Check out https://port7777.com, a product that was born out of this post! It's cheap and will setup everything you need to connect to your RDS from your local machine.
We learned that it not only increase our chances, but also make it easier to answer these questions with "It's AWS responsibility".
A bastion host tries to mitigate this issue by creating a point of entry inside AWS VPC with a public IP.
Fargate is a service designed for scaling containers and we could not have 2 containers taking the same IP address.