Enable the Pipelines API¶
This section describes how to deploy the Pipelines API and verify an end-to-end dispatch.
Deployed Kubernetes components¶
When enabled, the pipelines-api chart deploys the following components into the DataRobot namespace:
| Component | Description |
|---|---|
pipelines-api-server (Deployment) |
API server for pipelines, versions, images, inputs, dispatches, and schedules; runs the dispatch state machine and receives task callbacks. |
db-migrate (init container) |
Runs the database migrations against the pipelines schema before the app container starts. |
pipelines-api-service-account (ServiceAccount) |
The app identity; carries the cloud storage identity and the RBAC to create the Jobs, CronJobs, and Secrets used for dispatch. |
pipelines-electron-runner (ServiceAccount) |
The identity that prep, task, and schedule-trigger pods run as, with the same cloud storage identity as the app ServiceAccount. |
pipelines-api-env-config (ConfigMap) |
All non-sensitive PIPELINES_API_* settings. |
pipelines-api-secrets (Secret) |
The callback signing key; the database password comes from the persistent critical services (PCS) secret. |
pipelines-api-app (NetworkPolicy) |
Optional (networkPolicy.enabled); allows the pod's egress to Postgres, object storage, the Image Build Service, and the authentication service in clusters that enforce network policies. |
pipelines-api-ingress (Ingress) |
Routes /api/v2/pipelines to the Service (an HTTPRoute on Gateway API installs). |
Note
The Pipelines API creates dispatch prep Jobs, per-task Jobs, and schedule CronJobs at runtime; the chart provides the RBAC that authorizes the app to create them.
Prerequisites¶
- PostgreSQL — the Pipelines API owns a
pipelinesschema on the platform Postgres. Thepipelinesdatabase is provisioned as a persistent critical service, and its password is delivered from the in-cluster PCS secret. - Object storage — the platform's shared object store (
global.filestore): S3 on EKS/OCP, Azure Blob on AKS, GCS on GKE, or an S3-compatible store such as MinIO for air-gapped installs. The Pipelines API uses this store. - Image Build Service (IBS) — builds the per-pipeline execution images. Requires a build-context bucket and a container registry the service can push to.
- Authentication service (Hydra / DRAuth) — issues the service-to-service tokens the Pipelines API uses.
Deploy and enable¶
Set pipelines-api.enabled: true in the umbrella chart values:
pipelines-api:
enabled: true
Everything else comes from platform-level values: the container registry that pipeline images are pushed to from global.imageRegistry; object storage and the build-context bucket from global.filestore; Postgres host, port, TLS, and CA from global.postgresql; database credentials from the PCS secret; the build-service URL from a chart default; and the task resource-bundle catalog from a chart-rendered ConfigMap (see Capacity & resources).
Verify the deployment¶
The 08_pipelines_api post-install check exercises AI Pipelines end to end—it builds a pipeline image, uploads and dispatches a minimal pipeline, waits for the dispatch to reach COMPLETED, and cleans up the pipeline and image afterward. A skip means the Pipelines API is not enabled on the cluster, a pass confirms the end-to-end dispatch path, and a fail indicates a deployment problem.
You can also confirm the service is healthy manually:
- The
pipelines-api-serverpods areRunningandGET /healthreturns200. - The
db-migrateinit container completed and thepipelinesschema is present.
To validate from a user's perspective, author and dispatch a pipeline as a user would (through the DataRobot SDK or UI) and confirm the dispatch reaches COMPLETED.