Congrats! No need for the experimental version I referenced. Now, the official version of zrok supports setting the Caddy port to something other than 443. It'll use 443 if you don't set it.
You must publish these secure ports mentioned in the guide. These are "secure ports" because they terminate TLS, and so they must be "open" a.k.a. "published" to the web.
ZITI_CTRL_ADVERTISED_PORT - Ziti controller's TLS server
ZITI_ROUTER_PORT - Ziti router's TLS server
CADDY_HTTPS_PORT or TRAEFIK_HTTPS_PORT - a proxy for the insecure ports (default 443)
You should not publish these insecure ports. zrok controller and zrok frontend listen on these ports locally, and they must be published with a TLS proxy like Caddy or Traefik for security.