Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk7 min

How to Run Playwright in Docker on AWS

A practical guide to packaging Playwright in Docker and running it on AWS ECS Fargate, including version matching, task configuration, security, storage, and troubleshooting.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To run Playwright on AWS, build a container with a pinned Playwright package and its matching browser image, then run it as an Amazon ECS task on Fargate. Use a task for finite test runs; use an ECS service when you need a task to stay available or ECS to maintain a desired task count. Fargate requires awsvpc networking and task-level CPU and memory, and it does not support several local Docker settings sometimes used for Chromium, so a working docker run command is not by itself a Fargate deployment recipe.

1. Choose an ECS task or service

Use a task for finite test runs

An ECS task fits a scheduled, triggered, or one-off test batch: start the container, run the suite, send results and artifacts somewhere durable, then stop. Your scheduler or deployment pipeline can start the task when needed.

As an Amazon Associate I earn from qualifying purchases.

Use a service for work that must stay available

An ECS service is the better shape when a worker should remain available or ECS should maintain a desired number of running tasks. A service is not inherently required just because the container runs Playwright. Fargate services can select a platform version; if none is specified, AWS uses LATEST. AWS revises platform versions over time, so include the selected version in deployment maintenance rather than treating it as permanent. See AWS’s Fargate platform-version documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Build a reproducible Playwright image

The Playwright Docker image includes browser binaries and the system dependencies browsers need, but it does not install the Playwright package used by your tests. Install that package separately and keep its version aligned with the image: each Playwright release expects its corresponding browser binaries. Playwright warns that a mismatch can leave the package unable to find the expected browser executable. Pin a specific image version rather than using a floating tag. See Playwright’s Docker guidance and browser installation guidance.

Example project files

Choose an exact Playwright version for your project, then use that same release for the image and the package. The Dockerfile accepts the exact image tag and package version at build time so you do not silently follow a moving tag.

# Dockerfile
ARG PLAYWRIGHT_IMAGE
FROM ${PLAYWRIGHT_IMAGE}

WORKDIR /app
ARG PLAYWRIGHT_VERSION
COPY package.json package-lock.json ./
RUN npm ci
COPY . .
CMD ["npx", "playwright", "test"]

Declare the test package at the same exact version passed at build time. For example, this is the shape of package.json; set 1.x.y to the exact release you selected, not a range:

{
  "private": true,
  "scripts": { "test": "playwright test" },
  "devDependencies": { "@playwright/test": "1.x.y" }
}

Generate and commit the matching lockfile with your package manager, then build while supplying the corresponding official image tag and package version. The exact image tag suffix can depend on the image release you select; copy the tag for that release from Playwright’s Docker documentation. For example, the build command’s form is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
docker build 
  --build-arg PLAYWRIGHT_IMAGE=mcr.microsoft.com/playwright:<matching-image-tag> 
  --build-arg PLAYWRIGHT_VERSION=<matching-version> 
  -t playwright-tests .

Replace both angle-bracket values with the same release’s actual image tag and package version before running the command. The Dockerfile uses the lockfile through npm ci, so the locked dependency tree must include the declared Playwright package.

Minimal test file

For a basic smoke test, put this in tests/home.spec.js:

const { test, expect } = require('@playwright/test');

test('home page responds', async ({ page }) => {
  await page.goto('https://example.com');
  await expect(page).toHaveTitle(/Example Domain/);
});

Then build and run locally before deploying:

docker run --rm playwright-tests

Playwright recommends --init for local Docker use to handle PID 1 process behavior and --ipc=host for Chromium because limited shared memory can cause crashes. Those are local Docker options, not Fargate task settings. If you use them in local testing, do not copy them into an ECS task definition and assume Fargate supports them.

3. Translate the container to Fargate

Create an ECS task definition using the Fargate launch type or capacity provider, with task-level CPU and memory, awsvpc network mode, and your container image and command. Use the AWS-supported CPU/memory combinations in the Fargate task definition reference. Those combinations describe platform limits, not a measured Playwright requirement; start with a modest workload, measure it, and adjust.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fargate does not accept ipcMode, sharedMemorySize, or privileged containers. That means the local --ipc=host advice cannot be converted into a Fargate task-definition option. Test your actual browser workload on Fargate and allocate enough task memory rather than assuming local shared-memory settings are available.

Execution role and application role

Assign an ECS task execution role for operations performed by the ECS agent, such as pulling a private ECR image and delivering logs through the awslogs driver. Give the application a separate task role, and grant it only the AWS API actions the test code actually needs. AWS explains this distinction in its ECS IAM role best practices.

Networking

Because Fargate tasks use awsvpc, configure subnet placement and security groups for the task’s network interface. Allow outbound access required by the sites and services under test, and restrict inbound access unless the workload intentionally exposes a service endpoint. For a task that only runs tests and reports results, avoid opening inbound access unnecessarily.

4. Store logs, results, and browser artifacts

Configure container logging, commonly with the awslogs driver and the task execution role. Test failures are much easier to diagnose when the task’s stdout and stderr are available after it exits. Decide separately how reports, screenshots, downloads, and traces will survive task termination: write them to an appropriate durable destination or publish them before the task stops.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Linux Fargate tasks on platform version 1.4.0 or later have at least 20 GiB of ephemeral storage by default, configurable up to 200 GiB. The compressed and uncompressed image layers use part of that space. Estimate scratch requirements for browser downloads, traces, screenshots, and test output in addition to the image footprint. These are AWS storage limits and defaults, not a guarantee that any particular test suite will fit. Details are in AWS’s Fargate ephemeral-storage documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Secure browser workloads

Playwright’s documentation says its official Docker image is intended for testing and development and is not recommended for visiting untrusted websites. It also notes that running Chromium as root disables Chromium’s sandbox. For untrusted crawling or scraping, Playwright recommends a separate user and a seccomp profile; follow the relevant setup in its Docker documentation.

Fargate’s restrictions on privileged containers and capabilities are not a substitute for application security. Use narrow IAM permissions, limit egress to what the workload needs, protect test credentials, and isolate workloads according to the trust level of the pages they visit. Fargate gives each task dedicated infrastructure capacity and prevents access to the underlying host, but containers within one task share resources and network namespaces; a sidecar in the same task is not an independent isolation boundary. See AWS’s Fargate security considerations.

6. Consider a remote Playwright Server only when it fits

Playwright also documents running a Playwright Server in Docker while tests execute on another machine. This separates the test client from the browser process, but the client and server Playwright versions must match. Treat the server endpoint as a protected service; the cited Playwright guide explains the connection mechanics but does not prescribe an AWS authentication design. See Playwright’s Docker documentation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

7. Troubleshoot common failures

  • Browser executable missing: Check that the installed Playwright package and image use matching pinned releases. The official image does not install your project package for you.
  • Chromium crashes or exits under load: Check task memory and the actual concurrency, downloads, and browser workload. Do not rely on --ipc=host or sharedMemorySize in Fargate; those settings are unsupported there.
  • Task cannot pull its image or deliver logs: Verify the task execution role has the required permissions for the configured image registry and logging destination. Keep those agent operations distinct from the application’s task role.
  • Navigation times out or a test cannot reach a target: Inspect subnet routing and security-group egress, plus any destination-specific access requirements. Fargate’s awsvpc setup needs deliberate network configuration.
  • Artifacts disappear after the run: A stopped task is not a durable artifact store. Export reports, traces, and screenshots before exit, and confirm scratch files fit within available ephemeral storage.
  • Untrusted pages run with excessive access: Revisit the workload’s trust boundary, user and seccomp configuration, egress rules, and IAM scope. Fargate’s platform restrictions alone do not make arbitrary browsing safe.

8. Performance and cost: measure your workload

There is no universal CPU, memory, or concurrency setting for Playwright tests. Measure task duration, browser concurrency, memory pressure, image pulls, and artifact volume with the suite and sites you will actually run. Fargate’s CPU and memory combinations are configuration constraints, not performance guidance. Likewise, the documentation cited here does not establish that Fargate is cheaper than ECS on EC2 or another compute choice; compare current regional prices and your workload’s utilization before deciding.

Or skip the browser setup

If your goal is to capture a website screenshot rather than run browser assertions, ScreenshotNeo offers a screenshot API and MCP server. It is not a replacement for Playwright test execution. One request can return an image or PDF; for example:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation. Cookie banners are accepted and removed before capture, along with known consent platforms, newsletter popups, and chat widgets; bot checks, blank pages, and failed loads are not billed. Its MCP server lets AI agents take screenshots, and 1,000 screenshots a month are free with no card; paid plans start at $5 for 3,000. Sign up for the free plan.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.