Azure deployment

  1. Overview
  2. Prerequisites
  3. Requirements
    1. Hardware Requirements
      1. Postgres Database Sizing
    2. Infrastructure Requirements
  4. Getting Started
    1. Clone the Viya IAC Project
  5. Configuration Setup
  6. Infrastructure Deployment
    1. Docker (Recommended)
  7. Deploy PostgreSQL SSL Certificate
  8. Verify Azure Resources
  9. Next steps
  10. Troubleshooting
    1. Azure Authentication
    2. Cluster Deployment
    3. Helm Deployment Issues

Overview

This guide describes deploying an Azure infrastructure on which to deploy SAS Retrieval Agent Manager.

Complete Get started first. It covers the common prerequisites, tools, and license retrieval for every platform.

Prerequisites

In addition to the common prerequisites:

  • Ability to create resources in Azure
  • A PostgreSQL database server with bidirectional connectivity to the Kubernetes cluster

Requirements

Hardware Requirements

Cluster sizing is platform-independent. Choose a tier and read the resource requirements in Cluster sizing, then use an Azure instance type that meets them.

Example AKS node pool sizes:

Node Size Minimum Nodes Maximum Nodes Deployment Size
Standard_D8s_v6 1 3 Small
Standard_D8s_v6 2 6 Medium
Standard_D16s_v6 2 8 Large

Note: These D-series examples meet the minimum memory requirement. For embedding or vectorization workloads, use a memory-optimized E-series instance instead. See Example instance types.

Postgres Database Sizing

Follow the PostgreSQL sizing recommendations here.

Infrastructure Requirements

  • AKS version: 1.35+

Getting Started

Clone the Viya IAC Project

# Clone the Viya IAC repository
git clone https://github.com/sassoftware/viya4-iac-azure

# Navigate to project directory
cd viya4-iac-azure

Note: While we use the viya-iac repository, a viya license or deployment is not required to use SAS Retrieval Agent Manager. This is a standalone application that can be deployed independently of a Viya environment.

Configuration Setup

Before deploying, you’ll need to create and edit two configuration files with your custom values and place them inside of viya4-iac-azure repository directory:

File Purpose  
terraform.tfvars PostgreSQL name, prefix, and location settings Example
azure.env Azure credentials and environment variables Example

Tip: If you need help obtaining Azure environemnt variables, contact your Azure Cloud Administrator or refer to our Azure Help Guide

Infrastructure Deployment

Use the provided Docker image to deploy the AKS cluster and PostgreSQL database with the Example Terraform Values File. This method ensures a consistent environment and simplifies dependency management.

# Build the Docker image
docker build -t viya4-iac-azure .

# Deploy the cluster
docker run --rm --group-add root \
    --user "$(id -u):$(id -g)" \
    --env-file=azure.env \
    --volume=$HOME/.ssh:/.ssh \
    --volume=$(pwd):/workspace \
    viya4-iac-azure \
    apply -auto-approve \
    -var-file=/workspace/terraform.tfvars \
    -state=/workspace/terraform.tfstate

Deploy PostgreSQL SSL Certificate

If your Azure Database for PostgreSQL Flexible Server requires SSL, you must provide the SSL certificate bundle as a Kubernetes secret. Download the required root CA certificates from Microsoft:

For more details on Azure PostgreSQL TLS configuration, refer to the Microsoft documentation.

Then follow Secure the database connection to convert the certificates, build the cert.pem bundle, and create the Kubernetes secret.

Verify Azure Resources

Run these Azure Command-Line Interface (Azure CLI) commands after the infrastructure deployment.

First, verify the active Azure subscription:

az account show \
    --query "{subscriptionName:name, subscriptionId:id}" \
    --output table

Confirm that this output shows the subscription that contains the deployment.

List the Azure Kubernetes Service (AKS) clusters in the active subscription:

az aks list \
    --query "[].{name:name, resourceGroup:resourceGroup, provisioningState:provisioningState, location:location}" \
    --output table

List the Azure Database for PostgreSQL Flexible Servers in the active subscription:

az postgres flexible-server list \
    --query "[].{name:name, resourceGroup:resourceGroup, state:state, version:version, location:location}" \
    --output table

Use the Name and ResourceGroup columns for subsequent Azure CLI commands. Verify that the expected AKS cluster and PostgreSQL server are in the output. If a resource is not in the output, verify the active subscription and the infrastructure deployment result.

Next steps

  1. Verify the Azure resources.
  2. Install dependencies.
  3. Install and upgrade — deploy the application.

Troubleshooting

Azure Authentication

If you are experiencing authentication errors, ensure the following requirements are met:

  • All values in azure.env are correct and up-to-date
  • Azure service principal has sufficient permissions
  • Subscription ID is valid and accessible
  • Resource group exists and you have contributor access

For debugging authentication issues:

# Test Azure CLI authentication
az account show

# Verify service principal permissions
az role assignment list --assignee <client-id>

Cluster Deployment

If AKS cluster creation fails, consider:

  • Checking Azure region availability for Standard_D16s_v6 or Standard_D8s_v6 nodes
  • Verifying sufficient quota in your Azure subscription
  • Ensuring no naming conflicts with existing resources
  • Confirming network configuration allows cluster communication

Helm Deployment Issues

If the SAS Retrieval Agent Manager deployment fails, ensure the following requirements are met:

  • ram-values.yaml is properly configured for your environment
  • Ingress-Nginx and Kueue dependencies are successfully installed
  • Sufficient resources are available on worker nodes
  • Namespace does not have conflicting resources

For debugging deployment issues:

# Check pod status and logs
kubectl get pods -n retagentmgr
kubectl logs -l app=sas-retrieval-agent-manager -n retagentmgr

# Verify Helm release status
helm status sas-retrieval-agent-manager -n retagentmgr

For additional troubleshooting, refer to the main troubleshooting section


Table of contents