Why i've not done this is theoretically is possible, AWS Direct Connects use VLANs and Express Routes use Q-in-Q which appears to be supported on the Catalyst switches/IOS-XE.
Realistically the AWS Direct Connect/Express route is just a layer 2 pseudowire link connection that you would usually terminate onto a router/firewall.
I see most customers terminate these onto their DC Firewall clusters with Zones/Firewall policies applied to limit traffic going over and from the AWS/Azure environments.
Some ISPs can just terminate the Direct Connect/Express Routes into their MPLS WANS VRFs directly and allow the Direct Connect/Express route to terminate directly into the customers WAN VRFS.
Eliot F | Simplifying IT with Cloud Solutions
Found this helpful? Give me some Kudos! (click on the little up-arrow below)