I don't think AWS wants to imply in any way that you need to be on a VPN to interact with AWS resources. It's not the direction they are going (Zero trust / RBA https://aws.amazon.com/security/zero-trust/).
Zero trust doesn’t mean no VPNs, it means not just VPNs. In other words you can put your control plane behind ACLs (and you should!) but you should still require strong auth from the private network.