Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

For most teams, package Playwright and its matching browser image into a version-pinned Docker image, push it to Amazon ECR, and run it as an ECS service or task on AWS Fargate. Use ECS on EC2 when you need host-level control; reserve Lambda container images for short, event-driven jobs.

Choose the AWS execution model

The deployment workflow is the same at the image level, but the operating model differs significantly.

Option Best fit What you operate Important qualification
ECS on Fargate Most browser workers and services Task definition, networking, IAM, logs and scaling AWS manages the underlying server capacity; Fargate is integrated with ECS.
ECS on EC2 Specialized instance types, host-level tuning or predictable host utilization ECS container instances, Docker hosts, patching and capacity You must operate the EC2 container hosts.
Lambda container image Short, event-driven browser jobs Function configuration, triggers and the Lambda runtime constraints It is an alternative for jobs, not the default shape for a persistent Playwright service; verify current Lambda limits for your region and runtime.

A private worker task with controlled outbound access is generally safer than exposing a Playwright server publicly. If a browser service must accept inbound requests, add strong authentication, narrow ingress rules and rate limits.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prerequisites and version pinning

  • An AWS account with permission to create an ECR repository, ECS resources, IAM roles, networking and log groups.
  • Docker and the AWS CLI installed locally, with credentials configured for the target account and region.
  • A Node.js application whose playwright dependency is pinned to an exact version.
  • A decision about whether the container will run one browser per task or several contexts/workers. Memory pressure and crash rates increase as concurrency rises.

Playwright’s official container image includes browser binaries and system dependencies, but the Playwright package still has to be installed in your application. Keep the image tag and npm package on the same version so the package can discover the browser executables. The documentation lists tags such as v1.63.0-noble; use a specific tag rather than latest, and update both values together after testing.

Use a glibc-based image

Start with the documented Ubuntu-based Playwright image or another supported glibc-based base image. Alpine is not supported for the documented Firefox and WebKit builds because those browser builds require glibc. If you build from a Node image instead, install the exact Playwright package and browser dependencies explicitly.

Build a version-matched image

The following Dockerfile uses the official image and installs the matching package. Put Playwright in dependencies, not only in development dependencies, when the container runs browser code in production.

FROM mcr.microsoft.com/playwright:v1.63.0-noble

WORKDIR /app
COPY package*.json ./
RUN npm ci --omit=dev
COPY . .

# The official image provides the pwuser account.
RUN chown -R pwuser:pwuser /app
USER pwuser

CMD ["node", "worker.js"]

Your package.json and lockfile should resolve [email protected] to match the image tag. If you choose a plain Node base image, install the same package version and run the Playwright browser installation command with system dependencies during the image build; do not assume that a browser is present just because the npm package is installed.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep the container contract simple

  • Have the process log useful progress and errors to standard output and standard error so ECS can forward them.
  • Exit non-zero on a failed job so an ECS service can replace an unhealthy task.
  • Expose a port only when the process is an HTTP or Playwright server. A one-shot worker does not need a public port.
  • Record the Playwright package version and image digest in deployment metadata.

Test safely with Docker before AWS

Build and run the image locally before creating the ECS task:

docker build -t playwright:1.63.0 .
docker run --rm --init --ipc=host playwright:1.63.0

Playwright recommends Docker’s --init option so child processes are reaped correctly. For Chromium, --ipc=host is recommended because the default shared-memory setting can cause Chromium to run out of memory and crash. In ECS, translate the process and shared-memory requirements into options supported by your task definition and launch type; a local Docker flag is not automatically a production configuration.

Run browser tests against representative pages and concurrency levels. A container that succeeds with one context can fail when several Chromium processes share the same task memory.

Push the image to Amazon ECR

Create a private repository, authenticate Docker to the regional registry, tag the image with the complete repository URI, and push it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
REGION=us-east-1
ACCOUNT_ID=123456789012
REPOSITORY=playwright
IMAGE="$ACCOUNT_ID.dkr.ecr.$REGION.amazonaws.com/$REPOSITORY:1.63.0"

aws ecr create-repository --repository-name "$REPOSITORY" --region "$REGION"
aws ecr get-login-password --region "$REGION" | docker login --username AWS --password-stdin "$ACCOUNT_ID.dkr.ecr.$REGION.amazonaws.com"
docker build -t playwright:1.63.0 .
docker tag playwright:1.63.0 "$IMAGE"
docker push "$IMAGE"

The image value in ECS must be the full account.dkr.ecr.region.amazonaws.com/repository:tag name. A short local name such as playwright:1.63.0 cannot be pulled by ECS.

Give ECS the right IAM roles

Task execution role

The ECS task execution role is used by the ECS agent to pull a private ECR image and publish configured logs. For ECR image pulls, it needs these actions:

  • ecr:GetAuthorizationToken
  • ecr:BatchGetImage
  • ecr:GetDownloadUrlForLayer

Attach the role to the task definition as executionRoleArn. Fargate uses this ECS task execution role to pull from ECR. With the EC2 launch type, the container-instance role is involved in pulling images.

Application task role

Use a separate taskRoleArn for permissions needed by your application, such as reading a queue or writing results. Grant only the actions and resources the browser worker actually needs. Do not put application permissions on the execution role merely because both roles appear in the same task definition.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Register an ECS task definition

A task definition should specify the complete image URI, CPU and memory appropriate for your measured browser workload, logging, networking assumptions and (only for a service) a port mapping. This fragment shows the important shape; the CPU and memory values are an illustrative starting point, not a universal Playwright benchmark.

{
  "family": "playwright-worker",
  "requiresCompatibilities": ["FARGATE"],
  "networkMode": "awsvpc",
  "cpu": "1024",
  "memory": "2048",
  "executionRoleArn": "arn:aws:iam::ACCOUNT_ID:role/ecsTaskExecutionRole",
  "taskRoleArn": "arn:aws:iam::ACCOUNT_ID:role/playwrightTaskRole",
  "containerDefinitions": [
    {
      "name": "playwright",
      "image": "ACCOUNT_ID.dkr.ecr.REGION.amazonaws.com/playwright:1.63.0",
      "essential": true,
      "logConfiguration": {
        "logDriver": "awslogs",
        "options": {
          "awslogs-group": "/ecs/playwright",
          "awslogs-region": "REGION",
          "awslogs-stream-prefix": "worker"
        }
      }
    }
  ]
}

Replace the account, region, role names, image URI and log-group values for your account. Register the definition, then create an ECS service for a continuously available worker or run individual tasks for queued jobs. If the container serves HTTP, add a load balancer and a container port; if it only consumes jobs, keep it private and omit inbound exposure.

Networking for browser destinations

Place worker tasks in private subnets when they do not need inbound internet traffic. Provide controlled outbound access through the network design approved for your organization, and allow DNS, HTTPS and any APIs the browser must reach. A private subnet without egress will produce page timeouts that look like Playwright failures.

For a public Playwright endpoint, treat the endpoint as an untrusted-input boundary: authenticate every request, restrict security-group ingress, avoid broad network reachability and set job timeouts. Browsing arbitrary destinations can create SSRF and data-exfiltration risks even when the browser code itself is correct.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a safe browser trust boundary

Running Chromium as root disables its sandbox. For crawling, screenshot services or any other workload that visits untrusted sites, run as a non-root user and apply the seccomp profile with the user-namespace permissions required by Playwright. A root container may be acceptable for tightly controlled end-to-end tests, but it is the wrong default for arbitrary URLs.

Best Value
Docker Container Linux Devops Programming Coding T-Shirt
  • Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
  • Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Keep browser workers isolated from credentials and internal services. Use task roles with least privilege, avoid placing long-lived secrets in the image, and inject only the credentials required for the current job.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Operate and estimate the deployment

Logs and replacement

  • Send stdout and stderr to CloudWatch Logs or an equivalent sink.
  • Include the Playwright version, image tag and image digest in each deployment record.
  • Replace running tasks when the image digest changes; a reused tag alone does not guarantee that every task has the new image.
  • Track page timeouts, browser crashes, task restarts, job duration and memory utilization.

Cost model

There is no universal Playwright-on-AWS price. Estimate Fargate or EC2 compute from task CPU, memory, runtime and concurrency, then add ECR storage, log ingestion and retention, and network egress for the target region. Lambda adds its own invocation and duration model and must be checked against current regional pricing and limits.

Troubleshoot common failures

Symptom Likely cause Correction
“Executable doesn’t exist” or browser launch errors The npm package and image contain different Playwright versions, or the image never installed browsers. Pin the same exact version in the image tag and package; rebuild without relying on a floating tag.
Chromium crashes under load Insufficient shared memory or too many browser processes for the task memory. Use the recommended IPC/shared-memory configuration supported by the ECS launch type, reduce concurrency, or allocate more memory.
ECS cannot pull the image The image URI is incomplete, the execution role lacks ECR actions, or the task has no route to ECR. Use the full regional ECR URI, correct the execution role, and verify subnet routing and egress.
Pages consistently time out The task has no DNS or outbound route, or the destination blocks the task’s egress IP. Test network reachability from the task subnet and confirm the destination’s access policy.
Browser launch fails only for untrusted URLs The container runs as root or lacks the required sandbox/seccomp configuration. Use a non-root user and the Playwright-recommended seccomp settings for untrusted browsing.
Tasks restart without useful evidence Logs are not configured or the process exits without reporting the exception. Configure the awslogs driver, log uncaught errors, and inspect the stopped-task reason.

Or skip the browser setup

If your goal is reliable website screenshots rather than operating Chromium yourself, ScreenshotNeo provides a website screenshot API and MCP server. One GET request returns PNG, JPEG, WebP or PDF output; the service accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets. Each step can be turned off.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Only clean shots are billed. Bot checks and CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing, and the response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server exposes take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.

Example request (see the ScreenshotNeo API documentation):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

There is a free allowance of 1,000 screenshots per month with no card required. Paid plans start at $5 for 3,000 shots, and every feature is included on every plan. Create a free ScreenshotNeo account to try it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.