Deploy Argo Workflows
Argo Workflows orchestrates Collate ingestion pipelines. It requires special configuration on OpenShift due to Security Context Constraints. The recommended version is 3.5.4 (Helm chart0.40.8).
Note: Complete Prerequisites before this step to have the OIDC endpoint and S3 bucket values ready.
IAM Roles (ROSA)
Note: This section is ROSA/AWS-specific. On non-AWS OpenShift, skip to Create the Argo Namespace. Configure the
artifactRepository in the Helm values to point at your own S3-compatible store, or disable artifact archiving by setting useDefaultArtifactRepo: false.IRSA for Argo Workflows Controller
The Argo controller needs read/write access to S3 to archive workflow logs.IRSA for Argo Workflows Server
The Argo server needs read-only access to S3 to fetch and display workflow logs in the UI.Create the Argo Namespace
Create Database Credentials Secret
Argo Workflows requires a database for workflow archiving.Grant Required SCCs
OpenShift’s defaultrestricted-v2 SCC prevents Argo system components from running. Grant anyuid to the Argo service accounts before deploying:
Note:
anyuid allows pods to run as any UID including root. This is required for Argo system components only. Collate’s own pods run under restricted-v2 and do not require anyuid.Helm Values (argo-workflows.values.yml)
Deploy
Verify
Optional: Enable Prometheus Metrics
Next Step
Deploy Collate
Create the Collate IAM role, configure ECR credentials, and install Collate with the openmetadata Helm chart.