Also consider enabling S3 gateway endpoints:
https://docs.aws.amazon.com/vpc/latest/privatelink/vpce-gate...
That avoids paying NAT Gateway charges for traffic to S3 and in my testing also made a bit of a latency reduction, which came in handy once when I had a one-off data small file migration.