Requirements for Remote SAS Data Agent

Host Machine

Docker Desktop on Linux

Minimum Requirements

Here are additional requirements to run the container:

  • Basic knowledge of Linux commands is required.
  • The Docker process runs as a user with root privileges. As a result, the user who performs the deployment requires sudoers privileges in order to run many of the required commands.
    Note: Instead of granting sudoers privileges to any user who executes Docker commands, you can create a (UNIX) Docker group on the Docker host machine. Any users that are added to this group have Read/Write/Execute ownership of the Docker process, and are able to execute Docker commands without using sudo. For more information about the Docker group, see https://docs.docker.com/install/linux/linux-postinstall/.

Requirement for Docker SELinux

If Security Enhanced Linux (SELinux) is in use, additional configuration is required to access the directories and files of the remote SAS Data Agent container image. All directories and files on the local file system that are referenced from inside the container must have a security context (or label) that is recognized by the SELinux security policy that is in use. Here are the typical directories and files to label:

  • The /sasdata directory, the /sasdata/data subdirectory, and any other subdirectories such as /sasdata/backup, /sasdata/vault, and /sasdata/pgdata
  • The license file: SAS-SAS-license-file-name.jwt
  • The server certificate, private key, and certificate authority files: list-of-trusted-certificate-authorities.pem, tls-certificate-for-remote-data-agent-server.pem, tls-certificate-for-remote-data-agent-server-private-key.key
  • All directories and files that are referenced in the da-vars.env file
  • All directories and files that are referenced in the sas-access.properties file
  • All directories mounted on the container via the --mount, --sasdata, or --data options
Note: An example of labeling directories and files is provided in Quick Start for Remote SAS Data Agent: Step 7. The method that you use to label the directories and files can be different and are specific to the security policies in use. For more information about SELinux, see Docker SELinux Security Policy and SELinux Contexts – Labeling Files.

Podman on Linux

Minimum Requirements

  • Podman version 4.9.4-rhel or later on Red Hat Enterprise Linux 8.10 and RHEL 9.x and with the podman-docker package installed and configured:
    dnf install podman-docker

    The podman-docker package installs a script that emulates docker commands by using podman commands.

  • An empty file named /etc/containers/nodocker must be created.
    Note: If /etc/containers/nodocker does not exist, the following message is emitted and interferes with the use of SAS Container Manager to download the container image from the SAS repository: Emulate Docker CLI using podman. Create /etc/containers/nodocker to quiet msg.
  • Basic knowledge of Linux commands is required.

Rootless Podman and Running the Container

By default, remote SAS Data Agent runs as container user ID (UID) 1001 and rootless Podman maps that UID to a UID from /etc/subuid. The mapped UID in /etc/subuid requires Read privileges and, in some cases, Write privileges for the directories and files that are accessed by remote SAS Data Agent.

As an alternative, remote SAS Data Agent can run as the user that starts the container. In the following example, the keep-id mode is used to run the container as the current user and to map the current user inside the container to the current user outside the container:

./container-manager --user $(id -u):$(id -g) --userns keep-id

For more information, see Understanding rootless Podman's user namespace modes.

Hardware Requirements

Resource

Minimum Requirement

VMs

1

vCPUs

4 cores

RAM

1–4 GB

The amount of RAM required depends on the workload and the number of concurrent users.

Disk Space

12–15 GB

This value assumes that data is not stored in the file system inside the running container.

Kubernetes

For requirements and instructions to deploy remote SAS Data Agent to a Kubernetes cluster, see Deployment Example: Kubernetes.

Connectivity Requirements

Firewall in Use

To download and install the container image from SAS when a firewall is in use, configure the firewall to enable outbound connections to cr.sas.com on port 443.

Required Connectivity between SAS Viya Platform and Remote SAS Data Agent

Here is a summary of the required network connections between the SAS Viya platform deployment, the remote SAS Data Agent server, and the SAS Viya CLI (sas-viya CLI).

  • The sas-viya CLI must be able to send HTTPS requests to the SAS Viya platform deployment.
  • The services in the SAS Viya platform deployment must be able to send HTTPS requests to the remote SAS Data Agent server.
  • The remote SAS Data Agent server must be able to send HTTPS requests to the SAS Viya platform deployment.
  • The sas-viya CLI must be able to send HTTPS requests to the remote SAS Data Agent server. This is required for the following operations:
    • The sas-viya CLI security credentials --bypass-microservice command that manages the shadow domains credentials.
    • The sas-viya CLI sql --sql command that sends SQL commands to the remote SAS Data Agent server.
    • The sas-viya CLI servers test command that tests whether the remote SAS Data Agent server is running and is reachable by the sas-viya CLI.

All other sas-viya CLI operations are sent to the SAS Viya platform deployment and do not require a network connection between the sas-viya CLI and the remote SAS Data Agent server.

Last updated: September 16, 2026