Announcing the LocalStack for AWS 2026.09.0 Release

Announcing the LocalStack for AWS 2026.09.0 Release

Introduction

LocalStack for AWS 2026.09.0 is now available. This release introduces S3 Files for mounting versioned S3 bucket data in Lambda, ECS, and Batch workloads. It also makes the new DynamoDB and Kinesis engines the default for all users. DynamoDB Streams and Kinesis streams use shard-aware pollers by default for Lambda event source mappings and EventBridge Pipes.

The release also adds Timestream scheduled queries, expands AppSync GraphQL and Events behavior, and adds Logs Insights query support to the CloudWatch Logs v2 provider. CloudFormation broadens in-place resource updates and adds first support for four resource types.

How to upgrade?

To upgrade to LocalStack for AWS 2026.09.0, use lstk, which authenticates the session and pulls the latest image when started with:

Terminal window
lstk

If using Docker CLI or Docker Compose, update the Docker image:

Terminal window
docker pull localstack/localstack-pro:2026.09.0

Both DockerHub images (localstack/localstack and localstack/localstack-pro) are supported and contain the same image. Refer to the 2026.03.0 release notes for details about the consolidated image and auth token requirement.

What’s new in LocalStack for AWS 2026.09.0?

S3 Files

S3 Files presents objects in a general purpose S3 bucket as a shared file system. Applications use standard file operations, while S3 Files synchronizes the file system and bucket in both directions. The bucket remains the source of truth.

LocalStack supports all 21 S3 Files API operations for file systems, access points, mount targets, file system policies, synchronization configuration, and resource tags. The backing bucket must have versioning enabled and must be in the same Region and account as the file system. S3 Files assumes an IAM role to access the bucket.

Lambda functions, ECS tasks, and Batch jobs can mount an S3 Files file system through Docker or Kubernetes executors. A mount target must exist in each Availability Zone used by the compute workload. Lambda accepts one access point ARN in FileSystemConfigs, requires a LocalMountPath under /mnt, and must connect to a VPC. ECS task definitions use s3filesVolumeConfiguration and require taskRoleArn. Batch job definitions require jobRoleArn and a full fileSystemArn.

Changes made through the file system are exported to the bucket after 60 seconds without writes. Set S3FILES_EXPORT_DELAY_SECONDS to shorten this window for local testing. A shorter delay can hide behavior that occurs with AWS’s fixed 60-second window. Bucket changes appear in the file system within seconds. If both copies change concurrently, the bucket version wins. The local copy moves to .s3files-lost+found-<file-system-id> in the file-system root, and this directory is not exported to the bucket.

Refer to the S3 Files documentation for setup examples, synchronization behavior, and the complete limitations list. S3 Files is available starting with the Ultimate plan.

DynamoDB and Kinesis engine updates

The new DynamoDB engine is now the default and available to all users. It enables shard-aware DynamoDB Streams pollers by default for Lambda event source mappings and EventBridge Pipes. Each shard can have a concurrent consumer, and the pollers support resharding and checkpointing.

During startup, DynamoDB imports tables and data created by the legacy DynamoDB Local provider. Set DYNAMODB_SKIP_LEGACY_MIGRATION=1 to disable the import.

DynamoDB backup operations are also available to all plans. The available operations are CreateBackup, ListBackups, RestoreTableFromBackup, and DeleteBackup.

The new Kinesis engine is now the default for all users, and existing persisted state migrates automatically. Its shard-aware pollers for Lambda event source mappings and EventBridge Pipes support concurrent per-shard consumers, resharding, and checkpointing.

Timestream scheduled queries

Timestream scheduled queries can now be created, described, listed, updated, and deleted. Enabled queries run according to their ScheduleConfiguration. You can also run a scheduled query manually with ExecuteScheduledQuery and use the @scheduled_runtime parameter.

Scheduled queries can write results to a target table with MultiMeasureMappings or MixedMeasureMappings. Rows that cannot be written through mixed-measure mappings are included in an error report. Timestream can send SNS notifications when a scheduled query is created, updated, deleted, or run.

Other Timestream changes include:

  • Records with a DOUBLE measure value of 0 no longer cause a SQL syntax error.
  • Persistence restores and Cloud Pod loads no longer drop all but one Timestream database when the same LocalStack instance also runs RDS PostgreSQL.

AppSync GraphQL and Events

AppSync Events now supports the AWS_LAMBDA authorization mode for connect, subscribe, and publish requests. AppSync exposes handlerContext to channel namespace handlers, honors identityValidationExpression, caches results, and selects the matching provider for multi-auth APIs. Channel namespace handlers report Lambda Authorization from util.authType().

GraphQL APIs using the AWS_LAMBDA authorization mode send request variables, the operation name, and headers to the authorizer. Results can be cached per API and token through authorizerResultTtlInSeconds. Lambda authorizer failures return AuthorizerFailureException.

CloudFormation, SAM, and CDK can deploy AWS::AppSync::Api resources for AppSync Events. CloudFormation can also create AWS::AppSync::ChannelNamespace resources with auth modes, inline or S3 code handlers, handler configuration, and tags.

AppSync subscription behavior includes these changes:

  • A resolver on a Subscription field runs when the client subscribes. It can inspect request credentials through $ctx and reject the subscription.
  • Subscription operations sent to the HTTP endpoint return HTTP 400.
  • A subscription that selects a non-nullable field omitted by the mutation receives a cannot-return-null error with the data.
  • A mutation that returns data with errors still notifies subscribers.
  • Invalid subscription queries receive an error frame instead of an acknowledgment.
  • Resolvers do not run again when a notification is delivered.
  • AppSync Events subscription IDs need to be unique only within one WebSocket connection.

Resolver and mapping template behavior includes:

  • $util.authType() and util.authType() return the request authorization mode in VTL and JavaScript resolvers, including IAM, Cognito user pool, OIDC, and Lambda authorization.
  • AppSync and API Gateway VTL templates support the Java Map methods size, isEmpty, containsKey, containsValue, getOrDefault, remove, values, entrySet, and keySet.
  • VTL resolvers support $util.transform.toDynamoDBFilterExpression and $util.transform.toDynamoDBConditionExpression. $util.dynamodb.toDynamoDB represents Boolean values as BOOL.
  • AppSync resolvers and API Gateway mapping templates apply AWS-compatible #if and ! evaluation. They also support $util.map.copyAndRetainAllKeys, $util.map.copyAndRemoveAllKeys, and method-style $foreach.hasNext().
  • AppSync accepts GraphQL schemas that use @oneOf input objects. It validates these schemas without enforcing oneOf semantics, matching AWS AppSync.
  • AWSJSON output fields are JSON-encoded strings, and AWSJSON arguments are parsed into objects, lists, and scalars. Clients that previously consumed native output objects must parse returned values with JSON.parse.
  • GraphQL variable coercion now follows AWS behavior for String, Int, Float, Boolean, and ID. Inline literals remain strict.
  • Validation, execution, and resolver errors include AWS-compatible response fields. Syntax errors and invalid operation names return HTTP 400. Literal, argument, type, variable, and sub-selection errors use AWS-compatible wording. $util.toJson and other JSON helpers emit compact JSON, and String fields render lists and maps as [1, 2] and {a=1}.
  • Field-level authorization denials return HTTP 200, preserve authorized data, and include one Unauthorized error for each denied field. Malformed SigV4 requests return HTTP 403 with IncompleteSignatureException.
  • IAM denials return AccessDeniedException, and unparsable Cognito tokens return UnauthorizedException. IAM denial messages preserve the principal, action, and resource. Event API denials include the relevant operation details.
  • Mapping template version 2018-05-29 passes data source failures to the response template through $ctx.error. Version 2017-02-28 reports the error on the field.
  • With mapping template version 2017-02-28, null data source results skip response templates. Missing DynamoDB items return null in both template versions, and DynamoDB failures use AWS-compatible error names.
  • Lambda data source function and invocation failures are now reported as failures instead of returning the Lambda error document as successful data. Function errors behind mapping templates use Lambda:Unhandled, direct resolvers without templates use the exception class name, and invocation failures use Lambda:IllegalArgument. JavaScript response handlers receive the failure context. For AppSync Events, direct integrations continue to fail the publish, while code handlers run the response handler with the failure context and deliver the value it returns.

CloudWatch Logs v2 and destinations

The CloudWatch Logs v2 provider supports Logs Insights queries through StartQuery, GetQueryResults, and StopQuery. It evaluates fields, display, filter, stats, sort, limit, and parse. Queries can span multiple log groups, and JSON log messages expose discovered fields.

CloudWatch Logs subscription filters can target logical destination ARNs, including cross-account destinations. Matching events are forwarded to the destination’s target stream.

CloudWatch Logs also validates KMS access before associating a key with a log group. CreateLogGroup and AssociateKmsKey return AccessDeniedException when the key does not exist, is disabled, or its key policy does not grant the CloudWatch Logs service principal access. Setups that use a placeholder KMS key ARN must create and use a real KMS key. The v2 provider implements AssociateKmsKey and DisassociateKmsKey.

CloudFormation updates

CloudFormation adds in-place update support for these 63 resource types:

  • API and application services: AWS::ApiGateway::Account, AWS::ApiGateway::Authorizer, AWS::ApiGateway::Deployment, AWS::ApiGateway::DomainName, AWS::ApiGateway::Resource, AWS::ApiGateway::Stage, AWS::ApiGatewayV2::Api, AWS::ApiGatewayV2::DomainName, AWS::ApiGatewayV2::VpcLink, AWS::CloudFront::Distribution, AWS::CodeDeploy::DeploymentGroup, AWS::CodePipeline::Pipeline, AWS::ElasticBeanstalk::ApplicationVersion, AWS::ElasticBeanstalk::ConfigurationTemplate, AWS::ElasticBeanstalk::Environment, AWS::Pipes::Pipe, and AWS::SES::ReceiptRule.
  • Compute and scaling: AWS::ApplicationAutoScaling::ScalingPolicy, AWS::AutoScaling::AutoScalingGroup, AWS::Batch::ComputeEnvironment, AWS::Batch::JobDefinition, AWS::Batch::JobQueue, AWS::ECS::CapacityProvider, AWS::ECS::ClusterCapacityProviderAssociations, AWS::ECS::TaskDefinition, AWS::Glue::Job, AWS::Lambda::Alias, AWS::Lambda::EventInvokeConfig, AWS::Lambda::Version, AWS::MWAA::Environment, AWS::SageMaker::Endpoint, AWS::SageMaker::EndpointConfig, and AWS::SageMaker::Model.
  • Data and database services: AWS::DMS::Endpoint, AWS::DMS::ReplicationConfig, AWS::DMS::ReplicationInstance, AWS::DMS::ReplicationTask, AWS::DocDB::DBCluster, AWS::DocDB::DBInstance, AWS::ElastiCache::CacheCluster, AWS::ElastiCache::ReplicationGroup, AWS::KinesisAnalyticsV2::Application, AWS::KinesisAnalyticsV2::ApplicationCloudWatchLoggingOption, AWS::KinesisFirehose::DeliveryStream, AWS::Neptune::DBCluster, AWS::Neptune::DBInstance, and AWS::Redshift::Cluster.
  • Networking, storage, and discovery: AWS::ElasticLoadBalancingV2::Listener, AWS::ElasticLoadBalancingV2::ListenerRule, AWS::ElasticLoadBalancingV2::LoadBalancer, AWS::ElasticLoadBalancingV2::TargetGroup, AWS::Route53::HostedZone, AWS::S3::Bucket, AWS::ServiceDiscovery::HttpNamespace, and AWS::ServiceDiscovery::PublicDnsNamespace.
  • Identity, security, and operations: AWS::CertificateManager::Certificate, AWS::CloudTrail::Trail, AWS::Cognito::UserPoolDomain, AWS::IAM::InstanceProfile, AWS::IAM::ManagedPolicy, AWS::SecretsManager::SecretTargetAttachment, AWS::SSM::MaintenanceWindow, and AWS::SSM::PatchBaseline.

Stack updates also apply the related service changes, including API Gateway stage and deployment settings, ELBv2 listener and target group properties, Batch compute environment and job definition revisions, DMS endpoint and replication settings, Kinesis Data Analytics maintenance and logging configuration, Firehose destination and encryption settings, and Lambda alias routing configuration.

Related service changes include:

  • Service Discovery implements UpdatePublicDnsNamespace, and creating AWS::ServiceDiscovery::PublicDnsNamespace no longer creates a private namespace. SSM implements UpdateMaintenanceWindow, GetPatchBaseline, UpdatePatchBaseline, and tag operations for patch baselines.
  • CloudFormation stack updates to AWS::ApiGateway::Authorizer are no longer silently ignored, and updates to COGNITO_USER_POOLS authorizers preserve provider ARNs. API Gateway v2 OpenAPI re-imports preserve stages. API Gateway implements UpdateDomainName.
  • CloudFormation can create AWS::Batch::JobDefinition without a validation failure, and updates register a new revision. Job definitions no longer mangle keys in free-form maps such as Parameters, Labels, and LogConfiguration.Options.
  • CloudFormation can create AWS::KinesisAnalyticsV2::Application with ApplicationMaintenanceConfiguration. Kinesis Data Analytics implements UpdateApplicationMaintenanceConfiguration. Firehose implements StartDeliveryStreamEncryption and StopDeliveryStreamEncryption.
  • ELBv2 load balancer updates support subnets, security groups, IP address type, attributes, and tags. New load balancers created by CloudFormation receive aws:cloudformation:* system tags.
  • Auto Scaling group updates apply MaxInstanceLifetime, CapacityRebalance, PlacementGroup, TerminationPolicies, and DefaultCooldown, and attach or detach ELBv2 target groups.
  • CloudTrail trails apply IsOrganizationTrail and KMSKeyId during creation. GetEventSelectors, PutInsightSelectors, and UpdateTrail align more closely with AWS.
  • CodeDeploy deployment groups store and apply ServiceRoleArn, Ec2TagFilters, Ec2TagSet, OnPremisesInstanceTagFilters, and OnPremisesTagSet during creation and updates.
  • SageMaker endpoint configurations return endpoint-configuration ARNs and AWS-compatible defaults for network isolation, detailed observability, and initial variant weight. SageMaker implements UpdateEndpoint.
  • CloudFront routes TagResource and UntagResource correctly after the first request.

AWS::ECS::TaskDefinition supports stack updates for tag changes. AWS::ECS::CapacityProvider supports in-place updates and receives aws:cloudformation:* system tags when created by CloudFormation. AWS::ECS::ClusterCapacityProviderAssociations supports updates to capacity providers and the default capacity provider strategy.

CloudFormation now determines replacement behavior for referenced create-only properties like AWS. This fixes SAM AutoPublishAlias updates and create-only changes made through Fn::Sub. For a create-only property that references another resource, change sets can report Replacement: Conditional. Changing a nested create-only property, such as Template/TemplateName on AWS::SES::Template, also replaces the resource.

CloudFormation also adds first support for AWS::ApiGatewayV2::RoutingRule, AWS::AppSync::Api, AWS::AppSync::ChannelNamespace, and AWS::SES::EmailIdentity.

Additional capabilities include EFS PutBackupPolicy and DescribeBackupPolicy, which enable the BackupPolicy property of AWS::EFS::FileSystem and Terraform’s aws_efs_backup_policy resource. CloudFormation can also delete AWS::Lambda::CapacityProvider resources.

Existing resource behavior includes these fixes:

  • Replacing AWS::EC2::SubnetRouteTableAssociation re-associates the subnet with the new route table.
  • AWS::Cognito::UserPool returns a ProviderName based on the user pool ID. Updating AWS::Cognito::IdentityPool preserves AllowClassicFlow and DeveloperProviderName when they are omitted.

For AWS::Batch::ComputeEnvironment, MinvCpus, MaxvCpus, DesiredvCpus, and UpdateToLatestImageVersion support in-place updates. Other EC2 or SPOT ComputeResources fields update in place when ReplaceComputeEnvironment is false. Changing OperationsRole on AWS::ElasticBeanstalk::Environment and changing the Availability Zone of AWS::DMS::ReplicationInstance remain unsupported.

For AWS::Lambda::Version, changing FunctionScalingConfig updates the resource in place. Changing Description, CodeSha256, or ProvisionedConcurrencyConfig replaces the version. AWS::Lambda::EventInvokeConfig returns <FunctionName>|<Qualifier> from Ref.

CloudFormation also rewrites API Gateway execute-api URLs to resolvable LocalStack URLs. Set CFN_DISABLE_URL_REWRITE=1 to preserve URLs as written.

Compute and container services

ECS and AWS Batch

ECS includes the following changes:

  • Container overrides replace task definition CPU and memory values, and task responses report the resulting resources.
  • Dynamic host ports remain dynamic in DescribeTaskDefinition, which avoids repeated Terraform replacement of task definitions and services.
  • CreateService and UpdateService apply supported service parameters and reject invalid parameter combinations.
  • Daemon task definitions can be registered, described, listed, deleted, and tagged, including through Terraform.
  • Daemons, revisions, and deployments support create, update, describe, list, and delete operations. Daemon tasks are not yet placed on container instances.
  • StopTask stops a container that is still starting.
  • An ECS service can disable Service Connect during an update.
  • DeleteTaskDefinitions is implemented, and ListTaskDefinitions honors the requested status.
  • Read operations no longer intermittently return internal errors while tasks and services are created, started, or stopped.

AWS Batch enforces timeout.attemptDurationSeconds and retryStrategy for single-container, array, and multi-node jobs. DescribeJobs returns each attempt. Batch also maps VCPU and MEMORY requirements to ECS container resources, applies task-level sizing for Fargate, and combines overrides by resource type.

Step Functions

Step Functions StopExecution now immediately aborts an execution when its task is waiting for a task token, heartbeat, or activity. The execution no longer remains RUNNING until the task times out.

Persisted endpoint availability

After a restart with persistence, Lambda function URLs, API Gateway invocations, and Application Load Balancer endpoints are available on the first request. A preceding management API call is no longer required for Lambda function URLs.

Lambda

Lambda Managed Instances preserve an explicit MemorySize and derive the default PerExecutionEnvironmentMaxConcurrency from execution environment vCPUs and the runtime. This prevents repeated Terraform memory_size drift.

Lambda container images can start when the image omits CMD or ENTRYPOINT and Docker also omits the corresponding field from its image inspection response. GetFunctionConfiguration accepts alias qualifiers and returns the configuration of the targeted version.

Glue

Glue Scala ETL jobs can pass --conf through DefaultArguments on the Docker executor when LocalStack runs outside Docker in host mode (LEGACY_DOCKER_CLIENT=1). Kubernetes Glue job runs also use an S3 workspace key that stays within the S3 key length limit.

Runtime and emulator diagnostics

LocalStack reports fatal runtime signals by name and prints Python tracebacks for native crashes through Python’s faulthandler. Users can opt out by setting PYTHONFAULTHANDLER themselves.

The /_localstack/diagnose endpoint masks configuration values that resemble API keys, tokens, and passwords.

IAM, KMS, and security behavior

The IAM enforcement engine includes these changes:

  • KMS authorization requires the key resource policy to grant access to the principal.
  • IAM key policies can name regional service principals such as logs.<region>.amazonaws.com, and kms:EncryptionContext:* condition keys are evaluated. Key policies of multi-Region KMS keys are resolved when ENFORCE_IAM is enabled.
  • EventBridge PutEvents evaluates events:source, events:detail-type, and events:eventBusInvocation. PutRule evaluates events:source and events:detail-type. ForAllValues and ForAnyValue work with single-valued keys.
  • Version-specific S3 GetObject and HeadObject requests require s3:GetObjectVersion when IAM enforcement is enabled. HeadObject now enforces IAM permissions.

KMS ReplicateKey now honors the supplied Policy, or uses the default key policy when no policy is supplied, instead of copying the primary key’s policy. GenerateDataKey and GenerateDataKeyWithoutPlaintext reject asymmetric keys with InvalidKeyUsageException.

Database, analytics, and AI services

Database, analytics, and AI service changes include:

  • RDS instances and clusters accept ManageMasterUserPassword without returning AlreadyExistsException.
  • When LocalStack replicates an RDS instance or cluster, the replication job reports SUCCEEDED only after the replicated resource and its endpoint are available.
  • Deleting a PostgreSQL-backed RDS instance shuts down PostgreSQL and releases shared memory.
  • Terraform can destroy an RDS global cluster after a detached secondary cluster has already been deleted.
  • Aurora PostgreSQL master password changes remain effective after a Cloud Pod restore.
  • Deleting an RDS, Neptune, or DocumentDB cluster during creation stops its database server and releases its port.
  • ElastiCache and MemoryDB run Valkey as a child process instead of silently starting Redis when REDIS_CONTAINER_MODE=0, which is the default. This also applies to Kubernetes deployments that cannot create additional pods. EngineVersion values 7.2, 8.0, 8.1, 8.2, 9.0, and 9.1 map to pinned Valkey releases downloaded on first use.
  • OpenSearch implements DescribeDomainChangeProgress.
  • Neptune cluster startup retries a stalled dependency download after a read timeout.
  • Bedrock Converse and InvokeModel cap output at 2048 generated tokens when no maximum is supplied. Converse returns whole-call latencyMs as an integer number of milliseconds. It previously returned a floating-point value that was 1000 times too large.

Networking, messaging, and service provider updates

Other provider changes include:

  • CloudFront Functions associated with a non-default cache behavior run when the request path matches that behavior. Viewer-response associations remain unsupported.
  • CloudFront Functions maintain separate DEVELOPMENT and LIVE versions. Distribution traffic uses published code, and draft changes require republishing.
  • EC2 snapshots created without a description return an empty description instead of the string None.
  • Application Load Balancers with only an HTTPS listener are available through ELBv2 load balancer endpoints.
  • API Gateway custom domains honor RoutingMode and evaluate REST API header and base path conditions in priority order.
  • API Gateway REST integrations render missing or empty request path parameter values as empty strings in the integration URI.
  • Route 53 supports DNSSEC signing for public hosted zones, including key-signing key lifecycle operations.
  • S3 bucket notifications use eventVersion 2.6 and set hasObjectAnnotation for ObjectCreated:Copy.
  • EventBridge Pipes forwards MessageGroupId and MessageDeduplicationId to SQS FIFO queues.
  • Shield supports enabling, updating, and disabling application layer automatic response for a protected resource. DescribeProtection returns the configured response.
  • WAFv2 implements ListResourcesForWebACL. Associating a resource with a new web ACL removes its previous web ACL association.
  • IoT supports attaching, detaching, and listing policies for targets and principals.
  • SESv2 implements the PutEmailIdentity* operations and returns a fully populated GetEmailIdentity response. SES also supports changing receipt rule positions.
  • ACM Private CA DescribeCertificateAuthority returns AWS-compatible defaults, revocation settings, LastStateChangeAt, and Serial for activated certificate authorities.
  • STS routes pre-signed requests to the STS service.
  • The LocalStack package manager supports JSON output from lpm list -j and lpm list --json.
  • If PROVIDER_OVERRIDE_<SERVICE> names a provider that no longer exists, LocalStack logs a warning and loads the provider that would otherwise be selected.

Deprecations and removals

The legacy ELBv2 provider has been removed. PROVIDER_OVERRIDE_ELBV2=legacy no longer selects it. Existing persisted state continues to migrate automatically.

The previous Kinesis and DynamoDB engines are deprecated. The following DynamoDB settings apply only to the legacy provider and are deprecated: DYNAMODB_HEAP_SIZE, DYNAMODB_SHARE_DB, DYNAMODB_DELAY_TRANSIENT_STATUSES, DYNAMODB_OPTIMIZE_DB_BEFORE_STARTUP, and DYNAMODB_CORS.

ORAS Cloud Pod remotes are discontinued in LocalStack 2026.09. Use an S3 remote or LocalStack platform remote instead. Existing registry data is not modified.

Conclusion

Before using S3 Files, review the Docker and Kubernetes runtime requirements in the S3 Files documentation. Before upgrading to LocalStack for AWS 2026.09.0, review the deprecated engines and provider removals above. Report problems or parity gaps through GitHub Discussions.