SAS Cloud Analytic Services: Reference

Configuration File Options

How Do I Use CAS Configuration File Options?

During CAS server start-up, the controller shares the configuration as each worker and the backup controller (if present) connect. All the CAS configuration files are located in /cas/config directory.

For more information, see Standard Configuration Files.

For the order of precedence for server configuration options, see How the Session Option Values Are Determined in SAS Cloud Analytic Services: User’s Guide .

When a session starts, session options that are specified in the casconfig files are set for the session. For the order of precedence for session options that are specified in the casconfig files, see Server Configuration Files.

You can override CAS configuration file settings for a session by changing the equivalent session option. For more information, see Setting Session Options in SAS Cloud Analytic Services: User’s Guide.

Configuration File Options Reference

Note:
  • All the CAS configuration instances are disabled by default, which means that processing is not enabled for any modifications to the configuration instances in SAS Environment Manager. To allow the SAS administrator to modify the scripts in the configuration instances, set SAS_ALLOW_ADMIN_SCRIPTS to TRUE in the sas-shared-config configMap. For more information, see the README file at $deploy/sas-bases/overlays/sas-programming-environment/README.md (Markdown format) or $deploy/sas-bases/docs/sas-programming-environment-configuration-tasks.htm (HTML format).
  • Other security-related configuration file options can be found in Configuration File Options for Parallel Data Transfer in SAS Viya Platform Encryption: Data in Motion. To modify or set these options, see Edit Configuration Instances.

cas.APPTAG='tag-string'

specifies a string that is included in the JSON log line of some CAS log messages on the CAS server.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategorySession
DefaultNo tag-string
NoteThe CAS server uses apptag when writing to its log.
See cas.LOGCFGLOC
Example
apptag='my_app'

cas.AZUREAUTHCACHELOC="path"

specifies a location that is used to cache login information for connecting to an Azure storage system. This option can be used with device code authentication and it is optional.

Edit sas.cas.instance.config: config instance to set the path.

CategoryData

cas.AZURETENANTID="string"

specifies the tenant ID for connecting to an Azure storage system. The maximum length of the value is 64 bytes. Only alphanumeric characters and the hyphen character (-) are supported.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryData
RequirementCAS server configuration option cas.AZURETENANTID= or session option AZURETENANTID= is required for a Microsoft Azure storage system if your SAS Viya platform deployment is not configured for single sign-on using the OpenID Connect (OIDC) authentication protocol with Microsoft Entra ID. For more information, see SAS Viya Platform: Authentication.

cas.CMPOPT='optimization-value <optimization-value <...>>' | 'all' | 'none'

specifies the type of code generation optimizations to use in the SAS language compiler.

  • optimization-value

    specifies the type of optimization that the SAS compiler is to use. Specify one or more of the following as a space-delimited list enclosed in quotation marks:

    • 'dumptkgcode' | 'nodumptkgcode'

      specifies whether all CAS server nodes create an output file with the generated program. The CAS log lists where CAS writes the output file.

    • 'extramath' | 'noextramath'

      specifies whether the compiler is to retain or remove the extra mathematical operations that do not affect the outcome of a statement.

    • 'funcdifferencing' | 'nofuncdifferencing'

      specify funcdifferencing to calculate numeric-differencing derivatives for user-defined functions. Specify nofuncdifferencing to calculate analytic derivatives for user-defined functions.

    • 'guardcheck' | 'noguardcheck'

      specifies whether the compiler checks for array boundary problems.

      Note: noguardcheck is set when cmpopt is set to 'all' or 'none'.
    • 'misscheck' | 'nomisscheck'

      specifies whether to check for missing values in the data.

    • 'precise' | 'noprecise'

      specify precise to handle exceptions at the operation boundary. Specify noprecise to handle exceptions at the statement boundary.

  • 'all'

    specifies that the compiler is to optimize the machine language code by using the noextramath, nomisscheck, noprecise, noguardcheck, and nofuncdifferencing optimization values.

    Note: 'all' cannot be specified with other values.
  • 'none'

    specifies that the compiler is not set to optimize the machine language code by using the extramath, misscheck, precise, noguardcheck, and funcdifferencing optimization values.

    Note: 'none' cannot be specified with other values.
Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryAction
Defaultnoextramath, nofuncdifferencing, noguardcheck, nomisscheck, and noprecise
NoteIf the data contains a significant amount of missing data, specify misscheck to optimize the compilation. Otherwise, specify nomisscheck.
Example In this example, the SAS compiler is set to retain the extra mathematical operations, check for missing values, and handle exceptions at an operation boundary:
cas.cmpopt='extramath misscheck precise'

cas.COLLATE='mva' | 'uca'

specifies the collating sequence for sorting.

mva specifies SAS client collating. uca specifies a locale-appropriate collating sequence.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategorySort
Default'uca'
Example
cas.collate='mva'

cas.DATASTEPFMTERR=true | false

corresponds to the FMTERR in SAS. Specifies how the DATA step reacts when a format is not available. When true, the DATA step writes an error and stops. When false, the DATA step uses $w. or BEST12. instead of the unavailable format. (The unavailable format is still associated with variables in the output table.)

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryDATA Step
AliasFMTERR
DefaultTrue
NoteThe values true and false are case sensitive.
SeeFMTERR System Option
Example In this example, the DATA step uses $w. or BEST12. instead of the unavailable format.
cas.datastepfmterr=false

cas.DATASTEPMSGSUMLEVEL='all' | 'none' | 'put'

specifies the DATA step message summary level. When the DATA step runs on multiple threads, the same message can be generated on each thread. This option controls the summary level of duplicate messages.

  • 'all'

    The first occurrence of all message and put statements are sent to the client when they occur. Duplicate occurrences of all message and put statements are summarized and sent to the client when the DATA step exits. This is the default.

  • 'none'

    All message and put statements from every thread are written to the client log. No summarization occurs.

  • 'put'

    The first occurrence of all message and put statements are sent to the client. Duplicate occurrences of messages are summarized and sent to the client when the DATA step exits. Put statements are not summarized; rather, they are sent to the client when they occur.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryDATA Step
DefaultAll
ExampleIn this example, all message and put statements from every thread are written to the client log. No summarization occurs.
cas.datastepmsgsumlevel='none'

cas.DATASTEPREPLACETABLE=true | false

specifies whether a DATA step can replace an existing table.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryDATA Step
Defaulttrue
NoteThe values true and false are case sensitive.
Example
cas.datastepreplacetable=true

cas.DATASTEPMERGENOBY=‘ERROR’ | ‘NOWARN’ | ‘WARN’

specifies the dataStepMergeNoBy parameter. When a merge is run with no BY statement, this parameter determines whether no warning, a warning, or an error message is generated.

  • ERROR

    specifies that, when there is no BY statement, the merge does not run, and an error message is generated.

  • NOWARN

    specifies that, when there is no BY statement, the merge runs with no warning messages.

  • WARN

    specifies that, when there is no BY statement, the merge runs with warning messages.

Valid inCAS statement SESSOPTS option
CategoryDATA Step
DefaultNOWARN
Examplecas.dataStepMergeNoBy=‘WARN’

cas.DCHOSTNAMERESOLUTION= '[ ep | ep_fqdn | cas | cas_ipv6 ]'

specifies how CAS sends the CAS node machine name to SAS Embedded Process. cas.DCHOSTNAMERESOLUTION is valid for any data store that supports SAS Embedded Process.

  • 'ep'

    Send CAS node machine names to SAS Embedded Process exactly how they are defined in cas.hosts. SAS Embedded Process resolves the names using either IPv4 or IPv6.

  • 'ep_fqdn'

    Send CAS node machine names to SAS Embedded Process as fully qualified domain names. SAS Embedded Process resolves the names.

  • 'cas'

    (Default) send CAS node machine names to SAS Embedded Process as IPv4 addresses.

  • 'cas_ipv6'

    Send CAS node machine names to SAS Embedded Process as either IPv4 or IPv6 addresses.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryNetwork
Default'cas'
Example
cas.dchostnameresolution='ep'

cas.DQLOCALE='locale-code'

specifies the default locale to use for data quality (DQ) operations, using the five-letter SAS Quality Knowledge Base (QKB) ISO locale code.

For more information, see QKB Locale ISO Codes.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryData Quality
ExampleIn this example, the default locale for DQ operations is French Canadian:
cas.DQLOCALE='FRCAN'

cas.DQSETUPLOC='QKB-name'

specifies the name of the default SAS Quality Knowledge Base (QKB) to use for data quality (DQ) operations.

QKB-name is the name displayed in Name column in Quality Knowledge Bases in SAS Environment Manager.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryData Quality
Example
cas.DQSETUPLOC='QKB CI 32'

cas.EVENTDS='event-data-set'

specifies one or more event objects that define custom date events.

event-data-set specifies the name of a data set that contains event definitions. You can use a one-level name or a two-level name, such as libref.dataset. When specifying multiple names, separate each name with a space.

Enclose event-data-set in single quotation marks.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryInput Control
Example
cas.eventds='mydataset'

cas.FMTSEARCH='logicalformatlibname logicalformatlibname2 … '

specifies the format search list to be automatically set at session start-up.

Server configuration files can be used to add and promote common format libraries when a server starts. Promotion makes the format libraries available to all sessions.

During session start-up, the cas.FMTSEARCH value is used to generate and execute the setFmtsearch action. The setFmtsearch action specifies the order in which format libraries are searched. Table variables can have a user-defined format association. During table processing, when a user-defined format needs to be applied, CAS searches the list of format libraries established by the setFmtsearch action.

CategoryFormats
Defaultblank
InteractionSpecifying the setServOpt action for format search in startup.lua takes precedence over cas.FMTSEARCH used in casconfig.lua.
NoteThe format library names are logical names known to a session. The names are case insensitive.
Example
cas.fmtsearch='myformatsA myformatsB'

cas.S2FORMATSEARCH="caslib-1.tablename-1 <... caslib-n.tablename-n>"

specifies the format search list for format libraries that have been published to SingleStore for use by the SAS Embedded Process.

  • caslib.tablename

    specifies a caslib and table in a SingleStore database. The table contains a previously published format library. The caslib is required for each table. The caslib and table name cannot contain blank spaces. When specifying multiple tables, separate each caslib.tablename with a space.

This option is valid for the SAS SpeedyStore data connector. In that use case, WHERE expressions and computed columns are processed in the SingleStore database by using the SAS Embedded Process.

If a WHERE expression or computed column includes a user-defined format, you must use the sessionProp.saveFmtLib action to save the format library as a SingleStore database table. Then you must set the S2FORMATSEARCH= session option or cas.S2FORMATSEARCH= server option to list one or more database table names that contain the formats.

Valid inCAS statement SESSOPTS option, CAS configuration file
CategoryFormats
See Standard Configuration Files
Example
cas.s2formatsearch="singlestorelib.myfmtlib"

cas.GCPORT=port

specifies the network port that is used on a distributed server for communication between the controller and its worker nodes.

The commonly configured port is 5580.

Note: It is recommended that the value of this configuration variable is not modified. If the value needs to be changed, the administrator with elevated Kubernetes permissions has to edit the CASDeployment Custom Resource. Make sure to restart the CAS server pod to pick up the changes.
CategoryNetwork
Default0 (random port in the range 32678–61000)
SupportsCAS servers running MPP.
See cas.HTTPPORT and cas.PORT
Example
cas.gcport=5580

cas.HTTPPORT=port | port-range

The port (or range of ports) that SAS Cloud Analytic Services listens to for HTTP communication.

The commonly configured port is 8777.

Note: It is recommended that the value of this configuration variable is not modified. If the value needs to be changed, the administrator with elevated Kubernetes permissions has to edit the CASDeployment Custom Resource. Make sure to restart the CAS server pod to pick up the changes.
CategoryNetwork
Default0 (random port)
NoteIf the first port in the range is already taken, CAS tries the next port until it finds a port that is free.
See cas.HTTPPORTMAX , cas.GCPORT , and cas.PORT
Examples
cas.httpport=8777
cas.httpport=8777-9000

cas.HTTPPORTMAX=maximum-port-range

specifies the maximum port range that SAS Cloud Analytic Services listens to for HTTP communication.

Note: It is recommended that the value of this configuration variable is not modified. If the value needs to be changed, the administrator with elevated Kubernetes permissions has to edit the CASDeployment Custom Resource. Make sure to restart the CAS server pod to pick up the changes.
CategoryNetwork
Default0
Range0–65535
Seecas.HTTPPORT
Example
cas.httpport=8777-9000

cas.INTERVALDS='interval-1=libref.dataset-name-1 <interval-2=libref.dataset-name-2 ...>'

specifies one or more interval-name=value pairs, where the value is the name of a data set that contains user-defined intervals.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryInput Control
See INTERVALDS= System Option
Example
cas.intervalds='subsid1=subsid.storeHours'

cas.KEYFILE='pathname'

identifies to the CAS controller the path and filename to the X.509 digital certificate file that is used to start the server. The certificate must be signed by a CA that is trusted by the CAS server.

Enclose pathname in single quotation marks.

Note: It is recommended to not modify the value of this configuration variable. The KEYFILE is set up automatically by the CAS operator.
CategorySecurity
RequirementUsed with cas.elasticssl and cas.mode='mpp'.
SupportsCAS servers running MPP.
Example
cas.keyfile='/opt/TKGrid/certs/controller.pem'

cas.LOCALE='POSIX-locale-string'

specifies the locale to use for sorting and formatting. For a list of valid POSIX locale strings, see Locale-to-Encoding Mapping in SAS National Language Support (NLS): Reference Guide

Valid inCAS statement SESSOPTS option
CategoryLocalization
Default'en_US'
Example
cas.locale='fr_FR'

cas.LOGCFGLOC='pathname'

specifies the path to the SAS logging facility logging configuration file.

Enclose pathname in single quotation marks.

Note: It is recommended that the value of this configuration variable is not modified.
CategoryLog
Seecas.APPTAG
Example
cas.logcfgloc='/opt/sas/cas1/etc/logconfig.xml'

cas.LOGFLUSHTIME=-1 | 0 | number

specifies the log flush time, in milliseconds.

  • -1

    flushes logs after each action completes.

  • 0

    flushes logs as they are produced.

  • number

    flushes logs in number milliseconds.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryLog
Default100
Range-1–86400
ExampleIn the following example, the CAS server writes buffered lines to the log every 500 milliseconds:
cas.logflushtime=500

cas.MAXSESSIONS='n'

specifies the maximum number of concurrent sessions. Users who can assume the administrative role are not subject to the limit.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryServer
Default5000
Range0–100000
NotesSpecifying zero (0) indicates that there is no session limit.
This option cannot be changed after the system initializes.
ExampleIn this example, the maximum number of concurrent CAS sessions is 1,000:
cas.maxsessions='1000'

cas.MAXTABLEMEM=number | '[number k | m | g | t] '

specifies the maximum amount of physical memory to allocate for a table.

TipThe intent of cas.MAXTABLEMEM is to manage the efficiency of accessing CAS tables on disk, not to control the amount of data that CAS keeps resident in RAM.
  • number

    specifies the maximum amount of physical memory, in bytes, to allocate for a table.

  • '[number k | m | g | t]'

    specifies the maximum amount of physical memory to allocate for a table in a unit other than bytes: k (kilobytes), m (megabytes), g (gigabytes), and t (terabytes).

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryCaslib
Default16M
NoteAfter this threshold is reached, the server uses temporary files and operating system facilities for memory management.
ExampleIn this example, the CAS server can allocate up to 32MB of physical memory for a table:
cas.maxtablemem='32m'

cas.MESSAGELEVEL='all' | 'default' | 'error' | 'none' | 'note' | 'warning'

specifies the log message level.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryLog
Default'all'
Example
cas.messagelevel='default'

cas.METRICS=true | false

causes CAS server metrics information to be displayed (true) or not displayed (false) in the SAS log.

When cas.metrics=true, you see information similar to the following displayed in the SAS log:

NOTE: Action 'nobs' used (Total process time):
NOTE:       real time               2.100185 seconds
NOTE:       cpu time                0.010999 seconds (0.52%)
NOTE:       total nodes             6 (192 cores)
NOTE:       total memory            1.11T
NOTE:       memory                  7.00K (0.00%)
The analytic server processed the request in 2.100185 seconds.
Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryLog
Default false
NoteThe values true and false are case sensitive.
See CASLIB Statement
ExampleIn the following example, CAS server metrics information is not displayed in the SAS log:
cas.metrics=false

cas.NWORKERS=number

specifies the number of worker nodes associated with this session.

Note: It is recommended that the value of this configuration variable is not modified. The value is set by the administrator with elevated Kubernetes permissions in the CASDeployment Custom Resource.
Valid inCAS statement SESSOPTS option
CategoryAdministration
Default0
Range0–5000
Example
cas.nworkers=8

cas.PERMSTORE='path'

specifies the path to a directory where the CAS server stores permissions.

Enclose path in single quotation marks.

The server saves its caslib and access control information to the cas.PERMSTORE directory periodically and when it shuts down.

Each subsequent time that the server starts, caslib and access control information is initialized from the server’s cas.permstore location.

IMPORTANT When you update cas.PERMSTORE in CASDeployment custom resource, you must also update SASPERMSTORE in /cas/permstore. Add the line: export SASPERMSTORE=path.

The backing volume for /cas/permstore needs to be provisioned as a persistent volume claim to maintain the permstore if pods in a CAS deployment are reset.

CategoryAccess Control
RestrictionDo not directly edit the files in cas.PERMSTORE location.
NoteEach CAS server should have its own cas.PERMSTORE location. To minimize the potential for network timing issues, it is recommended that each cas.PERMSTORE location be on the controller machine and not on a network file system. The server creates directories that are named as primaryctrl and backupctrl, on the main controller and the backup controller, respectively. For example, if you specify cas.PERMSTORE='/var/my_permstore', CAS writes its permstore to /var/my_permstore/primaryctrl.

cas.PORT=port

specifies the port to which the CAS server listens.

The maximum allowable port number is 65535. If a valid port is not specified, the server listens on a port selected by the operating system through the TCP/IP ephemeral port range. A common range is 32768-61000.

The commonly configured port is 5570.

Note: It is recommended that the value of this configuration variable is not modified. The value is set by the administrator with elevated Kubernetes permissions in the CASDeployment custom resource.
CategoryNetwork
See cas.GCPORT and cas.HTTPPORT
Example
cas.port=5570

cas.STARTUP='filename'

specifies the configuration file that the CAS server runs before the server accepts any client connections. This start-up file contains CAS actions that the server runs as it starts up.

Note: It is recommended that the value of this configuration variable is not modified. The value is set by the administrator with elevated Kubernetes permissions in the CASDeployment custom resource.
CategoryServer
Defaultcasstartup.lua
See Standard Configuration Files
Example
cas.startup='casstartup.lua'

cas.STARTUPDIR='path'

specifies the location for the SAS Cloud Analytic Services start-up directory.

Note: It is recommended that the value of this configuration variable is not modified. The value is set by the administrator with elevated Kubernetes permissions in the CASDeployment custom resource.
CategoryServer
Default/cas/config
See Standard Configuration Files
ExampleHere is an example:
cas.startupdir='/cas/config/my_cas_startup'

cas.SUBSETSESSIONCOPIES=number-of-blocks

specifies the number of extra block copies made for failover in either of the following scenarios:

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryAdministration
Default0
Example
cas.subsetsessioncopies=3

cas.TAG='string'

specifies a string to name the CAS server instance that is visible in the operating system, such as in the process list.

The cas.TAG option can be useful when debugging CAS.

Edit sas.cas.instance.config:config instance to set the variable.

CategoryServer
Example In this example, the string ‘cas-my_tag’ is used to name the CAS server instance:
cas.tag='cas-my_tag'
When you view the process list from a Linux command prompt, you see something similar to the following:
27019 ?        00:00:01  cas-my_tag 

cas.DEFAULTTABLEREPLICATION=1

specifies the default replication factor for new tables for a session.

You can also edit the sas.cas.instance.config:config instance to set the variable.

Valid inCAS statement SESSOPTS option.
CategoryServer, Session
Default1
Range0 - number_of_workers
NotesThis option is valid starting in 2023.05.
A value of zero disables replication for new tables.
You can specify a value that is greater than number_of_workers. In that case, the value of number_of_workers is used instead.
See Session Options in SAS Cloud Analytic Services: User’s Guide for information about setting the session option.
Example
cas.DEFAULTTABLEREPLICATION=3

cas.TIMEZONE='time-zone-name' | 'time-zone-ID'

specifies the default time zone for CAS server.

'time-zone-name' specifies a three- or four-character time zone name. For example, EST is a time zone name for Eastern Time.

'time-zone-ID' specifies a region or area value that is defined by SAS. When you specify a time zone ID, the time zone that the CAS session uses is determined by the time zone name and Daylight Saving Time rules.

You can also edit the sas.cas.instance.config:config instance to set the variable.

Valid inSAS Environment Manager
CategoryServer, Session
DefaultEtc/GMT
NoteThe 'time-zone-ID' value corresponds to the value in the 'Time Zone Information' column in Time Zone Information and Time Zone Names in SAS System Options: Reference .
See Time Zone Information and Time Zone Names in SAS System Options: Reference
TIMEZONE= System Option in SAS System Options: Reference
Examples
cas.TIMEZONE='Europe/Paris'
cas.TIMEZONE='PDT'

cas.TABLEREDISTUPPOLICY = 'NOREDIST' | 'REBALANCE'

specifies a table redistribution policy that is applied when the number of workers in the CAS server is increased.

NOREDIST: specifies that the table data is not redistributed when the number of worker pods is changed on a running CAS server.

REBALANCE: specifies that table data is rebalanced when the number of worker pods is changed on a running CAS server.

You can also edit the sas.cas.instance.config: config instance to set the variable.

Valid inServer, Environment Manager
CategoryServer
DefaultNOREDIST

cas.SCALEDOWNMODE = 'SUSPEND' | 'BACKGROUND'

specifies how the data is moved in the global tables when a worker pod is gracefully removed from a CAS server by reducing the value of spec.workers in the CASDeployement custom resource corresponding to the CAS server.

SUSPEND: All server activity is paused when data in global tables is being moved to other worker pods. New actions are not started and new connections are not accepted when data is being moved.

BACKGROUND: Each global table is locked and a copy of the table is created that has data on the worker pods that are not scaled down. When the copy is completed, the original table is deleted and replaced with the copy. During this operation an action can read the locked table, and actions that attempt to alter the locked table have to wait for the copy to complete.

You can also edit the sas.cas.instance.config: config instance to set the variable.

Valid inServer, Environment Manager
CategoryServer
DefaultSUSPEND

cas.MAXCORESPERWORKER='n'

specifies the maximum number of cores per worker.

When MAXCORESPERWORKER=0, the system honors the container's core limit in order to reduce performance degradation due to overthreading. When MAXCORESPERWORKER= is set to a nonzero value, the number of cores is limited to that value, up to the container's CGroup core limit. Reducing the maximum number of cores per worker can help reduce contention of cores and improve performance. This is especially true when multiple users are running highly concurrent actions on the CAS server. By specifying this option, you can change the default maximum for all sessions on your CAS server. You can use session option MAXCORESPERWORKER= to change the maximum cores per worker for a single session in order to improve performance for that session only.

Edit the sas.cas.instance.config: config instance to set the variable.

CategoryServer, SAS Environment Manager
Default0
Range0–20000
NoteThis option is valid in 2025.03 and later.
See MAXCORESPERWORKER= Session Option in SAS Cloud Analytic Services: User’s Guide
ExampleIn this example, each session defaults to a session option having a value of 7.
cas.maxcoresperworker=7

cas.TIMEOUT=seconds

specifies the SAS Cloud Analytic Services session time-out in seconds for a new or existing session.

Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategorySession
DefaultIn order of descending precedence:
  1. CAS statement TIMEOUT= option value, if specified
  2. SAS system option CASTIMEOUT=, if you explicitly set it in SAS to a value greater than 0
  3. 60
Range0–31536000
NotesThe session time-out starts when the number of connections to the session becomes zero and no actions are executing.
If a connection is established before the time-out expires, the time-out is canceled. Otherwise, the session is automatically terminated when the time-out expires.
When set to 0, the session is terminated immediately when the connection count becomes zero.
SeeCASTIMEOUT= System Option
Example
cas.timeout=100

cas.SESSIONTABLEREDISTUPPOLICY = 'DEFER' | 'NOREDIST' | 'REBALANCE'

specifies an initial (default) value of the session table redistribution policy option when a new session is created.

DEFER: specifies that the redistribution policy selection is deferred to a higher-level entity.

NOREDIST: specifies that the table data is not redistributed when the number of worker pods is changed on a running CAS server.

REBALANCE: specifies that table data is rebalanced when the number of worker pods is changed on a running CAS server.

You can also edit the sas.cas.instance.config: config instance to set the variable.

Valid inServer, SAS Environment Manager
CategoryServer
DefaultNone
See SESSIONTABLEREDISTUPPOLICY= Session Option in SAS Cloud Analytic Services: User’s Guide

cas.ALLOWRESTBASICAUTH='FALSE'

Controls if the CAS server allows REST clients to authenticate with Basic Authentication.

By default, it is set to FALSE. The Basic Authentication is disabled by default and OAuth Authentication is enabled by default. If you want to enable Basic Authentication, then set this option to TRUE.

Note: Enabling Basic Authentication is not recommended. If you choose to enable, be aware of the potential security risks.

Edit the sas.cas.instance.config: config instance to set this option.

Valid inServer, SAS Environment Manager
CategoryServer
DefaultFALSE
SeeConfigure Authentication for REST APIs in SAS Viya Platform: Deployment Guide.
ExampleIn this example, Basic Authentication is enabled.
cas.ALLOWRESTBASICAUTH='TRUE'

cas.MAXSESSIONTRANSFERSIZE=table-size

Determines the maximum combined table sizes for a single session that can be transferred to a new server. Any sessions with more than the specified amount of data do not transfer all the session tables to a new server. The SAS administrator can put a limit on the size to minimize disruption. The default value is no limit, which is represented by -1.

You can also edit the sas.cas.instance.config: config instance to set this option.

Valid inServer, SAS Environment Manager
CategoryServer
Default-1 (no limit)
SeeEnable State Transfer for CAS Servers in SAS Viya Platform: Deployment Guide for more information about CAS state transfer.
Example
cas.MAXSESSIONTRANSFERSIZE=1000000000

cas.STATETRANSFERMODEL='SUSPEND' | 'READONLY'

Determines how the state is transferred to a new server.

SUSPEND: No actions can run during the transfer of global tables.

READONLY: (Default) Marks all the global state information (such as CASLIBS and permissions) 'readonly' during transfer of global tables. Any attempts to run actions that change the global state, results in a failure.

The server is unavailable during the transfer of session tables. The server waits for all running sessions to be at action boundaries after the global state has been saved.

You can also edit the sas.cas.instance.config: config instance to set this option.

Valid inServer, SAS Environment Manager
CategoryServer
DefaultREADONLY
SeeEnable State Transfer for CAS Servers in SAS Viya Platform: Deployment Guide for more information about CAS state transfer.
Example
cas.STATETRANSFERMODEL=READONLY

cas.USERLOC='%HOME' | 'pathname/%USER'

specifies that the CAS server creates a personal caslib for each user at session start-up time in the specified location.

Note: It is recommended that the value of this configuration variable is not modified. The value is set by the administrator with elevated Kubernetes permissions in the CASDeployment custom resource.

'%HOME' equates to the user’s operating system $HOME directory.

'pathname/%USER' refers to a directory named for the user’s user ID under the specified file system path. Make sure that %USER is always placed at the end of the path that is specified for the option value.

Enclose pathname in single quotation marks.

CategoryCaslib
ExamplesIn this example, the personal caslib directory is the user’s operating system $HOME directory:
cas.userloc='%HOME'
In this example, the user’s personal caslib directory is named as the user ID and is located under /local:
cas.userloc='/local/%USER'

cas.DEFAULTMEMORYFORMAT='STANDARD' | 'DVR'

specifies the default memory format for the CAS server.

  • STANDARD: Specifies that the standard memory format is used. The standard memory format is designed for performance. It is the default for this option.
  • DVR: Specifies that the duplicate value reduction memory format is used. The DVR memory format can reduce memory consumption and the on-disk size of SASHDAT files when the input data contains a large number of duplicate values.

You can also edit the sas.cas.instance.config: config instance to set the variable.

Valid inServer, SAS Environment Manager
CategoryServer
Default In order of precedence:
  1. Server option cas.DEFAULTMEMORYFORMAT, if set.
  2. Environment variable env.CAS_DEFAULT_MEMORY_FORMAT, if set.
  3. STANDARD
NoteSupport for the server and session options was added in 2025.11.
SeeDEFAULTMEMORYFORMAT= Session Option in SAS Cloud Analytic Services: User’s Guide
Fine Tuning: Memory Format in SAS Viya Platform: System Programming Guide

cas.BIGINTPROCESSING= 'TRUE' | 'FALSE'

specifies whether support for BIGINT is enabled.

Note: This option is used only by a limited number of CAS actions to determine whether to apply the legacy DOUBLE coercion behavior.

In SAS, by default, integer values are coerced into DOUBLE values before doing most of the calculations in procedures and actions. For large integer values of 15–16 digits or more, this conversion can result in a loss of precision.

When cas.BIGINTPROCESSING=TRUE, these selected CAS actions bypass the coercion and preserves BIGINT values with full precision.

When cas.BIGINTPROCESSING=FALSE, the default DOUBLE semantics is applied.

Note:
  • To know which CAS actions use this option, see Details in SAS Cloud Analytic Services: User’s Guide . Setting this option on other CAS actions has no effect.
  • Other actions might already support BIGINTPROCESSING natively and do not require any session setting.
Valid inCAS statement SESSOPTS option. You can also edit sas.cas.instance.config: config instance to set the variable.
CategoryData
DefaultFALSE
NotesSupport for this option was added in 2025.12.
Value of BIGINTPROCESSING=session option overrides the server option.
See Details in SAS Cloud Analytic Services: User’s Guide

Grouped by Categories

Access Control Options

Action Options

Administration Options

Caslib Options

Data Quality Options

Input Control Options

Localization

Security Options

Note: Other security-related configuration file options can be found in Configuration File Options for Parallel Data Transfer in SAS Viya Platform Encryption: Data in Motion.

Sort Options

CAS Environment Variables

Where Do I Set CAS Environment Variables?

During CAS server start-up, the controller shares the configuration as each worker and the backup controller (if present) connect. All the CAS configuration files are located in /cas/config directory.

For more information, see Standard Configuration Files.

CAS Environment Variables Reference

Note: The SAS administrator can set the environment variables, which can be modified by editing the CAS configuration instances in SAS Environment Manager. To allow the SAS administrator to modify the scripts in the configuration instances, set SAS_ALLOW_ADMIN_SCRIPTS to TRUE in the sas-shared-config configMap. For more information about setting SAS_ALLOW_ADMIN_SCRIPTS, see Edit Configuration Instances.

env.CASACTIONHISTORYLEN

specifies the number of bytes to use for reporting action names and action parameters when the builtins.history action is run.

If specified, the HISTORYLINELEN session option takes precedence over the CASACTIONHISTORYLEN environment variable.

If the action request is longer than the action history line length, then it is truncated.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryEnvironment
Default8192
Range8192–8388608 (8 megabytes)

env.CASACTIONLINELEN

specifies the number of bytes to use for logging the action name and action parameters in the server log when an action is run.

The maximum value is 32768.

If the action request is longer than the logging line length, then it is truncated.

The default length is 1024. If the logging level is set, then it might affect the default length.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryEnvironment
Default1024

env.CASALLHOSTACCOUNTS

when specified, causes CAS sessions to run under the host identity of the requesting user. This environment variable is intended for deployments in which each user launches CAS sessions under their individual host identity. This environment variable provides a low-maintenance alternative to assigning all users to the CASHostAccountRequired group.

Edit sas.cas.instance.config: config instance to set the variable.

  • If CASALLHOSTACCOUNTS is specified, it has precedence over the existence and membership of the CASHostAccountRequired group. For example, if CASALLHOSTACCOUNTS is specified, all users launch CAS sessions under their host identity, even if the CASHostAccountRequired group exists and has only one member.
  • If CASALLHOSTACCOUNTS is not specified, only those users who are members of the CASHostAccountRequired group can launch CAS sessions under their host identity.

By default, CAS cannot launch sessions under a user's host identity. To enable host launch for CAS, see Enable Host Launch in SAS Viya Platform: Deployment Guide.

TipTo determine whether this environment variable is set, use the builtins.serverStatus action. If the value of the CASHostAccountRequired key is ALL, the environment variable is set. If the value is OPTIONAL, the environment variable is not set.
CategorySecurity
Exampleenv.CASALLHOSTACCOUNTS='true'

env.CASCLOUDNATIVE

when specified with a value of 1, the Identities service is used to fetch the POSIX attributes instead of standard C library functions if a CAS session is to be launched under OS identity (user is a member of the CASHostAccountRequired group).

By default CASCLOUDNATIVE is enabled. To disable CASCLOUDNATIVE, the value should be set to 0.

The user’s home directory is available from the Identities service if the config/identities/sas.identities/identifier.homeDirectoryPrefix configuration variable is set in the deployment. If the configuration variable is not set, the user’s home directory defaults to the location set by the userloc option. (Default location: /cas/data/caslibs/casuserlibraries).

CategoryEnvironment
DefaultCASCLOUDNATIVE=1
SeeTo disable CASCLOUDNATIVE and to enable System Security Services Daemon (SSSD), see the sections, Disable Cloud Native Mode and Enable System Security Services Daemon (SSSD) Container in $deploy/sas-bases/examples/cas/configure/README.md for README files in Markdown language or $deploy/sas-bases/examples/cas/configure/README.htm for README files in HTML.

env.CAS_ADMIN_GLOBAL_UDFMTS

enables an administrator to turn on and turn off an administrative-credentials check for users attempting to perform certain manipulations on user-defined formats in CAS.

The value of env.CAS_ADMIN_GLOBAL_UDFMTS=YES|ON|TRUE specifies that escalation of administrative authority to Superuser is required to promote or delete the global user-defined format libraries.

The value of env.CAS_ADMIN_GLOBAL_UDFMTS=NO|OFF|FALSE specifies that escalation of administrative authority to Superuser is NOT required to perform these operations.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryEnvironment
DefaultNO|OFF|FALSE
NoteThe accepted values for this environment variable are case insensitive

env.CAS_CONTROLLER_TEMP='path [[:path] ...]'

specifies the disk paths to temporarily store data on the CAS controller node for the CAS upload action and when saving CSV files to certain cloud platforms such as Amazon S3.

Delimit multiple paths with a colon (:).

Note: It is recommended that the value of this environment variable is not modified. The value is set by the administrator with elevated Kubernetes permissions in the CASDeployment custom resource.
CategoryData
DefaultWhen env.CAS_CONTROLLER_TEMP is not specified, CAS defaults to the locations pointed to by env.CAS_DISK_CACHE.
Restrictionsenv.CAS_CONTROLLER_TEMP is case sensitive.
env.CAS_CONTROLLER_TEMP should point to a file system that uses only a local disk.
Example
env.CAS_CONTROLLER_TEMP = '/upload_data/disk1:/upload_data/disk2'

env.CASDATADIR=‘path-to-CAS-data-directory’

specifies an alternate path for product caslibs instead of the default path /cas/data. It allows users to use the public caslib to read and write data from the location that is specified.

CASDATADIR points to the directory where the cas-default-data persistent volume (PV) is mounted. cas-default-data is the default CAS data PV.

It is recommended that this option be configured to point to a high-performance storage platform. The backing volume for /cas/data needs to be provisioned as a persistent volume claim to maintain this data when pods in a CAS deployment are reset.

Note: It is recommended that the value of this environment variable is not modified. The value is set by the administrator with elevated Kubernetes permissions in the CASDeployment custom resource.

The CAS data directory is accessible only by the primary and secondary CAS controllers.

CategoryData

env.TKUTILLOC='path'

enables the user to specify a different directory to create temporary utility files to avoid filling up the default /tmp directory.

By default, the temporary files are stored in /tmp. To use a different directory, the administrator must set this environment variable to the desired directory before starting the CAS server.

Edit sas.cas.instance.config: config instance to set the variable.

Note: This environment variable is primarily used by the SAS Federation Server. However, this variable is also used by some CAS data feeders such as Snowflake. For more information, see Configure Temporary Storage for SAS Utility Files in SAS Federation Server: Administrator’s Guide .
CategoryData
Default/tmp
Example
env.TKUTILLOC='myDir/UtilityFiles'

env.CAS_DEFAULT_MEMORY_FORMAT='STANDARD' | 'DVR'

when the memory format is set to DVR, then the server uses a duplicate value reduction (DVR) memory format. When the data to load into memory and analyze has many repeating values, the DVR memory format can reduce the in-memory size of tables and the on-disk size of SASHDAT files. The standard memory format is designed for high-performance and performs well when the input data contains many numeric variables with unique values–as is common with modeling.

CategoryData
DefaultSTANDARD
SeeFine Tuning: Memory Format in SAS Viya Platform: System Programming Guide

env.CAS_DISK_CACHE='path [[:path] ...]'

specifies the disk paths to cache data on CAS worker nodes.

Delimit multiple paths with a colon (:).

Note: It is recommended that the value of this environment variable is not modified. The value is set by the administrator with elevated Kubernetes permissions in the CASDeployment custom resource.
IMPORTANT It is a best practice to always specify env.CAS_DISK_CACHE. When not specified, env.CAS_DISK_CACHE defaults to /cas/cache directory. The backing volume for /cas/cache is by default an emptyDir volume.
CategoryData
Restrictionsenv.CAS_DISK_CACHE is case sensitive.
env.CAS_DISK_CACHE should point to a file system that uses only a local disk.
TipThere is an advantage to using multiple physical disks. When using multiple threads, mapping files can occur concurrently if multiple disks are used.
Example
env.CAS_DISK_CACHE = '/data/disk1:/data/disk2'

env.CAS_LOADTABLEBACKINGSTORE=CASDISKCACHE | INPLACEPREFERRED

specifies how the server performs memory mapping with supported data formats on supported data sources.

  • CASDISKCACHE

    specifies to make a copy of the blocks for an in-memory table. The blocks are stored in the directories identified by the CAS_DISK_CACHE environment variable at server start-up.

  • INPLACEPREFERRED

    specifies to use the blocks from an existing SASHDAT file for memory mapping. If the existing blocks cannot be used, then copies of the blocks are used as described for CASDISKCACHE.

Edit the sas.cas.instance.config: config instance to set the variable.

CategoryData
DefaultCASDISKCACHE
Exampleenv.CASLOADTABLEBACKINGSTORE=INPLACEPREFERRED

env.SAS_LOCALE_DATA=COMPAT | CLDR

specifies the SAS Locale data version that is used for a session. The default value of the SAS Locale data version is the legacy SAS Locale date version that is SAS 9 compatible.

  • COMPAT (default): Use the legacy SAS Locale data that is SAS 9 compatible.
  • CLDR: Use Common Locale Data Repository (CLDR) data. The version of this data is updated periodically to keep up with the new releases of CLDR.

Edit the sas.cas.instance.config: config instance to set the variable.

CategoryData
DefaultCOMPAT
ExampleThis example allows CLDR data to be used in the launched session.
env.SAS_LOCALE_DATA='CLDR'

env.CAS_HEARTBEAT_LOST_TIMEOUT='interval'

specifies the interval (in seconds) since the last heartbeat received from a CAS worker node before the controller treats the node as lost.

Smaller intervals detect machines that silently leave the network more quickly. Larger intervals are more tolerant of machines that might be exceptionally overloaded.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryServer
Default120 seconds
Range60 – (no upper limit) seconds
Restrictionenv.CAS_HEARTBEAT_LOST_TIMEOUT is case sensitive.
Example
env.CAS_HEARTBEAT_LOST_TIMEOUT='300'

env.CAS_ENABLE_CONSUL_RESOURCE_MANAGEMENT='TRUE' | 'FALSE'

when specified, enables CAS resource management policies by turning on communication with SAS Configuration Server (Consul).

Edit the sas.cas.instance.config: config instance to set the variable.

CategoryServer
DefaultOff (FALSE)
Restrictionenv.CAS_ENABLE_CONSUL_RESOURCE_MANAGEMENT is case sensitive.
SeeFor more information, see CAS Resource Management.
Example
env.CAS_ENABLE_CONSUL_RESOURCE_MANAGEMENT='true'

env.CASHOMEDIRLOC='path'

specifies the location of the directory where each user’s home directory is created and matches the user name in the system.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryEnvironment
NoteCASHOMEDIRLOC is used only if CASMAKEHOMEDIR is set.
Examples
env.CASHOMEDIRLOC='/home'
Here is an example where the user name is user01
'/home/user01'

env.CASHOMEDIRPERMS=permissions

specifies the permission mode for the home directory on a CAS machine.

Note: Permissions are used only if CASMAKEHOMEDIR is set and a home directory is created.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryEnvironment
DefaultDirectory permissions are set to 0700
Restriction
  • Supported directory permission values are between 0700 and 0777
  • Specify permissions in octal format
  • The default setting provides Read/Write/Execute permissions to the user only
Example
env.CASHOMEDIRPERMS=750

env.CASMAKEHOMEDIR='CONTROLLER'|'WORKER'|'BACKUP'|'ALL'

creates a home directory on a CAS machine, if it is not found when the user starts a session.

  • CONTROLLER

    creates a home directory on the primary controller machine only.

  • WORKER

    creates a home directory on the primary controller and the worker machines.

  • BACKUP

    creates a home directory on the primary controller and the backup controller.

  • ALL

    creates a home directory on all the nodes.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryEnvironment
DefaultIf any other value is specified, it defaults to only creating the home directory on the primary controller.

env.CASPWFORCEHOST=true|false

when env.CASPWFORCEHOST=true, CAS sessions for users that connect directly to CAS (using a user name and a password) run under the user's OS identity.

CategorySecurity
RequirementThis option has an effect only when env.CASCLOUDNATIVE=1.

env.CASPWONLYCHAR=true|false

when specified and the server is configured with a password authentication provider, only users in the CASHostAccountRequired group are authenticated against the password authentication provider. Enabling this environment variable provides the following benefits:

  • Users who can authenticate with a user name and a password to SAS Logon manager can start CAS sessions with a service account.
  • Users who are members of the CASHostAccountRequired group can start CAS sessions with their host credentials.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryEnvironment

env.CASSPN="HTTP/FQDN"

when attempting a direct Kerberos connection to the CAS server in SAS Viya platform using the binary port from a SAS 9 client or a SAS Viya 3.x client, the default service principal name of "sascas@FQDN" must be replaced with the SAS Viya platform value of "HTTP/FQDN" where FQDN is the fully qualified domain name of the primary node of the Kubernetes cluster.

CategorySecurity

env.CAS_QUOTA_MODE='ALLTABLES'

specifies that the quota applies on all the tables.

When this variable is not set or set to some other value, tables that are mapped only from CAS_DISK_CACHE are counted toward quota limits.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryData
Restrictionenv.CAS_QUOTA_MODE is case sensitive.

env.CASSTRIPOAUTH=1

strips the @domain that is a part of the user name when authenticating a user name and password with SASLogon.

This environment variable helps in resolving a mismatch between host authentication and LDAP authentication when host authentication requires “user@domain” format user names, and LDAP authentication requires “user” format user names without the @domain part with SASLogon.

Edit sas.cas.instance.config: config instance to set the variable.

CategorySecurity
DefaultDoes not strip the domain name that is specified after the @ character in the user name.
Example Here is an example where the user name is user01@company.com. It is authenticated as:
'user01'

env.CASUSERIGNORECASE='ON'

when in effect (specified using any value), causes the CAS server to ignore the letter casing for user names during authentication, group lookup, and process launch. Always specify env.CASUSERLOWERCASE whenever specifying env.CASUSERIGNORECASE, unless instructed otherwise by SAS Technical Support.

The typical scenario for declaring env.CASUSERIGNORECASE is when users run their CAS sessions under their own host account and the user authentication system is configured to be case-insensitive and contains uppercase or mixed case user names. For more information, see The CASHostAccountRequired Custom Group in SAS Viya Platform: Identity Management.

Edit sas.cas.instance.config: config instance to set the variable.

CategorySecurity
Defaultoff
Restrictionenv.CASUSERIGNORECASE is case sensitive.
RequirementUse with env.CASUSERLOWERCASE.
NoteTo turn off env.CASUSERIGNORECASE, remove its definition.
ExampleIn this example, env.CASUSERIGNORECASE is in effect:
env.CASUSERIGNORECASE='on'

env.CASUSERLOWERCASE='ON'

when in effect (specified using any value), causes the CAS server to convert user names to lowercase. env.CASUSERLOWERCASE is typically used in conjunction with env.CASUSERIGNORECASE.

The typical scenario for declaring env.CASUSERLOWERCASE is when users run their CAS sessions under their own host account and the user authentication system is configured to be case-sensitive and their user name contains uppercase or mixed case user names. For more information, see The CASHostAccountRequired Custom Group in SAS Viya Platform: Identity Management.

Edit sas.cas.instance.config: config instance to set the variable.

CategorySecurity
Defaultoff
Restrictionenv.CASUSERLOWERCASE is case sensitive.
RequirementUse with env.CASUSERIGNORECASE.
NoteTo turn off env.CASUSERLOWERCASE, remove its definition.
ExampleIn this example, env.CASUSERLOWERCASE is in effect:
env.CASUSERLOWERCASE='on'

env.TKHTTP_CORS_ALLOWED_ORIGINS

specifies a list of valid origins that is delimited by a comma and is added to the CORS policy allowlist. You can also specify an asterisk (*) to match any valid origin.

A valid origin can be in the following form that includes a host name or an IP address:

scheme://hostname:[\{_}port\{_}]
scheme://ipAddress:[\{_}port\{_}]

Edit the sas.cas.instance.config: config instance to set the variable.

CategorySecurity
ExampleThis example allows the incoming browser connections from the origin http://support.sas.com, and HTTPS connections on port 442 from the host name internal.companysite.com. However, this example does not allow connections from https://internal.companysite.com:443 or https://companysite.com:442 due to a mismatched port and wrong subdomain.
env.TKHTTP_CORS_ALLOWED_ORIGINS='http://support.sas.com,https://internal.companysite.com:442'

env.TKHTTP_CONTENT_SECURITY_POLICY

specifies the Content-Security-Policy (C-S-P) header that is used to prevent Cross-Site Scripting (XSS) attacks.

If the env.TKHTTP_CONTENT_SECURITY_POLICY is not set, then the following default C-S-P header is used:

Content-Security-Policy: default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval';
style-src 'self' 'unsafe-inline';frame-ancestors 'none';object-src 'none';connect-src 'self';
img-src 'self';base-uri 'self';form-action 'self';require-trusted-types-for 'script';

If the env.TKHTTP_CONTENT_SECURITY_POLICY is set to some value, then this value takes precedence over any other value provided as the C-S-P header.

If the env.TKHTTP_CONTENT_SECURITY_POLICY is set to an empty string "", then the C-S-P header is not used.

CategorySecurity
Defaultenv.TKHTTP_CONTENT_SECURITY_POLICY is not set.

env.AUTOTUNING_LEVEL_ALLOWED='none' | 'sequential' | 'parallel'

This environment variable allows the SAS administrator to control the level of the auto-tuning.

  • none

    all auto-tune actions display the following error message and stop the execution:Auto-tune is not allowed for this environment.

  • sequential

    all auto-tune actions enforce the configurations to be evaluated sequentially, independent of whether the user requested a parallel execution. The following warning message is displayed in the log: Auto-tune is limited to sequential execution for this environment.

  • parallel

    if this environment variable is not defined or the parallel option is specified, then auto-tune actions execute normally and use parallel evaluations depending on the available resources.

Edit the sas.cas.instance.config: config instance to set the variable.

CategoryPerformance
Defaultenv.AUTOTUNING_LEVEL_ALLOWED is not set.
Example
env.AUTOTUNING_LEVEL_ALLOWED='sequential'

env.FEDSQL_OPTIMIZE_VARBINARY_PRECISION='TRUE' | 'FALSE'

When this environment variable is set to TRUE, all invocations of the fedSql.execDirect action run with an optimization for VARBINARY columns. The action uses the maximum size of VARBINARY data that is stored in a column rather than the declared maximum size when reading and creating VARBINARY columns with the fedSql.execDirect action.

The optimization can offer significant benefits when there is a large difference between the declared and actual sizes of VARBINARY columns. For example, when a VARBINARY column has a declared maximum size of 16000 characters, but does not contain any values larger than 30 characters. Use of the smaller precision can improve query performance and reduce the memory consumption of in-memory tables that have VARBINARY columns.

In addition, when a new table is created using FedSQL CREATE TABLE AS, VARBINARY columns in the new table are created with the needed size rather than propagating VARBINARY precisions from the source table. What was originally a VARBINARY(16000) column in the source table can become a VARBINARY(30) column in the newly created table.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryPerformance
DefaultFALSE

env.FEDSQL_OPTIMIZE_VARCHAR_PRECISION='TRUE' | 'FALSE'

When this environment variable is set to TRUE, it offers the same benefits as FEDSQL_OPTIMIZE_VARBINARY_PRECISION, except that the benefits apply to the VARCHAR data type.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryPerformance
DefaultFALSE

env.SAS_EXTLANG_SETTINGS

specifies the path available to all CAS workers that contains the external languages access control XML configuration file.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryEnvironment

env.SAS_RNG_METHOD='random-number-generator'

specifies the random number generator (RNG) used when running CAS actions and procedures.

Examples of valid RNGs are: 'PCG' (permuted congruential generator) or 'TF2' (Threefry, 2x64-bit counter-based). The complete set of values for random-number-generator is listed under the CALL STREAMINIT Routine in SAS Functions and CALL Routines: Reference.

Edit sas.cas.instance.config: config instance to set the variable.

CategoryData
DefaultWhen env.SAS_RNG_METHOD is not specified, the default RNG is 'MTHYBRID' (Hybrid 1998/2002 32-bit Mersenne twister).
Example
env.SAS_RNG_METHOD='PCG'

env.TKTXTANIO_BINDAT_DIR='install-path'

specifies the installation directory for SAS linguistic binary files required to perform text analysis.

Note: TKTGDat.sh contains the SAS linguistic binary files required to perform text analysis in SAS LASR Analytic Server with SAS Visual Analytics and to run PROC HPTMINE and HPTMSCORE with SAS Text Miner.

Edit or sas.cas.instance.config: config instance to set the variable. You can also set the variable in sas.cas.instance.config: settings instance by using bash format.

CategoryData
Restrictionenv.TKTXTANIO_BINDAT_DIR is case sensitive.
ExampleHere is an example:
env.TKTXTANIO_BINDAT_DIR='/opt/sas/viya/home/SASFoundation/utilities/TKTGDat'

Grouped by Categories

CAS Resource Management Policies

Overview

CAS resource management policies enable you to manage CAS_DISK_CACHE used by CAS tables through three different table categories:

Table Categories and Policies That Manage Them

Table category

caslib type

caslib example

Policy

Global tables

Global

HPS, PUBLIC

globalCaslibs

Global tables

Personal

CASUSER

Priority-n

Session tables1

Personal

CASUSER

Priority-n

1 The sum of all tables in each session. Individual caslib limits at the session level are not supported.
TipWith the CAS command line interface, you can create a policy template that can serve as a starting point for creating your own CAS resource management policies. For more information, see Create Policies from JSON Templates in SAS Viya Platform: Using the Command-Line Interface.

Global caslib Policy

Because global caslibs apply to all users, global caslibs have a unique policy.

POLICY DEFINITION

globalCaslibs
   _ALL_         quota
   [global-caslib  quota]
   [...]

global-caslib

specifies a global caslib.

quota

specifies the maximum amount of CAS_DISK_CACHE space, in bytes, that global-caslib can use.

_ALL_

specifies all global caslibs.

When _ALL_ is specified, quota specifies the total amount of CAS_DISK_CACHE space that can be used for all global tables, regardless of the caslibs to which the tables belong.

Example

  globalCaslibs 
     _ALL_      400000000 
     HPS        200000000 
     MyGlobal   100000000 

  [CAS-server-priority-n
          globalCasuser     - quota
          sessionTables     - quota]
  [...]

  priorityAssignments
     user	priority-level
     [...]

In this example, the shared global caslibs HPS and MySiteGlobal can use up to 200GB and 100GB of disk cache space, respectively. The maximum amount of disk cache space that all global caslibs can use is 400GB.

Priority-Level Policies

Priority-level policies assign disk cache space quotas based on a user’s group membership, or a user’s explicit assignment with the priority-assignment option. You can define up to five priority-level policies.

POLICY DEFINITION

  [CAS-server-priority-n
          globalCasuser     - quota
          sessionTables     - quota]

  [...]

CAS-server

specifies a CAS server (for example, cas-shared-default or cas-tenant1-default.)

priority-n

specifies the priority level for a policy. n is a number 1 - 5.

quota

specifies the maximum amount of CAS_DISK_CACHE space, in bytes, that the associated table category can use.

globalCasuser

specifies the quota for global tables that are defined in a user’s personal caslib (the CASUSER caslib).

sessionTables

specifies the quota to be placed on session tables (for example, MyTable).

Example

  globalCaslibs
     _ALL_         quota
     [global-caslib  quota]
     [...]

  priorityLevels
     cas-shared-default-priority-1 
                globalCasuser     - 500000000 
                sessionTables     - 500000000 
     cas-shared-default-priority-2 
                globalCasuser     - 50000000 
                sessionTables     - 50000000 
     cas-shared-default-priority-3 
                globalCasuser     - 10000000 
                sessionTables     - 10000000 

  priorityAssignments
     user	priority-level
     [...]

In this example, three out of a maximum of five policies are defined for the CAS server, cas-shared-default. The policy, cas-shared-default-priority-1, applies to CAS users who are members of the user group with the same name, or to CAS users who are explicitly assigned with the priority-assignment option. CAS users for which the cas-shared-default-priority-1 applies to can use up to 500GB of CAS_DISK_CACHE space in their personal caslibs for shared global caslibs. These CAS users can use up to 500GB CAS_DISK_CACHE space for session tables.

Priority Assignments

Users that are not a member of a resource management user group can be explicitly assigned to a priority-level policy.

POLICY DEFINITION

  priorityAssignments
     user 	priority-level
     [...]

user

specifies a CAS user ID that is not a member of a CAS resource management user group (for example, cas-shared-default-priority-1).

TipInstead of a user ID, user can be an asterisk (*), that includes any user IDs that do not match any of the specified user IDs or CAS resource management group names.

priority priority-level

specifies a priority level that maps to a specific policy. priority-level is a number 1–5.

For example, if 4 is specified, user is assigned to the cas-shared-default-priority-4 policy.

IMPORTANT If a priority level is specified for which there is no corresponding policy defined, the user has no policy assignment.

Example

  globalCaslibs
     _ALL_         quota
     [global-caslib  quota]
     [...]

  [CAS-server-priority-n
          globalCasuser     - quota
     sessionTables     - quota]
  [...]

  priorityAssignments 
     userA	1 

In this example, three out of a maximum of five policies are defined for the CAS server, cas-shared-default. UserA is not a member of any of the CAS resource management user groups (for example, cas-shared-default-priority-1). Therefore, when UserA starts a CAS session, the cas-shared-default-priority-1 policy contains the resource definitions.

See Also

CAS Configuration Logging

SAS Viya platform logs are streamed to standard output at the Kubernetes cluster level, rather than written to local or server-level log files. As a SAS administrator, your access to log data depends on the solution provided by the administrator with elevated Kubernetes permissions at your site.

For more information about logging, see Ways to View Log Messages in SAS Viya Platform: Log Monitoring.

Last updated: August 18, 2026