Original source: https://github.com/aws-quickstart/quickstart-cisco-asav-ravpn
With lots of changes because the original is intended to do ... just about everything, from create a VPC to standing up a route 53 zone to adding a transit gateway. Way more than we want.