We successfully deployed a Transit VPC in AWS using the Deployment guide, with auto-vpn provisioning for spoke VPC.
The question revolves around supporting more than TWO AWS accounts. The guide does not seem to cover this or we could not find a good reference.
OnPrem R80.10 MDS
AWS Main account holds Transit VPC gateways (used key and secret for auth)
AWS sub-account1 has spoke VPC (auth via STS auth and role)
We have four or five more sub-accounts we would like to add to the configuration leveraging the same Transit VPC. While we see we can possibly add more "controllers" using autoprov-cfg, it is not clear if this is the right approach and even if this would build VPN tunnels back to the main transit VPC hub.
Can someone help us determine the right next steps?