Rollback

Rollback Behavior on a Failed Create or Update

On AWS 24 , a failed create deletes everything already created and ends in ROLLBACK_COMPLETE, where the only option is deleting the stack; a failed update restores the changed resources and ends in UPDATE_ROLLBACK_COMPLETE, still usable. --disable-rollback keeps what succeeded in CREATE_FAILED or UPDATE_FAILED so you can fix and retry, and rollback-stack rolls back later. A failed rollback waits in UPDATE_ROLLBACK_FAILED for continue-update-rollback. On LocalStack 4.13.1 63,725 , this template creates a table, then a bucket with an illegal name:

infra/rollback-demo.yaml: the second resource failsYAML
Resources:
  DemoTable:
    Type: AWS::DynamoDB::Table
    Properties:
      TableName: booknest-rollback-demo
      BillingMode: PAY_PER_REQUEST
      AttributeDefinitions: [{AttributeName: id, AttributeType: N}]
      KeySchema: [{AttributeName: id, KeyType: HASH}]
  BadBucket: {Type: AWS::S3::Bucket, DependsOn: DemoTable, Properties: {BucketName: Book_Nest}}
A failed create on LocalStack: what remains afterwardsShell
aws cloudformation create-stack --stack-name booknest-rollback \
  --template-body file://rollback-demo.yaml --query StackId --output text | cut -d/ -f1-2
sleep 5
aws cloudformation describe-stack-events --stack-name booknest-rollback --output text \
  --query 'reverse(StackEvents)[].[LogicalResourceId,ResourceStatus]'
aws dynamodb list-tables --output text --query 'TableNames[?contains(@, `rollback`)]'
Output
arn:aws:cloudformation:us-east-1:000000000000:stack/booknest-rollback
booknest-rollback   CREATE_IN_PROGRESS
DemoTable   CREATE_IN_PROGRESS
DemoTable   CREATE_COMPLETE
BadBucket   CREATE_IN_PROGRESS
BadBucket   CREATE_FAILED
booknest-rollback   CREATE_FAILED
booknest-rollback   ROLLBACK_COMPLETE
booknest-rollback   CREATE_FAILED
booknest-rollback-demo

LocalStack logs a ROLLBACK_COMPLETE event, yet the stack ends in CREATE_FAILED with the table kept; a failed update on 4.13.1 even ends in UPDATE_COMPLETE. AWS would delete the table and end in ROLLBACK_COMPLETE (not run here). So on LocalStack, read the events for FAILED, not the final status, and run cfn-lint 2,641 first: it rejects this bucket name before anything is deployed (Linting and Testing).