You just mentioned one of the benefits of having a controller as in no need to extend VLANs to the AP and tunneling all the traffic. If you want to replicate the same traffic tunneling or require ClearPass access from an internet location, you might need a VPN, and using a controller/gateway for that is (one way of) how to do it. Are these RAPs connected to the internet or to your internal network?
From the information you provide about your environment, requirements, and architecture, it is hard to tell what is simple or what is hard to achieve. There are multiple options and some may match better than others.
As with moving from controller-based to Instant AP your architecture significantly changes, I would advise you to revisit or even recreate your design based on the requirements that may have changed over the years. You may be good at moving from centralized to decentralized, or you may the re-think solutions like RAP. With this, it is important to overlook the bigger picture, not just the issues you run into, as the risk is that you get an ugly bandaid point-solution.
Your Aruba partner or possible Aruba SE should be able to discuss the different Aruba architectures mapped on your environment and requirements.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
------------------------------