If your traffic is being broken out at the AP's, all you need on the switch port facing the controller is the vlan you have for AP management
If however you are tunneling traffic back to the controller, and the traffic is being broken out at the controller, the switch port facing the controller needs have the necessary vlans you have provisioned on your SSID's and the ports facing the AP's only need the vlans for AP management