Use one disposable session boundary
Launch one isolated runtime per browsing session or tenant trust boundary. Give the session a fresh browser profile, writable temporary directory, unique network identity, hard timeout, and no inherited cookies. Do not share one Chrome process across unrelated tenants. Incognito contexts reduce state sharing but are not equivalent to a separate runtime boundary for hostile multi-tenant execution.Preserve the browser sandbox
Playwright’s official guidance warns that its default root container disables Chromium’s sandbox and is not recommended for untrusted websites. Puppeteer’s official image documents a sandbox mode requiringSYS_ADMIN.
Fargate restricts SYS_ADMIN and custom host-level seccomp behavior. That makes the exact secure Chromium sandbox configuration a design gate. Do not silently add --no-sandbox to make production start.
Use a runtime that demonstrably supports the browser sandbox, or place the browser in a stronger microVM/VM boundary. Test the actual kernel, seccomp, user namespaces, image, and browser version.
Restrict network reachability
A URL allowlist is useful but incomplete. Enforce egress at the network layer:- deny instance metadata and link-local addresses,
- deny VPC private ranges unless explicitly required,
- validate every redirect and DNS result,
- route public traffic through an egress proxy,
- log destinations without sensitive query strings,
- block unsupported protocols and raw socket access.
Protect credentials
Keep model credentials in the controller when possible. If the browser needs site credentials, scope them to one session and domain. Separate authenticated browsing from arbitrary open-web browsing. Downloads and clipboard content can exfiltrate secrets.Bound browser behavior
Limit tabs, popups, downloads, total bytes, CPU, memory, session duration, idle duration, navigation time, and output. Upload selected screenshots or traces, then destroy the browser profile.Frequently asked questions
Is a Docker container enough for a browser agent?
Is a Docker container enough for a browser agent?
Not automatically. The browser’s own sandbox must work, network reachability must be restricted, and tenant sessions need strong separation. Containers are one layer in the boundary, not the complete threat model.
Can browser agents use Springwinter Workers today?
Can browser agents use Springwinter Workers today?
Trusted automation can fit a Worker after testing. Hostile multi-tenant browsing needs disposable per-session execution and a verified browser sandbox, which is not a current first-class Springwinter resource.
Why is SSRF still relevant inside an isolated task?
Why is SSRF still relevant inside an isolated task?
The task may still reach metadata, private services, databases, or control-plane endpoints. A compromised page can make the browser request those targets unless egress policy blocks them.