AIToday
Large Language ModelsAI Coding AssistantsZenn AI/MLPublished: Oct 5, 2026, 22:00 JST

AgentCore Browser fails on CodeZip, fixed via /tmp copy

AgentCore Browser fails on CodeZip, fixed via /tmp copy

3 Key Points

  1. What happened

    Testing Amazon Bedrock AgentCore Browser under a CodeZip runtime returned "PermissionError: [Errno 13] Permission denied: '/var/task/playwright/driver/node'", matching AWS notes that the browser tool needs a Container build.

  2. Why it matters

    This means teams running agents on CodeZip cannot use AgentCore Browser out of the box, so the browser option is likely off the table unless they move to a Container build or apply a workaround.

  3. What to watch

    The fix is a workaround, not an official setup, so it hinges on whether copying the Playwright Node driver to /tmp holds up in production; watch whether AWS updates its guidance for CodeZip.

WHO IT HITSDevelopers and platform teams building AI agents on Amazon Bedrock AgentCore Runtime with a CodeZip deployment are the ones affected, since they must either switch to a Container build or apply a manual workaround to use browser-based tools.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

The article sets out to compare three ways an AI agent on Amazon Bedrock AgentCore Runtime can reach web information: AgentCore Browser, a plain HTTP request approach, and AgentCore Web Search. A fourth candidate, running Chromium directly inside the runtime, was dropped early because it requires bundling Chromium and OS libraries, which does not fit the CodeZip format. The author's focus is only on AgentCore Browser.

The central tension is that AgentCore Browser is not meant for the CodeZip deployment style. AWS's own export notes state the browser tool requires a Container build and that the Playwright Node driver cannot run in a CodeZip runtime. The author confirmed this in practice, hitting a permission error on the driver file, and noted how the runtime is laid out: the read-only app files under /var/task, and a writable /tmp area. Copying the driver into /tmp and granting execute permission resolved it.

Once fixed, the tool handled every test the author threw at it, from simple page summaries to a full login flow and a live stock-price lookup. The author's closing read is that AgentCore Browser covers essentially any browser task, but is more than a web-search-only use case needs. A default setup can run into bot-detection CAPTCHAs, which raises the risk of wrong answers, and stricter control means writing more Playwright code. The trade-off is likely to hinge on how much browser control a team actually requires.

FAQ
Why does AgentCore Browser fail on a CodeZip runtime?
AWS's own export notes say the browser tool requires a Container build, and that the Playwright Node driver cannot be executed in a CodeZip (Lambda-style) runtime, so the tool fails at invocation time.
How did the developer get AgentCore Browser working anyway?
The developer copied the Playwright Node driver to /tmp and granted it execute permission, which confirmed AgentCore Browser could be used from a CodeZip runtime.
Did all the browser tests pass after the fix?
Yes. The tool handled general page reads, structured extraction, a JSON API GET request, and clicks and logins. It also answered a free-form SpaceX stock price question, though a CAPTCHA appeared and it fell back to DuckDuckGo.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleStrata runs 125B Qwen3.8-Flash-Next on gaming PCs