Package matching browser versions
Pin Puppeteer and the browser together. The official Puppeteer image includes Chrome for Testing and required libraries, but its documented sandboxed mode requires theSYS_ADMIN Linux capability.
AWS Fargate does not allow adding SYS_ADMIN. Running Chrome with --no-sandbox removes an important security boundary and is not appropriate for hostile pages or multi-tenant browsing.
For trusted internal pages, build and test a dedicated image. For untrusted sites, use a browser platform with a supported sandbox or a stronger isolated runtime.
Worker process model
Use one long-lived Node.js process, a bounded browser pool, and a strict maximum number of pages per browser. Recycle browsers after a job count, memory threshold, crash, or timeout. Each job should:- Validate the URL and operation.
- Enforce an allowlist when possible.
- Create a fresh incognito browser context.
- Set navigation, request, and total job timeouts.
- Block unnecessary downloads and resource types.
- Upload output to S3.
- Close the page and context in
finally. - Restart the browser after any uncertain failure.
Deploy as a Springwinter Worker
Select a memory size based on concurrent pages, not only Node.js heap use. Chrome uses multiple child processes and shared memory outside V8. Begin with one browser and one page per container, then measure. Send structured logs to stdout. Record target hostname, duration, browser exit code, timeout category, output size, and memory pressure without logging sensitive page content.Shutdown behavior
When the Worker receivesSIGTERM, stop accepting jobs, close pages and browser processes, and leave unfinished queue messages unacknowledged. Use an init process in the image when supported so orphaned Chrome children are reaped.
Frequently asked questions
Can Puppeteer run on AWS Fargate?
Can Puppeteer run on AWS Fargate?
Headless Chrome can run on Fargate, but the secure sandbox configuration is the key constraint. Fargate cannot add
SYS_ADMIN, while disabling Chrome’s sandbox weakens isolation. Test the exact browser, image, flags, and threat model.Why does Puppeteer consume so much memory?
Why does Puppeteer consume so much memory?
Chrome uses several processes for browser, renderer, network, and utility work. Multiple pages, large images, PDFs, JavaScript-heavy sites, and leaked contexts increase memory beyond the Node.js heap.
Should one browser handle every job forever?
Should one browser handle every job forever?
No. Reuse can improve latency, but browsers accumulate state and may leak resources. Recycle after bounded use and create a fresh isolated context for each job.