Yes, you need a VPN to connect AWS to your private database, as exposing IP to the internet is not the right way (not recommended).