Yeah try reconfiguring a remote firewall with breaking changes and therefore new behavior without OOB access. Don’t make a single mistake or you could be traveling hours/days.
Good luck with your “reading” now that the breaking changes have made hundreds of online tutorials, articles, books etc that would guide you obsolete and wrong.
So if you skip testing, and you skip reading the upgrade guide, skip editing pf.conf to adapt to some upcoming change and reboot into the upgraded OS version, you will still get a default pf that allows you to ssh in and fix it.
But sure, one can still shoot oneself in the foot if you aim for it.