Yes, you need either vSZ-D or SZ100-D (appliance version of vSZ-D using SZ100 hardware).
The vSZ-H controller only manages the AP's over an SSH tunnel to each AP. The vSZ-H never handles data traffic.
When configuring an SSID/WLAN to tunnel traffic the AP will actually have 2 tunnels - SSH (port 22) from AP to vSZ-H controller for configuration and management of the AP and then a Ruckus GRE (rgre) tunnel from AP to vSZ-D data plane. All client device traffic will be transparently tunneled to the vSZ-D and egress onto the network where the vSZ-D is located. If you configure WLAN to use VLAN tags (or Dynamic VLAN's) then the traffic will egress the vSZ-D tagged as configured so the Switch port connecting to the vSZ-D for data traffic needs to handle those VLAN's (tagged ingress). There is no need to have those VLAN's on the AP switch network
I hope this information is helpful.