Hello Marco Eichstetter,
this is doable and very often implemented in a Central office and branch office scenario. I am assuming that Berlin is central office where ZD and AD will reside. In this deployment once deployed same configuration at Berlin office will reflect in Munich office and same AD credential can be used at branch office.
Make sure that latency of VPN connection is less than 100ms.
Since both sites are connected via VPN. let the AP(s) join via layer 3 through the VPN. refer to following URL on how to do this -
https://support.ruckuswireless.com/an...
You can add the 2nd ZD at Munich office for redundancy then both Zd's can be configured in a such way that AP's in case of failure of ZD or VPN are forced to contact alternate ZD which could be on same site or remote site depending on nature of fault.
Please remember that during redundancy AP's will work only with one ZD i.e active or primary.
Also make sure that LWAPP ports are opened on remote site router & firewall, latency is less than 100 ms and keep an eye on MTU of the VPN link.
Hope this helps.