Yeah, I hate it. I'd want some sort of SAML SSO auth in front of the actual RDS Gateway to allow you to use whatever identity provider and MFA you already have.
You really don't want to allow all manner of auth attempts able to be made against your actual workload servers, which is what it sounds like you are describing.