Both are just abstractions over primatives and services find in the underlying operating system.
Moving to just native PF or nftables and running your firewall like a server has been on of my best moves. You will learn a tone more, have a lot more flexibility and overall I think it’s a much better experience.
I am a traditional network engineer as well (learned Juno’s/Cisco/etc). Ansible is a good way to do “commits” and config management.


Sorry. Fast typing on a phone who’s autocomplete doesnt know these terms. Yes