That is correct. In tunnel mode, the AP creates a GRE tunnel for each BSSID and tunnels all traffic back to the controller. This allows for central policy decisions, firewall processing, etc. We have about 10k simultaneous users across two Aruba 7240s each with two 10G uplinks to our distribution switches and we are nowhere near capacity.
We'd be perfectly fine with one 10G uplink but we use two for redundancy.