Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a Lambda container image that matches your Python runtime and CPU architecture, and package Selenium, a compatible Chrome/Chromium binary, ChromeDriver, and native libraries together. For Python 3.12 and newer, AWS Lambda Python base images use Amazon Linux 2023 (AL2023); Python 3.11 uses Amazon Linux 2 (AL2). That distinction changes package-manager commands and available libraries. Build and test the complete browser stack locally before deploying.

Choose the Lambda runtime, base image and architecture first

AWS offers three practical image paths: an AWS language base image, an AWS OS-only image, or a non-AWS base image. The language image already includes the Python runtime and Lambda Runtime Interface Client (RIC). An OS-only or non-AWS image must include the runtime and, for Lambda compatibility, the Python RIC as AWS documents at AWS’s container-image guide.

Lambda choice What you get What you must manage
AWS Python language image Python runtime, Lambda interface, AWS-supported base Selenium, browser, driver and native libraries
AWS OS-only image AWS operating-system base Python runtime, RIC, Selenium, browser, driver and libraries
Non-AWS image Maximum operating-system control Everything needed for Lambda invocation and the browser stack

Select the function architecture at the same time. Build for linux/amd64 or linux/arm64; the browser and driver must be compiled for that same architecture. A binary copied from a developer laptop is not a valid assumption.

AL2023 versus AL2 commands

  • Python 3.12 and later Lambda base images use AL2023 minimal images. Use microdnf, also available as dnf, rather than yum.
  • Python 3.11 uses AL2. Follow AL2 package names and yum-based instructions.
  • AL2023 has library differences, including a newer glibc baseline. Test every native dependency in the target image.

See the AWS runtime overview for the distinction between deployment models and runtimes: Lambda runtimes. AWS’s AL2023 background is at Using AL2023 in AWS Lambda.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build a reproducible container image

Pin Selenium in your application, obtain Chrome or Chromium and ChromeDriver from a current authoritative release source during the build, and assert that the browser and driver versions and architectures match. Do not hard-code an unverified release URL: Chrome for Testing release metadata changes, and the correct download differs between amd64 and arm64.

Example application code

This handler explicitly points Selenium at the binaries installed in the image and uses headless mode. It writes temporary browser data under /tmp, the writable area available to a Lambda execution environment.

import os
from selenium import webdriver
from selenium.webdriver.chrome.options import Options
from selenium.webdriver.chrome.service import Service

def lambda_handler(event, context):
    options = Options()
    options.binary_location = os.environ.get("CHROME_BINARY", "/opt/chrome/chrome")
    options.add_argument("--headless=new")
    options.add_argument("--no-sandbox")
    options.add_argument("--disable-dev-shm-usage")
    options.add_argument("--disable-gpu")
    options.add_argument("--user-data-dir=/tmp/selenium-profile")
    options.add_argument("--window-size=1280,900")
    service = Service(os.environ.get("CHROMEDRIVER", "/opt/chromedriver/chromedriver"))
    driver = webdriver.Chrome(service=service, options=options)
    try:
        driver.get(event.get("url", "https://example.com"))
        return {"statusCode": 200, "title": driver.title, "url": driver.current_url}
    finally:
        driver.quit()

Place selenium in a pinned requirements.txt, install it in the image, and set executable permissions on both browser files. Install every shared library required by the selected browser in the image rather than discovering missing libraries only after deployment.

Dockerfile pattern

The exact browser package and download commands depend on the current release and architecture, so treat this as a structure to complete with verified, matching artifacts:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
FROM public.ecr.aws/lambda/python:3.12

COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt --target "${LAMBDA_TASK_ROOT}"

# Install AL2023 libraries with dnf/microdnf.
# Copy a verified AL2023-compatible Chrome/Chromium and ChromeDriver pair.
COPY chrome /opt/chrome/chrome
COPY chromedriver /opt/chromedriver/chromedriver
RUN chmod +x /opt/chrome/chrome /opt/chromedriver/chromedriver

COPY app.py ${LAMBDA_TASK_ROOT}/app.py
CMD ["app.lambda_handler"]

If you choose a non-AWS image, add awslambdaric and configure its entry point as AWS describes. Keep browser profiles, caches and downloaded files under writable paths such as /tmp; the image filesystem is not a general-purpose writable disk.

Keep Chrome and ChromeDriver compatible

Modern Selenium bindings include Selenium Manager. When a driver is missing, Selenium can invoke Manager to locate or download a driver, as described in the Selenium Manager documentation and Python API documentation. That convenience does not prove that downloads will succeed during every Lambda cold start: outbound network access, DNS, permissions, cache persistence and native libraries vary by deployment.

For predictable production behavior, package a pinned browser and matching driver in the image. During the image build:

  1. Resolve the browser release from the current authoritative release metadata.
  2. Download the artifact for the image architecture.
  3. Download the corresponding driver for that same release and architecture.
  4. Run chrome --version and chromedriver --version; fail the build if the expected versions do not match.
  5. Run a real navigation smoke test, not just an import test.

Build and test for Lambda locally

  1. Build with the target platform, for example docker buildx build --platform linux/amd64 -t selenium-lambda . (use linux/arm64 for an ARM function).
  2. Start the image with AWS’s documented Lambda Runtime Interface Emulator workflow.
  3. Invoke the local endpoint with a JSON event containing a controlled URL.
  4. Confirm that Chrome starts, the page loads, the title is returned and driver.quit() runs.
  5. Repeat with the same memory, timeout and architecture settings planned for Lambda.

A successful import only proves that Python can load Selenium. End-to-end navigation catches missing ELF libraries, wrong architecture, incompatible driver versions, unwritable profiles, sandbox restrictions and insufficient timeout.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Lambda settings that affect browser reliability

Memory and timeout

Browser startup and page rendering are resource-intensive relative to a simple Python handler. Set a timeout long enough for cold start, browser startup and navigation, then measure your own workload. No authoritative Selenium-on-Lambda benchmark establishes a universal value, so avoid copying an arbitrary number.

Temporary storage and reuse

Use /tmp for profiles, downloads and screenshots. An execution environment may be reused, so clear per-request state or use a unique directory. Never assume that a cache exists on the next invocation.

Networking

If the function is attached to a VPC, verify DNS and outbound access to the target site and any package or driver endpoint. A runtime download that works locally can fail in a private subnet. This is one reason an image containing the browser stack is more reproducible.

Troubleshooting

“Unable to obtain driver” or Selenium Manager download errors

Cause: the driver is absent and the function cannot reach or cache Selenium Manager’s download. Fix: package a verified driver in the image, set Service to its path, or explicitly validate network, permissions and cache behavior in the deployed configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Exec format error”

Cause: an ARM image contains an x86 binary, or the reverse. Fix: rebuild with the Lambda platform and download browser and driver artifacts for that architecture.

Chrome exits immediately or reports a missing shared library

Cause: a native library is absent or incompatible with AL2/AL2023. Fix: install the required libraries in the selected base image, inspect the binary’s dependencies during the build, and run the same smoke test locally.

“DevToolsActivePort file doesn’t exist”

Cause: a profile path is unwritable, shared between concurrent processes, or the browser cannot start in the container. Fix: use a unique --user-data-dir under /tmp, include headless flags, and ensure only one driver uses that profile.

Timeouts and blank pages

Cause: slow navigation, blocked outbound traffic, bot checks or a page that requires more browser time. Fix: set explicit Selenium page-load and script timeouts, wait for a meaningful element, log the final URL and browser console where available, and test the target from the Lambda network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

ScreenshotNeo provides a website screenshot API and MCP server, so you can request a screenshot without packaging Chrome, ChromeDriver or Linux libraries. Before capture it accepts cookie/consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed; response headers identify the page verdict and billing status. Its MCP tools—take_screenshot, get_page_info and capture_pdf—work with Claude, Cursor and other MCP clients.

One GET request is enough:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

See the ScreenshotNeo documentation for options including full-page and element capture, device and retina settings, PDFs, custom CSS or JavaScript, waits, request blocking, cookies, headers, geolocation, caching, signed links, asynchronous jobs and bulk capture. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

FAQ

Can I use a ZIP deployment instead?

A ZIP can work for suitable dependency bundles, but there is no universal browser-size or compatibility procedure. A container image is the more practical packaging path for a complete browser stack.

Should I use AL2 or AL2023?

Use the base image that corresponds to your selected Lambda Python runtime: Python 3.11 is AL2; Python 3.12 and later are AL2023. Do not mix installation instructions between them.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is Selenium Manager forbidden on Lambda?

No. It may simplify driver management, but you must validate downloads, cache behavior and network access in your actual function. Packaging matched binaries removes that runtime dependency.

Frequently Asked Questions

What must match besides the Chrome version?

The browser, ChromeDriver, Linux userspace libraries and CPU architecture must all be compatible with the Lambda image.

Why does a local Selenium test pass while Lambda fails?

Lambda may use a different architecture, base image, filesystem permissions, network path or cold-start cache. Test the complete container through the Lambda local invocation flow.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.