Is this AWS architecture correct for OpenZiti ZTNA?

Hey all. I have been taking baby steps in setting up OpenZiti ZTNA in my company's architecture. I don't want to deal with multiple VPNs but only have 1 centralized VPN being OpenZiti. Am I understanding this correctly where in the CORP VPC where the edge router and controller is the hub and where I have the 1 edge router in each other VPC CIDR?

The 1 goal I want to establish is being able to have developers connect to their respective Tunneler on their local workstation and then have Ziti gatekeep RDS access and to internal web services such as GitLab and ArgoCD.

Here is my diagram: