Is it possible to modify this solution so a spoke VPC connects to the TGW hub over VPN, and that spoke VPC's internet access is centralized full tunnel?
Perhaps route 0/0 on the spoke to strongswan. Then have an edge association on the hub's igw to route 0/0 to the tgw?
If not, can I build a solution using my own NAT instance, or web proxies? I need internet at the VPC level please due to a VM provisioning service outside of my control.