The two typical scenarios are;
1. You want to use the same IP space multiple times across different networks (i.e. multi-tenant)
2. You have a bunch of different networks that you really never want to ever be able to talk to each other (you can allow it through routes, etc. but by default this does not happen). Although you can achieve this with VLANs and ACLs, on a single routing table, rules can become a real pain in the ass to manage very quickly
You could use this for stuff like guest or IoT networks.
I'm currently wrangling with a good solution for selectively routing certain traffic via one of multiple VPN connections I have on my router.
I'll look into rdomains to see if this may help my situation if not only to make it more simple.
These days, I have removed this functionality from my router and moved it directly onto the server. I run the container haugene/transmission-openvpn which creates and maintains a VPN for transmission, but also has a proxy I can direct other containers to use. This has the benefit of keeping more of the prerequisites of these servers managed in the same docker compose file. It bakes in most of the popular public VPN configs, so you can enable them with a few ENV vars.
I admit it was a bit nerve-wracking knowing that I'd be losing my Internet while the transition was in progress. In the end, it only took 5-10 mins to install OpenBSD itself and another hour or so to configure dhcpd, pf, unbound. Granted, I spent a few hours reading man pages and documentation before hand in preparation.
Wireguard took me a little bit longer but it's actually part of the kernel since OpenBSD 6.8 which is great. I don't think pfsense supports this yet in-kernel, but I could be wrong.
I have yet setup anything further than this except for automated borg backup to rsync.net.
In the end I'm extremely happy with my decision to move despite knowing that my apu2d4 won't achieve gigabit speeds pfsense on the same hardware is capable of. My Internet is only 200mbps so it's not an issue and if I upgrade I'll probably get a protectli.
While I feel the pfsense project is great, I simply feel more confident using command-line instead of web UIs and also knowing precisely how the system is setup without the pfsense magic.
One caveat: A power cut during the relinking process that occurs during and after boot can wreck the filesystem. A UPS is advisable. Once the relinking finishes the filesystem is quite robust.