Skip to content

Enable the Pipelines API

This section describes how to deploy the Pipelines API and verify an end-to-end dispatch.

Deployed Kubernetes components

When enabled, the pipelines-api chart deploys the following components into the DataRobot namespace:

Component Description
pipelines-api-server (Deployment) API server for pipelines, versions, images, inputs, dispatches, and schedules; runs the dispatch state machine and receives task callbacks.
db-migrate (init container) Runs the database migrations against the pipelines schema before the app container starts.
pipelines-api-service-account (ServiceAccount) The app identity; carries the cloud storage identity and the RBAC to create the Jobs, CronJobs, and Secrets used for dispatch.
pipelines-electron-runner (ServiceAccount) The identity that prep, task, and schedule-trigger pods run as, with the same cloud storage identity as the app ServiceAccount.
pipelines-api-env-config (ConfigMap) All non-sensitive PIPELINES_API_* settings.
pipelines-api-secrets (Secret) The callback signing key; the database password comes from the persistent critical services (PCS) secret.
pipelines-api-app (NetworkPolicy) Optional (networkPolicy.enabled); allows the pod's egress to Postgres, object storage, the Image Build Service, and the authentication service in clusters that enforce network policies.
pipelines-api-ingress (Ingress) Routes /api/v2/pipelines to the Service (an HTTPRoute on Gateway API installs).

Note

The Pipelines API creates dispatch prep Jobs, per-task Jobs, and schedule CronJobs at runtime; the chart provides the RBAC that authorizes the app to create them.

Prerequisites

  • PostgreSQL — the Pipelines API owns a pipelines schema on the platform Postgres. The pipelines database is provisioned as a persistent critical service, and its password is delivered from the in-cluster PCS secret.
  • Object storage — the platform's shared object store (global.filestore): S3 on EKS/OCP, Azure Blob on AKS, GCS on GKE, or an S3-compatible store such as MinIO for air-gapped installs. The Pipelines API uses this store.
  • Image Build Service (IBS) — builds the per-pipeline execution images. Requires a build-context bucket and a container registry the service can push to.
  • Authentication service (Hydra / DRAuth) — issues the service-to-service tokens the Pipelines API uses.

Deploy and enable

Set pipelines-api.enabled: true in the umbrella chart values:

pipelines-api:
  enabled: true

Everything else comes from platform-level values: the container registry that pipeline images are pushed to from global.imageRegistry; object storage and the build-context bucket from global.filestore; Postgres host, port, TLS, and CA from global.postgresql; database credentials from the PCS secret; the build-service URL from a chart default; and the task resource-bundle catalog from a chart-rendered ConfigMap (see Capacity & resources).

Verify the deployment

The 08_pipelines_api post-install check exercises AI Pipelines end to end—it builds a pipeline image, uploads and dispatches a minimal pipeline, waits for the dispatch to reach COMPLETED, and cleans up the pipeline and image afterward. A skip means the Pipelines API is not enabled on the cluster, a pass confirms the end-to-end dispatch path, and a fail indicates a deployment problem.

You can also confirm the service is healthy manually:

  • The pipelines-api-server pods are Running and GET /health returns 200.
  • The db-migrate init container completed and the pipelines schema is present.

To validate from a user's perspective, author and dispatch a pipeline as a user would (through the DataRobot SDK or UI) and confirm the dispatch reaches COMPLETED.