MediaCloud, a SaaS provider, needs to connect its 50 customer VPCs across multiple AWS Regions and accounts, allowing all VPCs to communicate while providing one-way access for license validation from each customer VPC to MediaCloud's central management VPC; what two steps provide the required connectivity with the LEAST operational overhead, considering future growth?