I want to make comment that ZD requires as much licenses from Flexmaster, as APs it can manage (ZD license size), even if there is ust one AP. So Zd1106 uses 6 Flexmaster licences, not 1, and, for example, ZD1112 need 12 licenses.
So you can connect only ZD1106 to Flexmaster with evaluation license.
Also there is no much sense to manage ZD by Flexmaster in you case, as it is on your site and there is much more management features in ZD (and you need access to it anyway).
It is possible to install ZD in DMZ, open proper ports, and install APs on remote sites after Firewall, making address translation for neccessary ports, without VPN.
It will work (if delays on WAN are less than 50-100-msec), but it is not what you usually want to do. Vpn is more safe, but it adds delays, so requirement to WAN become even higher. If delays are too big, clients can time-out autentication and fail to connect.
Unfortunately, you can't expect to have centralized management and no communication between sites, it is unrealistic wish.
Some other vendors (Aruba, for example) which mainly use only tunneled connection for APs, support architecture when AP itself creates Ipsec tunnel to controller over Internet, which is really handy for remote brunches. But it's not required really often, or Ruckus would implemented it too.
Hope it helps,