We're facing the same problem.
As far as I saw now, we will be able to add a new VLAN on every site (around 250!) and add it to the VPN via API.
But I noticed I will have to change the per-port configuration for 3 ports on every of the 250 sites, means 750 times... Isn't there a better solution on this?
The API still is very incomplete. For example the DHCP settings of the MX are also totally missing, so we need to update this every time for every network (yes, using templates, but reserved DHCP ranges could be scripted, but not configured properly in a template).