We are planning to implement the AWS Patch Manager solution to patch our Windows and Linux EC2 instances. We will be setting up a WSUS/Satellite server in a shared account and, in the client account (within the same region and under the same OU), we will create a VPC endpoint and cross-account IAM role for connectivity. Do we need any VPC peering or Transit Gateway (TGW) for this solution to work, or will the VPC endpoint and cross-account IAM role be sufficient?..Basically looking for network connectivity options to achieve this solution.