SAM Doctor

ERROR REFERENCE

Stack is in ROLLBACK_COMPLETE state and can not be updated

A terminal CloudFormation stack must be recreated before deployment

CloudFormation refuses an update when the stack is in ROLLBACK_COMPLETE after a failed first create or DELETE_COMPLETE after deletion. The next operation must recreate the stack, with the right cleanup and root-cause checks first.

WHAT IT MEANS

What this error means

Stack: my-app is in ROLLBACK_COMPLETE state and can not be updated.
Stack: my-app is in DELETE_COMPLETE state and can not be updated.

ROLLBACK_COMPLETE follows a failed initial stack creation, while DELETE_COMPLETE means CloudFormation has finished deleting the stack. Neither state is an update target, so a subsequent sam deploy or aws cloudformation deploy must take the create path.

FIX

How to fix it

  1. Confirm the terminal state and inspect events (read-only). For a rollback, locate the earliest CREATE_FAILED entry:
    aws cloudformation describe-stack-events --stack-name YOUR_STACK \
      --query "StackEvents[?ResourceStatus=='CREATE_FAILED'].[LogicalResourceId,ResourceStatusReason]" \
      --output table
  2. Fix the original cause when the state is ROLLBACK_COMPLETE. Deleting and recreating without fixing the first failed resource reproduces the same failure.
  3. Review the cleanup path. For DELETE_COMPLETE, wait until deletion is complete and inspect retained resources and custom names before creating again. For a rolled-back initial create, review what the failed stack holds before deleting it:
    aws cloudformation delete-stack --stack-name YOUR_STACK
    aws cloudformation wait stack-delete-complete --stack-name YOUR_STACK
  4. Create again with the same stack name. Once the root cause is fixed, deletion is complete, and retained-resource conflicts are understood, the create can proceed normally.
  5. Optional for iterating on new stacks: sam deploy --disable-rollback keeps successfully created resources on failure so you can fix forward. Use it consciously; it leaves partial stacks behind.

AUTOMATE THE TRIAGE

Diagnose this automatically

SAM Doctor recognizes both terminal states (high confidence), separates them from ordinary rollback noise, and points you at the first failed resource or cleanup check. Runs locally; no AWS access, no log upload.

python -m pip install sam-doctor
sam-doctor diagnose deployment.log --format markdown

RELATED

Longer walkthrough: finding the first useful CloudFormation failure.