, I have been using my 8a with graphene since Jan. Works great.
I actually put Google Play and the few apps that use that in the Private Space and just use clean apps in my owner profile. There are a lot of different ways to divide up apps between Owner Profile, Private Space, the 31 separate user profiles, and work profiles.
As for app sources I use mostly Graphene, FDroid, Aurora, and Obtainium stores and tools. I only use Play Store directly in my Private Space. There are pros and cons of course.
Whatever https://www.privacyguides.org/ recommends. I am not a big VPN user. I care more about using good apps and prefering the web browser over apps and configuring that.