Azure deployment
- Overview
- Prerequisites
- Requirements
- Getting Started
- Configuration Setup
- Infrastructure Deployment
- Deploy PostgreSQL SSL Certificate
- Verify Azure Resources
- Next steps
- Troubleshooting
Overview
This guide describes deploying an Azure infrastructure on which to deploy SAS Retrieval Agent Manager.
Complete Get started first. It covers the common prerequisites, tools, and license retrieval for every platform.
Prerequisites
In addition to the common prerequisites:
- Ability to create resources in Azure
- A PostgreSQL database server with bidirectional connectivity to the Kubernetes cluster
Requirements
Hardware Requirements
Cluster sizing is platform-independent. Choose a tier and read the resource requirements in Cluster sizing, then use an Azure instance type that meets them.
Example AKS node pool sizes:
| Node Size | Minimum Nodes | Maximum Nodes | Deployment Size |
|---|---|---|---|
| Standard_D8s_v6 | 1 | 3 | Small |
| Standard_D8s_v6 | 2 | 6 | Medium |
| Standard_D16s_v6 | 2 | 8 | Large |
Note: These
D-series examples meet the minimum memory requirement. For embedding or vectorization workloads, use a memory-optimizedE-series instance instead. See Example instance types.
Postgres Database Sizing
Follow the PostgreSQL sizing recommendations here.
Infrastructure Requirements
- AKS version: 1.35+
Getting Started
Clone the Viya IAC Project
# Clone the Viya IAC repository
git clone https://github.com/sassoftware/viya4-iac-azure
# Navigate to project directory
cd viya4-iac-azure
Note: While we use the viya-iac repository, a viya license or deployment is not required to use SAS Retrieval Agent Manager. This is a standalone application that can be deployed independently of a Viya environment.
Configuration Setup
Before deploying, you’ll need to create and edit two configuration files with your custom values and place them inside of viya4-iac-azure repository directory:
| File | Purpose | |
|---|---|---|
terraform.tfvars | PostgreSQL name, prefix, and location settings | Example |
azure.env | Azure credentials and environment variables | Example |
Tip: If you need help obtaining Azure environemnt variables, contact your Azure Cloud Administrator or refer to our Azure Help Guide
Infrastructure Deployment
Docker (Recommended)
Use the provided Docker image to deploy the AKS cluster and PostgreSQL database with the Example Terraform Values File. This method ensures a consistent environment and simplifies dependency management.
# Build the Docker image
docker build -t viya4-iac-azure .
# Deploy the cluster
docker run --rm --group-add root \
--user "$(id -u):$(id -g)" \
--env-file=azure.env \
--volume=$HOME/.ssh:/.ssh \
--volume=$(pwd):/workspace \
viya4-iac-azure \
apply -auto-approve \
-var-file=/workspace/terraform.tfvars \
-state=/workspace/terraform.tfstate
Deploy PostgreSQL SSL Certificate
If your Azure Database for PostgreSQL Flexible Server requires SSL, you must provide the SSL certificate bundle as a Kubernetes secret. Download the required root CA certificates from Microsoft:
For more details on Azure PostgreSQL TLS configuration, refer to the Microsoft documentation.
Then follow Secure the database connection to convert the certificates, build the cert.pem bundle, and create the Kubernetes secret.
Verify Azure Resources
Run these Azure Command-Line Interface (Azure CLI) commands after the infrastructure deployment.
First, verify the active Azure subscription:
az account show \
--query "{subscriptionName:name, subscriptionId:id}" \
--output table
Confirm that this output shows the subscription that contains the deployment.
List the Azure Kubernetes Service (AKS) clusters in the active subscription:
az aks list \
--query "[].{name:name, resourceGroup:resourceGroup, provisioningState:provisioningState, location:location}" \
--output table
List the Azure Database for PostgreSQL Flexible Servers in the active subscription:
az postgres flexible-server list \
--query "[].{name:name, resourceGroup:resourceGroup, state:state, version:version, location:location}" \
--output table
Use the Name and ResourceGroup columns for subsequent Azure CLI commands. Verify that the expected AKS cluster and PostgreSQL server are in the output. If a resource is not in the output, verify the active subscription and the infrastructure deployment result.
Next steps
- Verify the Azure resources.
- Install dependencies.
- Install and upgrade — deploy the application.
Troubleshooting
Azure Authentication
If you are experiencing authentication errors, ensure the following requirements are met:
- All values in
azure.envare correct and up-to-date - Azure service principal has sufficient permissions
- Subscription ID is valid and accessible
- Resource group exists and you have contributor access
For debugging authentication issues:
# Test Azure CLI authentication
az account show
# Verify service principal permissions
az role assignment list --assignee <client-id>
Cluster Deployment
If AKS cluster creation fails, consider:
- Checking Azure region availability for Standard_D16s_v6 or Standard_D8s_v6 nodes
- Verifying sufficient quota in your Azure subscription
- Ensuring no naming conflicts with existing resources
- Confirming network configuration allows cluster communication
Helm Deployment Issues
If the SAS Retrieval Agent Manager deployment fails, ensure the following requirements are met:
ram-values.yamlis properly configured for your environment- Ingress-Nginx and Kueue dependencies are successfully installed
- Sufficient resources are available on worker nodes
- Namespace does not have conflicting resources
For debugging deployment issues:
# Check pod status and logs
kubectl get pods -n retagentmgr
kubectl logs -l app=sas-retrieval-agent-manager -n retagentmgr
# Verify Helm release status
helm status sas-retrieval-agent-manager -n retagentmgr
For additional troubleshooting, refer to the main troubleshooting section