
Announcing the LocalStack for AWS 2026.09.0 Release
Introduction
LocalStack for AWS 2026.09.0 is now available. This release introduces S3 Files for mounting versioned S3 bucket data in Lambda, ECS, and Batch workloads. It also makes the new DynamoDB and Kinesis engines the default for all users. DynamoDB Streams and Kinesis streams use shard-aware pollers by default for Lambda event source mappings and EventBridge Pipes.
The release also adds Timestream scheduled queries, expands AppSync GraphQL and Events behavior, and adds Logs Insights query support to the CloudWatch Logs v2 provider. CloudFormation broadens in-place resource updates and adds first support for four resource types.
How to upgrade?
To upgrade to LocalStack for AWS 2026.09.0, use lstk, which authenticates the session and pulls the latest image when started with:
lstkIf using Docker CLI or Docker Compose, update the Docker image:
docker pull localstack/localstack-pro:2026.09.0Both DockerHub images (localstack/localstack and localstack/localstack-pro) are supported and contain the same image. Refer to the 2026.03.0 release notes for details about the consolidated image and auth token requirement.
What’s new in LocalStack for AWS 2026.09.0?
- S3 Files
- DynamoDB and Kinesis engine updates
- Timestream scheduled queries
- AppSync GraphQL and Events
- CloudWatch Logs v2 and destinations
- CloudFormation updates
- Compute and container services
- Runtime and emulator diagnostics
- IAM, KMS, and security behavior
- Database, analytics, and AI services
- Networking, messaging, and service provider updates
- Deprecations and removals
- Conclusion
S3 Files
S3 Files presents objects in a general purpose S3 bucket as a shared file system. Applications use standard file operations, while S3 Files synchronizes the file system and bucket in both directions. The bucket remains the source of truth.
LocalStack supports all 21 S3 Files API operations for file systems, access points, mount targets, file system policies, synchronization configuration, and resource tags. The backing bucket must have versioning enabled and must be in the same Region and account as the file system. S3 Files assumes an IAM role to access the bucket.
Lambda functions, ECS tasks, and Batch jobs can mount an S3 Files file system through Docker or Kubernetes executors. A mount target must exist in each Availability Zone used by the compute workload. Lambda accepts one access point ARN in FileSystemConfigs, requires a LocalMountPath under /mnt, and must connect to a VPC. ECS task definitions use s3filesVolumeConfiguration and require taskRoleArn. Batch job definitions require jobRoleArn and a full fileSystemArn.
Changes made through the file system are exported to the bucket after 60 seconds without writes. Set S3FILES_EXPORT_DELAY_SECONDS to shorten this window for local testing. A shorter delay can hide behavior that occurs with AWS’s fixed 60-second window. Bucket changes appear in the file system within seconds. If both copies change concurrently, the bucket version wins. The local copy moves to .s3files-lost+found-<file-system-id> in the file-system root, and this directory is not exported to the bucket.
Refer to the S3 Files documentation for setup examples, synchronization behavior, and the complete limitations list. S3 Files is available starting with the Ultimate plan.
DynamoDB and Kinesis engine updates
The new DynamoDB engine is now the default and available to all users. It enables shard-aware DynamoDB Streams pollers by default for Lambda event source mappings and EventBridge Pipes. Each shard can have a concurrent consumer, and the pollers support resharding and checkpointing.
During startup, DynamoDB imports tables and data created by the legacy DynamoDB Local provider. Set DYNAMODB_SKIP_LEGACY_MIGRATION=1 to disable the import.
DynamoDB backup operations are also available to all plans. The available operations are CreateBackup, ListBackups, RestoreTableFromBackup, and DeleteBackup.
The new Kinesis engine is now the default for all users, and existing persisted state migrates automatically. Its shard-aware pollers for Lambda event source mappings and EventBridge Pipes support concurrent per-shard consumers, resharding, and checkpointing.
Timestream scheduled queries
Timestream scheduled queries can now be created, described, listed, updated, and deleted. Enabled queries run according to their ScheduleConfiguration. You can also run a scheduled query manually with ExecuteScheduledQuery and use the @scheduled_runtime parameter.
Scheduled queries can write results to a target table with MultiMeasureMappings or MixedMeasureMappings. Rows that cannot be written through mixed-measure mappings are included in an error report. Timestream can send SNS notifications when a scheduled query is created, updated, deleted, or run.
Other Timestream changes include:
- Records with a
DOUBLEmeasure value of0no longer cause a SQL syntax error. - Persistence restores and Cloud Pod loads no longer drop all but one Timestream database when the same LocalStack instance also runs RDS PostgreSQL.
AppSync GraphQL and Events
AppSync Events now supports the AWS_LAMBDA authorization mode for connect, subscribe, and publish requests. AppSync exposes handlerContext to channel namespace handlers, honors identityValidationExpression, caches results, and selects the matching provider for multi-auth APIs. Channel namespace handlers report Lambda Authorization from util.authType().
GraphQL APIs using the AWS_LAMBDA authorization mode send request variables, the operation name, and headers to the authorizer. Results can be cached per API and token through authorizerResultTtlInSeconds. Lambda authorizer failures return AuthorizerFailureException.
CloudFormation, SAM, and CDK can deploy AWS::AppSync::Api resources for AppSync Events. CloudFormation can also create AWS::AppSync::ChannelNamespace resources with auth modes, inline or S3 code handlers, handler configuration, and tags.
AppSync subscription behavior includes these changes:
- A resolver on a
Subscriptionfield runs when the client subscribes. It can inspect request credentials through$ctxand reject the subscription. - Subscription operations sent to the HTTP endpoint return HTTP
400. - A subscription that selects a non-nullable field omitted by the mutation receives a cannot-return-null error with the data.
- A mutation that returns data with errors still notifies subscribers.
- Invalid subscription queries receive an error frame instead of an acknowledgment.
- Resolvers do not run again when a notification is delivered.
- AppSync Events subscription IDs need to be unique only within one WebSocket connection.
Resolver and mapping template behavior includes:
$util.authType()andutil.authType()return the request authorization mode in VTL and JavaScript resolvers, including IAM, Cognito user pool, OIDC, and Lambda authorization.- AppSync and API Gateway VTL templates support the Java
Mapmethodssize,isEmpty,containsKey,containsValue,getOrDefault,remove,values,entrySet, andkeySet. - VTL resolvers support
$util.transform.toDynamoDBFilterExpressionand$util.transform.toDynamoDBConditionExpression.$util.dynamodb.toDynamoDBrepresents Boolean values asBOOL. - AppSync resolvers and API Gateway mapping templates apply AWS-compatible
#ifand!evaluation. They also support$util.map.copyAndRetainAllKeys,$util.map.copyAndRemoveAllKeys, and method-style$foreach.hasNext(). - AppSync accepts GraphQL schemas that use
@oneOfinput objects. It validates these schemas without enforcing oneOf semantics, matching AWS AppSync. AWSJSONoutput fields are JSON-encoded strings, andAWSJSONarguments are parsed into objects, lists, and scalars. Clients that previously consumed native output objects must parse returned values withJSON.parse.- GraphQL variable coercion now follows AWS behavior for
String,Int,Float,Boolean, andID. Inline literals remain strict. - Validation, execution, and resolver errors include AWS-compatible response fields. Syntax errors and invalid operation names return HTTP
400. Literal, argument, type, variable, and sub-selection errors use AWS-compatible wording.$util.toJsonand other JSON helpers emit compact JSON, andStringfields render lists and maps as[1, 2]and{a=1}. - Field-level authorization denials return HTTP
200, preserve authorized data, and include oneUnauthorizederror for each denied field. Malformed SigV4 requests return HTTP403withIncompleteSignatureException. - IAM denials return
AccessDeniedException, and unparsable Cognito tokens returnUnauthorizedException. IAM denial messages preserve the principal, action, and resource. Event API denials include the relevant operation details. - Mapping template version
2018-05-29passes data source failures to the response template through$ctx.error. Version2017-02-28reports the error on the field. - With mapping template version
2017-02-28, null data source results skip response templates. Missing DynamoDB items return null in both template versions, and DynamoDB failures use AWS-compatible error names. - Lambda data source function and invocation failures are now reported as failures instead of returning the Lambda error document as successful data. Function errors behind mapping templates use
Lambda:Unhandled, direct resolvers without templates use the exception class name, and invocation failures useLambda:IllegalArgument. JavaScript response handlers receive the failure context. For AppSync Events, direct integrations continue to fail the publish, while code handlers run the response handler with the failure context and deliver the value it returns.
CloudWatch Logs v2 and destinations
The CloudWatch Logs v2 provider supports Logs Insights queries through StartQuery, GetQueryResults, and StopQuery. It evaluates fields, display, filter, stats, sort, limit, and parse. Queries can span multiple log groups, and JSON log messages expose discovered fields.
CloudWatch Logs subscription filters can target logical destination ARNs, including cross-account destinations. Matching events are forwarded to the destination’s target stream.
CloudWatch Logs also validates KMS access before associating a key with a log group. CreateLogGroup and AssociateKmsKey return AccessDeniedException when the key does not exist, is disabled, or its key policy does not grant the CloudWatch Logs service principal access. Setups that use a placeholder KMS key ARN must create and use a real KMS key. The v2 provider implements AssociateKmsKey and DisassociateKmsKey.
CloudFormation updates
CloudFormation adds in-place update support for these 63 resource types:
- API and application services:
AWS::ApiGateway::Account,AWS::ApiGateway::Authorizer,AWS::ApiGateway::Deployment,AWS::ApiGateway::DomainName,AWS::ApiGateway::Resource,AWS::ApiGateway::Stage,AWS::ApiGatewayV2::Api,AWS::ApiGatewayV2::DomainName,AWS::ApiGatewayV2::VpcLink,AWS::CloudFront::Distribution,AWS::CodeDeploy::DeploymentGroup,AWS::CodePipeline::Pipeline,AWS::ElasticBeanstalk::ApplicationVersion,AWS::ElasticBeanstalk::ConfigurationTemplate,AWS::ElasticBeanstalk::Environment,AWS::Pipes::Pipe, andAWS::SES::ReceiptRule. - Compute and scaling:
AWS::ApplicationAutoScaling::ScalingPolicy,AWS::AutoScaling::AutoScalingGroup,AWS::Batch::ComputeEnvironment,AWS::Batch::JobDefinition,AWS::Batch::JobQueue,AWS::ECS::CapacityProvider,AWS::ECS::ClusterCapacityProviderAssociations,AWS::ECS::TaskDefinition,AWS::Glue::Job,AWS::Lambda::Alias,AWS::Lambda::EventInvokeConfig,AWS::Lambda::Version,AWS::MWAA::Environment,AWS::SageMaker::Endpoint,AWS::SageMaker::EndpointConfig, andAWS::SageMaker::Model. - Data and database services:
AWS::DMS::Endpoint,AWS::DMS::ReplicationConfig,AWS::DMS::ReplicationInstance,AWS::DMS::ReplicationTask,AWS::DocDB::DBCluster,AWS::DocDB::DBInstance,AWS::ElastiCache::CacheCluster,AWS::ElastiCache::ReplicationGroup,AWS::KinesisAnalyticsV2::Application,AWS::KinesisAnalyticsV2::ApplicationCloudWatchLoggingOption,AWS::KinesisFirehose::DeliveryStream,AWS::Neptune::DBCluster,AWS::Neptune::DBInstance, andAWS::Redshift::Cluster. - Networking, storage, and discovery:
AWS::ElasticLoadBalancingV2::Listener,AWS::ElasticLoadBalancingV2::ListenerRule,AWS::ElasticLoadBalancingV2::LoadBalancer,AWS::ElasticLoadBalancingV2::TargetGroup,AWS::Route53::HostedZone,AWS::S3::Bucket,AWS::ServiceDiscovery::HttpNamespace, andAWS::ServiceDiscovery::PublicDnsNamespace. - Identity, security, and operations:
AWS::CertificateManager::Certificate,AWS::CloudTrail::Trail,AWS::Cognito::UserPoolDomain,AWS::IAM::InstanceProfile,AWS::IAM::ManagedPolicy,AWS::SecretsManager::SecretTargetAttachment,AWS::SSM::MaintenanceWindow, andAWS::SSM::PatchBaseline.
Stack updates also apply the related service changes, including API Gateway stage and deployment settings, ELBv2 listener and target group properties, Batch compute environment and job definition revisions, DMS endpoint and replication settings, Kinesis Data Analytics maintenance and logging configuration, Firehose destination and encryption settings, and Lambda alias routing configuration.
Related service changes include:
- Service Discovery implements
UpdatePublicDnsNamespace, and creatingAWS::ServiceDiscovery::PublicDnsNamespaceno longer creates a private namespace. SSM implementsUpdateMaintenanceWindow,GetPatchBaseline,UpdatePatchBaseline, and tag operations for patch baselines. - CloudFormation stack updates to
AWS::ApiGateway::Authorizerare no longer silently ignored, and updates toCOGNITO_USER_POOLSauthorizers preserve provider ARNs. API Gateway v2 OpenAPI re-imports preserve stages. API Gateway implementsUpdateDomainName. - CloudFormation can create
AWS::Batch::JobDefinitionwithout a validation failure, and updates register a new revision. Job definitions no longer mangle keys in free-form maps such asParameters,Labels, andLogConfiguration.Options. - CloudFormation can create
AWS::KinesisAnalyticsV2::ApplicationwithApplicationMaintenanceConfiguration. Kinesis Data Analytics implementsUpdateApplicationMaintenanceConfiguration. Firehose implementsStartDeliveryStreamEncryptionandStopDeliveryStreamEncryption. - ELBv2 load balancer updates support subnets, security groups, IP address type, attributes, and tags. New load balancers created by CloudFormation receive
aws:cloudformation:*system tags. - Auto Scaling group updates apply
MaxInstanceLifetime,CapacityRebalance,PlacementGroup,TerminationPolicies, andDefaultCooldown, and attach or detach ELBv2 target groups. - CloudTrail trails apply
IsOrganizationTrailandKMSKeyIdduring creation.GetEventSelectors,PutInsightSelectors, andUpdateTrailalign more closely with AWS. - CodeDeploy deployment groups store and apply
ServiceRoleArn,Ec2TagFilters,Ec2TagSet,OnPremisesInstanceTagFilters, andOnPremisesTagSetduring creation and updates. - SageMaker endpoint configurations return endpoint-configuration ARNs and AWS-compatible defaults for network isolation, detailed observability, and initial variant weight. SageMaker implements
UpdateEndpoint. - CloudFront routes
TagResourceandUntagResourcecorrectly after the first request.
AWS::ECS::TaskDefinition supports stack updates for tag changes. AWS::ECS::CapacityProvider supports in-place updates and receives aws:cloudformation:* system tags when created by CloudFormation. AWS::ECS::ClusterCapacityProviderAssociations supports updates to capacity providers and the default capacity provider strategy.
CloudFormation now determines replacement behavior for referenced create-only properties like AWS. This fixes SAM AutoPublishAlias updates and create-only changes made through Fn::Sub. For a create-only property that references another resource, change sets can report Replacement: Conditional. Changing a nested create-only property, such as Template/TemplateName on AWS::SES::Template, also replaces the resource.
CloudFormation also adds first support for AWS::ApiGatewayV2::RoutingRule, AWS::AppSync::Api, AWS::AppSync::ChannelNamespace, and AWS::SES::EmailIdentity.
Additional capabilities include EFS PutBackupPolicy and DescribeBackupPolicy, which enable the BackupPolicy property of AWS::EFS::FileSystem and Terraform’s aws_efs_backup_policy resource. CloudFormation can also delete AWS::Lambda::CapacityProvider resources.
Existing resource behavior includes these fixes:
- Replacing
AWS::EC2::SubnetRouteTableAssociationre-associates the subnet with the new route table. AWS::Cognito::UserPoolreturns aProviderNamebased on the user pool ID. UpdatingAWS::Cognito::IdentityPoolpreservesAllowClassicFlowandDeveloperProviderNamewhen they are omitted.
For AWS::Batch::ComputeEnvironment, MinvCpus, MaxvCpus, DesiredvCpus, and UpdateToLatestImageVersion support in-place updates. Other EC2 or SPOT ComputeResources fields update in place when ReplaceComputeEnvironment is false. Changing OperationsRole on AWS::ElasticBeanstalk::Environment and changing the Availability Zone of AWS::DMS::ReplicationInstance remain unsupported.
For AWS::Lambda::Version, changing FunctionScalingConfig updates the resource in place. Changing Description, CodeSha256, or ProvisionedConcurrencyConfig replaces the version. AWS::Lambda::EventInvokeConfig returns <FunctionName>|<Qualifier> from Ref.
CloudFormation also rewrites API Gateway execute-api URLs to resolvable LocalStack URLs. Set CFN_DISABLE_URL_REWRITE=1 to preserve URLs as written.
Compute and container services
ECS and AWS Batch
ECS includes the following changes:
- Container overrides replace task definition CPU and memory values, and task responses report the resulting resources.
- Dynamic host ports remain dynamic in
DescribeTaskDefinition, which avoids repeated Terraform replacement of task definitions and services. CreateServiceandUpdateServiceapply supported service parameters and reject invalid parameter combinations.- Daemon task definitions can be registered, described, listed, deleted, and tagged, including through Terraform.
- Daemons, revisions, and deployments support create, update, describe, list, and delete operations. Daemon tasks are not yet placed on container instances.
StopTaskstops a container that is still starting.- An ECS service can disable Service Connect during an update.
DeleteTaskDefinitionsis implemented, andListTaskDefinitionshonors the requested status.- Read operations no longer intermittently return internal errors while tasks and services are created, started, or stopped.
AWS Batch enforces timeout.attemptDurationSeconds and retryStrategy for single-container, array, and multi-node jobs. DescribeJobs returns each attempt. Batch also maps VCPU and MEMORY requirements to ECS container resources, applies task-level sizing for Fargate, and combines overrides by resource type.
Step Functions
Step Functions StopExecution now immediately aborts an execution when its task is waiting for a task token, heartbeat, or activity. The execution no longer remains RUNNING until the task times out.
Persisted endpoint availability
After a restart with persistence, Lambda function URLs, API Gateway invocations, and Application Load Balancer endpoints are available on the first request. A preceding management API call is no longer required for Lambda function URLs.
Lambda
Lambda Managed Instances preserve an explicit MemorySize and derive the default PerExecutionEnvironmentMaxConcurrency from execution environment vCPUs and the runtime. This prevents repeated Terraform memory_size drift.
Lambda container images can start when the image omits CMD or ENTRYPOINT and Docker also omits the corresponding field from its image inspection response. GetFunctionConfiguration accepts alias qualifiers and returns the configuration of the targeted version.
Glue
Glue Scala ETL jobs can pass --conf through DefaultArguments on the Docker executor when LocalStack runs outside Docker in host mode (LEGACY_DOCKER_CLIENT=1). Kubernetes Glue job runs also use an S3 workspace key that stays within the S3 key length limit.
Runtime and emulator diagnostics
LocalStack reports fatal runtime signals by name and prints Python tracebacks for native crashes through Python’s faulthandler. Users can opt out by setting PYTHONFAULTHANDLER themselves.
The /_localstack/diagnose endpoint masks configuration values that resemble API keys, tokens, and passwords.
IAM, KMS, and security behavior
The IAM enforcement engine includes these changes:
- KMS authorization requires the key resource policy to grant access to the principal.
- IAM key policies can name regional service principals such as
logs.<region>.amazonaws.com, andkms:EncryptionContext:*condition keys are evaluated. Key policies of multi-Region KMS keys are resolved whenENFORCE_IAMis enabled. - EventBridge
PutEventsevaluatesevents:source,events:detail-type, andevents:eventBusInvocation.PutRuleevaluatesevents:sourceandevents:detail-type.ForAllValuesandForAnyValuework with single-valued keys. - Version-specific S3
GetObjectandHeadObjectrequests requires3:GetObjectVersionwhen IAM enforcement is enabled.HeadObjectnow enforces IAM permissions.
KMS ReplicateKey now honors the supplied Policy, or uses the default key policy when no policy is supplied, instead of copying the primary key’s policy. GenerateDataKey and GenerateDataKeyWithoutPlaintext reject asymmetric keys with InvalidKeyUsageException.
Database, analytics, and AI services
Database, analytics, and AI service changes include:
- RDS instances and clusters accept
ManageMasterUserPasswordwithout returningAlreadyExistsException. - When LocalStack replicates an RDS instance or cluster, the replication job reports
SUCCEEDEDonly after the replicated resource and its endpoint are available. - Deleting a PostgreSQL-backed RDS instance shuts down PostgreSQL and releases shared memory.
- Terraform can destroy an RDS global cluster after a detached secondary cluster has already been deleted.
- Aurora PostgreSQL master password changes remain effective after a Cloud Pod restore.
- Deleting an RDS, Neptune, or DocumentDB cluster during creation stops its database server and releases its port.
- ElastiCache and MemoryDB run Valkey as a child process instead of silently starting Redis when
REDIS_CONTAINER_MODE=0, which is the default. This also applies to Kubernetes deployments that cannot create additional pods.EngineVersionvalues7.2,8.0,8.1,8.2,9.0, and9.1map to pinned Valkey releases downloaded on first use. - OpenSearch implements
DescribeDomainChangeProgress. - Neptune cluster startup retries a stalled dependency download after a read timeout.
- Bedrock
ConverseandInvokeModelcap output at 2048 generated tokens when no maximum is supplied.Conversereturns whole-calllatencyMsas an integer number of milliseconds. It previously returned a floating-point value that was 1000 times too large.
Networking, messaging, and service provider updates
Other provider changes include:
- CloudFront Functions associated with a non-default cache behavior run when the request path matches that behavior. Viewer-response associations remain unsupported.
- CloudFront Functions maintain separate
DEVELOPMENTandLIVEversions. Distribution traffic uses published code, and draft changes require republishing. - EC2 snapshots created without a description return an empty description instead of the string
None. - Application Load Balancers with only an HTTPS listener are available through ELBv2 load balancer endpoints.
- API Gateway custom domains honor
RoutingModeand evaluate REST API header and base path conditions in priority order. - API Gateway REST integrations render missing or empty request path parameter values as empty strings in the integration URI.
- Route 53 supports DNSSEC signing for public hosted zones, including key-signing key lifecycle operations.
- S3 bucket notifications use
eventVersion2.6and sethasObjectAnnotationforObjectCreated:Copy. - EventBridge Pipes forwards
MessageGroupIdandMessageDeduplicationIdto SQS FIFO queues. - Shield supports enabling, updating, and disabling application layer automatic response for a protected resource.
DescribeProtectionreturns the configured response. - WAFv2 implements
ListResourcesForWebACL. Associating a resource with a new web ACL removes its previous web ACL association. - IoT supports attaching, detaching, and listing policies for targets and principals.
- SESv2 implements the
PutEmailIdentity*operations and returns a fully populatedGetEmailIdentityresponse. SES also supports changing receipt rule positions. - ACM Private CA
DescribeCertificateAuthorityreturns AWS-compatible defaults, revocation settings,LastStateChangeAt, andSerialfor activated certificate authorities. - STS routes pre-signed requests to the STS service.
- The LocalStack package manager supports JSON output from
lpm list -jandlpm list --json. - If
PROVIDER_OVERRIDE_<SERVICE>names a provider that no longer exists, LocalStack logs a warning and loads the provider that would otherwise be selected.
Deprecations and removals
The legacy ELBv2 provider has been removed. PROVIDER_OVERRIDE_ELBV2=legacy no longer selects it. Existing persisted state continues to migrate automatically.
The previous Kinesis and DynamoDB engines are deprecated. The following DynamoDB settings apply only to the legacy provider and are deprecated: DYNAMODB_HEAP_SIZE, DYNAMODB_SHARE_DB, DYNAMODB_DELAY_TRANSIENT_STATUSES, DYNAMODB_OPTIMIZE_DB_BEFORE_STARTUP, and DYNAMODB_CORS.
ORAS Cloud Pod remotes are discontinued in LocalStack 2026.09. Use an S3 remote or LocalStack platform remote instead. Existing registry data is not modified.
Conclusion
Before using S3 Files, review the Docker and Kubernetes runtime requirements in the S3 Files documentation. Before upgrading to LocalStack for AWS 2026.09.0, review the deprecated engines and provider removals above. Report problems or parity gaps through GitHub Discussions.