Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
For most teams, package Playwright and its matching browser image into a version-pinned Docker image, push it to Amazon ECR, and run it as an ECS service or task on AWS Fargate. Use ECS on EC2 when you need host-level control; reserve Lambda container images for short, event-driven jobs.
Choose the AWS execution model
The deployment workflow is the same at the image level, but the operating model differs significantly.
| Option | Best fit | What you operate | Important qualification |
|---|---|---|---|
| ECS on Fargate | Most browser workers and services | Task definition, networking, IAM, logs and scaling | AWS manages the underlying server capacity; Fargate is integrated with ECS. |
| ECS on EC2 | Specialized instance types, host-level tuning or predictable host utilization | ECS container instances, Docker hosts, patching and capacity | You must operate the EC2 container hosts. |
| Lambda container image | Short, event-driven browser jobs | Function configuration, triggers and the Lambda runtime constraints | It is an alternative for jobs, not the default shape for a persistent Playwright service; verify current Lambda limits for your region and runtime. |
A private worker task with controlled outbound access is generally safer than exposing a Playwright server publicly. If a browser service must accept inbound requests, add strong authentication, narrow ingress rules and rate limits.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minutePrerequisites and version pinning
- An AWS account with permission to create an ECR repository, ECS resources, IAM roles, networking and log groups.
- Docker and the AWS CLI installed locally, with credentials configured for the target account and region.
- A Node.js application whose
playwrightdependency is pinned to an exact version. - A decision about whether the container will run one browser per task or several contexts/workers. Memory pressure and crash rates increase as concurrency rises.
Playwright’s official container image includes browser binaries and system dependencies, but the Playwright package still has to be installed in your application. Keep the image tag and npm package on the same version so the package can discover the browser executables. The documentation lists tags such as v1.63.0-noble; use a specific tag rather than latest, and update both values together after testing.
#1 Best Overall
Use a glibc-based image
Start with the documented Ubuntu-based Playwright image or another supported glibc-based base image. Alpine is not supported for the documented Firefox and WebKit builds because those browser builds require glibc. If you build from a Node image instead, install the exact Playwright package and browser dependencies explicitly.
Build a version-matched image
The following Dockerfile uses the official image and installs the matching package. Put Playwright in dependencies, not only in development dependencies, when the container runs browser code in production.
FROM mcr.microsoft.com/playwright:v1.63.0-noble
WORKDIR /app
COPY package*.json ./
RUN npm ci --omit=dev
COPY . .
# The official image provides the pwuser account.
RUN chown -R pwuser:pwuser /app
USER pwuser
CMD ["node", "worker.js"]
Your package.json and lockfile should resolve [email protected] to match the image tag. If you choose a plain Node base image, install the same package version and run the Playwright browser installation command with system dependencies during the image build; do not assume that a browser is present just because the npm package is installed.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Keep the container contract simple
- Have the process log useful progress and errors to standard output and standard error so ECS can forward them.
- Exit non-zero on a failed job so an ECS service can replace an unhealthy task.
- Expose a port only when the process is an HTTP or Playwright server. A one-shot worker does not need a public port.
- Record the Playwright package version and image digest in deployment metadata.
Test safely with Docker before AWS
Build and run the image locally before creating the ECS task:
docker build -t playwright:1.63.0 .
docker run --rm --init --ipc=host playwright:1.63.0
Playwright recommends Docker’s --init option so child processes are reaped correctly. For Chromium, --ipc=host is recommended because the default shared-memory setting can cause Chromium to run out of memory and crash. In ECS, translate the process and shared-memory requirements into options supported by your task definition and launch type; a local Docker flag is not automatically a production configuration.
Run browser tests against representative pages and concurrency levels. A container that succeeds with one context can fail when several Chromium processes share the same task memory.
Push the image to Amazon ECR
Create a private repository, authenticate Docker to the regional registry, tag the image with the complete repository URI, and push it.
REGION=us-east-1
ACCOUNT_ID=123456789012
REPOSITORY=playwright
IMAGE="$ACCOUNT_ID.dkr.ecr.$REGION.amazonaws.com/$REPOSITORY:1.63.0"
aws ecr create-repository --repository-name "$REPOSITORY" --region "$REGION"
aws ecr get-login-password --region "$REGION" | docker login --username AWS --password-stdin "$ACCOUNT_ID.dkr.ecr.$REGION.amazonaws.com"
docker build -t playwright:1.63.0 .
docker tag playwright:1.63.0 "$IMAGE"
docker push "$IMAGE"
The image value in ECS must be the full account.dkr.ecr.region.amazonaws.com/repository:tag name. A short local name such as playwright:1.63.0 cannot be pulled by ECS.
Rank #3
Give ECS the right IAM roles
Task execution role
The ECS task execution role is used by the ECS agent to pull a private ECR image and publish configured logs. For ECR image pulls, it needs these actions:
ecr:GetAuthorizationTokenecr:BatchGetImageecr:GetDownloadUrlForLayer
Attach the role to the task definition as executionRoleArn. Fargate uses this ECS task execution role to pull from ECR. With the EC2 launch type, the container-instance role is involved in pulling images.
Application task role
Use a separate taskRoleArn for permissions needed by your application, such as reading a queue or writing results. Grant only the actions and resources the browser worker actually needs. Do not put application permissions on the execution role merely because both roles appear in the same task definition.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRegister an ECS task definition
A task definition should specify the complete image URI, CPU and memory appropriate for your measured browser workload, logging, networking assumptions and (only for a service) a port mapping. This fragment shows the important shape; the CPU and memory values are an illustrative starting point, not a universal Playwright benchmark.
{
"family": "playwright-worker",
"requiresCompatibilities": ["FARGATE"],
"networkMode": "awsvpc",
"cpu": "1024",
"memory": "2048",
"executionRoleArn": "arn:aws:iam::ACCOUNT_ID:role/ecsTaskExecutionRole",
"taskRoleArn": "arn:aws:iam::ACCOUNT_ID:role/playwrightTaskRole",
"containerDefinitions": [
{
"name": "playwright",
"image": "ACCOUNT_ID.dkr.ecr.REGION.amazonaws.com/playwright:1.63.0",
"essential": true,
"logConfiguration": {
"logDriver": "awslogs",
"options": {
"awslogs-group": "/ecs/playwright",
"awslogs-region": "REGION",
"awslogs-stream-prefix": "worker"
}
}
}
]
}
Replace the account, region, role names, image URI and log-group values for your account. Register the definition, then create an ECS service for a continuously available worker or run individual tasks for queued jobs. If the container serves HTTP, add a load balancer and a container port; if it only consumes jobs, keep it private and omit inbound exposure.
Networking for browser destinations
Place worker tasks in private subnets when they do not need inbound internet traffic. Provide controlled outbound access through the network design approved for your organization, and allow DNS, HTTPS and any APIs the browser must reach. A private subnet without egress will produce page timeouts that look like Playwright failures.
For a public Playwright endpoint, treat the endpoint as an untrusted-input boundary: authenticate every request, restrict security-group ingress, avoid broad network reachability and set job timeouts. Browsing arbitrary destinations can create SSRF and data-exfiltration risks even when the browser code itself is correct.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Choose a safe browser trust boundary
Running Chromium as root disables its sandbox. For crawling, screenshot services or any other workload that visits untrusted sites, run as a non-root user and apply the seccomp profile with the user-namespace permissions required by Playwright. A root container may be acceptable for tightly controlled end-to-end tests, but it is the wrong default for arbitrary URLs.
Best Value
- Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
- Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
Keep browser workers isolated from credentials and internal services. Use task roles with least privilege, avoid placing long-lived secrets in the image, and inject only the credentials required for the current job.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Operate and estimate the deployment
Logs and replacement
- Send stdout and stderr to CloudWatch Logs or an equivalent sink.
- Include the Playwright version, image tag and image digest in each deployment record.
- Replace running tasks when the image digest changes; a reused tag alone does not guarantee that every task has the new image.
- Track page timeouts, browser crashes, task restarts, job duration and memory utilization.
Cost model
There is no universal Playwright-on-AWS price. Estimate Fargate or EC2 compute from task CPU, memory, runtime and concurrency, then add ECR storage, log ingestion and retention, and network egress for the target region. Lambda adds its own invocation and duration model and must be checked against current regional pricing and limits.
Troubleshoot common failures
| Symptom | Likely cause | Correction |
|---|---|---|
| “Executable doesn’t exist” or browser launch errors | The npm package and image contain different Playwright versions, or the image never installed browsers. | Pin the same exact version in the image tag and package; rebuild without relying on a floating tag. |
| Chromium crashes under load | Insufficient shared memory or too many browser processes for the task memory. | Use the recommended IPC/shared-memory configuration supported by the ECS launch type, reduce concurrency, or allocate more memory. |
| ECS cannot pull the image | The image URI is incomplete, the execution role lacks ECR actions, or the task has no route to ECR. | Use the full regional ECR URI, correct the execution role, and verify subnet routing and egress. |
| Pages consistently time out | The task has no DNS or outbound route, or the destination blocks the task’s egress IP. | Test network reachability from the task subnet and confirm the destination’s access policy. |
| Browser launch fails only for untrusted URLs | The container runs as root or lacks the required sandbox/seccomp configuration. | Use a non-root user and the Playwright-recommended seccomp settings for untrusted browsing. |
| Tasks restart without useful evidence | Logs are not configured or the process exits without reporting the exception. | Configure the awslogs driver, log uncaught errors, and inspect the stopped-task reason. |
Or skip the browser setup
If your goal is reliable website screenshots rather than operating Chromium yourself, ScreenshotNeo provides a website screenshot API and MCP server. One GET request returns PNG, JPEG, WebP or PDF output; the service accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets. Each step can be turned off.
Recommended Free Tools
Only clean shots are billed. Bot checks and CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing, and the response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server exposes take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.
Example request (see the ScreenshotNeo API documentation):
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
There is a free allowance of 1,000 screenshots per month with no card required. Paid plans start at $5 for 3,000 shots, and every feature is included on every plan. Create a free ScreenshotNeo account to try it.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

