Configuration Properties: Concepts

Service Configurations

SAS Viya platform servers and services have properties that are configured by default at the time of deployment to ensure that they run properly. You can also add properties (through a configuration instance), or modify an existing property, such as configuring a logging property. To view, modify, or add configuration properties, use the following methods:

  • Configuration page in SAS Environment Manager.

    See Configuration Page in SAS Environment Manager: User’s Guide for information about using SAS Environment Manager to view and change configuration information.

  • sas-viya command-line interface (CLI) and the configuration plug-in.

    See How to (CLI) for information about using the CLI to manage configuration information.

Configuration Instances and Definitions

A service's configuration consists of configuration instances that the service uses. These configuration instances are a collection of name-value pairs (or properties). (These name-value pairs can sometimes be nested.)

Configuration instances are based on a configuration definition. A configuration definition is a schema that describes a type of configuration. You create a configuration instance from a configuration definition. There are two types of configuration definitions:

  • service configuration definition

    a configuration definition that applies to one or a small set of services. An example is sas.reportdata.properties.

  • system configuration definition

    a configuration definition that applies to any service. Examples are jvm and spring. See System Configuration Definitions for a list of system configuration definitions.

A SAS Viya platform service can be affected by one or more configuration instances. Some services have a one-to-one relationship with a configuration instance and some services are associated with more than one configuration instance. It is important to note that some services do not have any configuration instances, other than Global Configuration Instances, but you can specify configuration properties for most of these services.

For a list of services that have only global configuration instances, see Services That Have Only Global Configuration Instances by Default.

To view a list of services and their configurations, or to view a list of service definitions use one of these commands:

  • sas-viya command-line interface (CLI): sas-viya configuration configurations list

    For a list of configuration instances for a service: sas-viya configuration configurations list --service servicename

    For a list of configuration definitions: sas-viya configuration definitions list

  • SAS Environment Manager Configuration page. It contains two views: All services and Definitions.

    The All services view lists all SAS Viya platform services that are currently deployed and those that an administrator has not manually stopped.

    The Definitions view lists all the SAS Viya platform configuration definitions.

When To Restart a Service After a Configuration Change

SAS Viya platform services (sometime referred to as microservices) configuration properties are stored in SAS Configuration Server of SAS Infrastructure Data Server. For configuration property updates or additions, you might need to restart the service to which you are making the update. This is based on whether the service is written in Java or Go.

For services written in Java, changes trigger a refresh, and the new property values are applied to the service. In most situations, no restart of the service is required. Verify that the configuration changes were applied. Restart the service if the change was not applied. For a list of Java services, use this command:

kubectl -n namespace get deployments --selector='sas.com/deployment-base=spring'

For services written in Go, a restart is required and the restart occurs automatically after configuration changes are applied. For a list of Go services, use this command:

kubectl -n namespace get deployments --selector='sas.com/deployment-base=golang'

If you need to restart a service, find the associated pod in your SAS Viya namespace and delete it. The pod automatically restarts after it has been deleted. Here is an example:

export viya=name-of-namespace
kubectl -n $viya delete pods -l app.kubernetes.io/name=app-name

See Managing a Specific Server or Service in SAS Viya Platform: General Management of Servers and Services for more information.

System Configuration Definitions

System configuration definitions can apply to any service (whereas configuration definitions that apply to one or a small set of services are referred to as service configuration definitions). Below is a list of system configuration definitions and their properties that can be configured.

jvm (Java Virtual Machine)

JVM (Java Virtual Machine) options are used to configure the Java Virtual Machine when it is launched.

Starting with 2025.06, Viya uses the XX:MaxRAMPercentage JVM (java virtual machine) option that was introduced with Java 8 version. This option configures the maximum heap size of the Java application as a percentage of the total memory of a container. This percentage-based value allows you to manage the pod size to tune your deployments. (If the JVM settings are too low, memory that is reserved for the pod is never used. If the JVM settings are too high, the pod is subject to random failures for exceeding memory resource limits.)

The default value for XX:MaxRAMPercentage is 75% for most services. Updates to your deployment use these new heap settings. However, if you had modified jvm options in your deployment, your modified settings are maintained across updates.

Note: The xmx option always overrides the XX:MaxRAMPercentage option. However, SAS recommends that you begin to use the XX:MaxRAMPercentage jvm option when you are tuning your Viya deployment.

To view the services that are configured, use the Configuration page of SAS Environment Manager. Select Definitions from the drop-down menu and highlight jvm. You might see the java-option-xmx option without a value. Or, a service is listed as being configured for a jvm property, but no option is listed. This signifies that the XX:MaxRAMPercentage has been set at start up.

Alternatively, you can use the sas-viya CLI to view services that are configured:

sas-viya configuration configurations list --definition-name jvm

sas.commons.rest.client

Use the sas.commons.rest.client definition to configure the commons REST client library. The property value for the service is Global, which indicates that the configuration instance applies to all services.

Property

Value

Description

Services:

servicename

The name of the service to which this configuration instance applies.

Note: The value of Global indicates the configuration instance applies to all services.

A URL that is accessible to clients external to the SAS system:

not set by default

Overrides the external host and port used when generating URLs for accessing this system. Use https://host:port/ syntax, where :port is optional.

Bypass HTTP proxy:

not enabled by default

Enables requests to be routed directly to the service rather than through the HTTP proxy.

sas.commons.web.security

The sas.commons.web.security definition contains a set of properties that are used to configure web security. By default, your SAS web applications, such as SAS Studio, SAS Environment Manager, Model Studio, and SAS Visual Analytics, are already configured with this configuration instance.

To view the services that are already configured with sas.commons.web.security, use the Configuration page of SAS Environment Manager. Select Definitions from the View: drop-down menu and highlight sas.commons.web.security. Alternatively, you can use the sas-viya CLI:

sas-viya configuration configurations list --definition-name sas.commons.web.security

Property

Default Value

Description

Services:

servicename

The name of the service to which this configuration instance applies.

content-security-policy:

default-src 'self'; object-src 'none'; frame-ancestors 'self'; form-action 'self';

The string used for the Content-Security-Policy HTTP header.

content-security-policy-enabled:

enabled by default

Sends the Content-Security-Policy header in HTTP responses to prevent injection attacks.

x-content-type-options:

nosniff

The string used for the X-Content-Type-Options header for unsecured endpoints.

x-content-type-options-enabled:

enabled by default

Sends the X-Content-Type-Options header in HTTP responses for unsecured endpoints.

x-frame-options:

(not set)

DEPRECATED: Use content-security-policy with the frame-ancestors directive instead. The string used for the X-Frame-Options HTTP header. A restart is required to pick up changes to this property.

x-frame-options-enabled:

DEPRECATED: Use content-security-policy with the frame-ancestors directive instead. Sends the X-Frame-Options header in HTTP responses. A restart is required to pick up changes to this property.

x-xss-protection:

1; mode=block

The string used for the X-XSS-Protection header for unsecured endpoints.

Note: The protections brought by this property are largely superseded by a strong content security policy. It is recommended to use the content-security-policy property and to leave the x-xss-protection as its default value.

x-xss-protection-enabled:

enabled by default

Sends the X-XSS-Protection header in HTTP responses for unsecured endpoints.

Note: The protections brought by this property are largely superseded by a strong content security policy. It is recommended to use the content-security-policy property and to leave the x-xss-protection-enabled at its default value.

sas.commons.web.security.cookies

The set of properties that are used to configure security related to cookies. Modifying one of these property values requires that the associated service restarts. Some services restart automatically. If an impacted service does not restart after you save your changes, restart it manually.

Property

Value

Description

sameSite:

Unset

same-site cookie attribute is not set.

Strict

browser prevents sending the cookie in any cross-site request.

Lax

browser sends the cookie only in same-site requests and cross-site top level GET requests.

None

same-site cookie attribute is set and the cookie is always sent in cross-site requests.

The string used to specify whether cookies should be sent only with same-site requests. Valid values are 'Unset', 'Strict', 'Lax', and 'None'.

sas.commons.web.security.cors

These set of properties are used to configure how the server responds to cross-origin resource sharing (CORS) requests. By default, CORS is not enabled. An example of needing to enable CORS is when you configure SAML as your authentication method. See Configure SAML in SAS Viya Platform: Authentication.

For more information about CORS, see CORS support in Spring Framework.

Modifying one of these property values requires that you restart services. Some services restart automatically. If an impacted service does not restart after you save your changes, restart it manually. See Managing a Specific Server or Service in SAS Viya Platform: General Management of Servers and Services.

Property

Default Value

Description

allowCredentials:

false

Allows user credentials to be used in cross-origin requests.

allowedHeaders:

The comma-separated list of HTTP headers that a pre-flight request can list as allowed for use during an actual request. The special value '*' allows actual requests to send any header, but '*' cannot be used when allowCredentials is set to true.

allowedMethods:

HEAD,GET

The comma-separated list of HTTP methods that are allowed in cross-origin requests. The special value '*' allows all methods.

allowedOrigins:

The comma-separated list of origins that are allowed by default.

Note: Prior to 2023.02, if you are modifying this property, make sure that it has the same value that is assigned to the TKHTTP_CORS_ALLOWED_ORIGINS environment variable, if the environment variable is set in the sas.cas.instance.config: settings configuration instance. For more information, see FIX env.TKHTTP_CORS_ALLOWED_ORIGINS in SAS Viya Platform: SAS Cloud Analytic Services.

maxAge:

The duration of time in seconds that the response from a pre-flight request can be cached by clients.

sas.commons.web.security.csrf

Cross-Site Request Forgery (CSRF) security is enabled by default. SAS Viya protects against CSRF using the following:

  • Synchronizer Tokens: Randomly generated tokens that are associated with the user’s current session. CSRF is checked only on requests with authenticated sessions and is always skipped on GET, HEAD, TRACE, and OPTIONS requests. For more information, see Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet.
  • Header Checking: A filter that checks that the HTTP Referer header has the host and port of the requested URI or matches an optional allowlist of URIs that is configured as a comma-separated list in the sas.commons.web.security.csrf.allowedUris property.

For more information about CSRF, see Common application properties.

The following property is available for sas.commons.web.security.csrf:

Property

Description

allowedReferers:

This property is not used.

allowedUris:

The comma-separated list of referer URIs that are allowed by default. The list must contain regular expressions.

failifNoHeaders:

This property is not used.

Disable Cross-Site Request Forgery (CSRF) Checking

CAUTION

SAS strongly recommends that CSRF is enabled. Disabling CSRF is a security risk and certain functionality of the SAS Viya system might become inoperable. For example, SAS Visual Analytics requires CSRF to be enabled.

  1. To disable Cross-Site Request Forgery (CSRF) checking, create a new configuration for the security definition. On the Configurations page in SAS Environment Manager, highlight security from the View: Definitions list.
  2. Click New Configuration at the top right of the page.
  3. In the New security Configuration window, click + Add property.
  4. Enter the following:
    • Name: enable-csrf
    • Value: false
  5. Click Save.
  6. Modifying this property requires that you restart services. Some services restart automatically. If an impacted service does not restart after you save your changes, restart it manually. See Managing a Specific Server or Service in SAS Viya Platform: General Management of Servers and Services.

Spring Boot Properties

Here is the list of third-party, Spring Boot properties that you can configure. For a list of the valid property names and descriptions, see Common Application Properties.

CAUTION

When adding a property, be extremely careful. Entering the wrong property name or an invalid data type can cause SAS Viya to become inoperable.

Property

Description

Endpoints

The set of properties that are used to configure Spring Actuator endpoints.

Flyway

The set of properties that are used to configure Spring Flyway integration.

Liquibase

The set of properties that are used to configure Spring Liquibase integration.

Logging

The set of properties that are used to configure logging.

Logging.Level

The set of properties that are used to configure logging levels.

Management

The set of properties that are used to configure Spring application management.

Multipart

The set of properties that are used to configure Spring multipart handling.

Security

The set of properties that are used to configure Spring security.

Server

The set of properties that are used to configure the embedded Spring server.

Use this property to modify the session time-out interval for SAS Viya web applications. You can use either of the following tools to perform this task:

Shell

The set of properties that are used to configure the Spring remote shell.

Spring

The set of properties that are used to configure other Spring features.

Zones

Note: As of release 2023.10 of the SAS Viya platform, application multi-tenancy, which comprises multiple tenants in the same SAS Viya platform deployment, is no longer supported. Customers who support use cases that require separate tenants are encouraged to deploy the SAS Viya platform into more than one namespace on the same Kubernetes cluster.

The set of properties that are used to configure zone information for multi-tenancy. Modifying one of these property values requires you to restart the service.

Property

Description

internal.hostnames:*

The comma-separated list of internal host names that are used to access the provider zone, or that are used in a subdomain to access other zones.

Tip Be sure to specify the base host name without any tenant prefixes.

Tip If you use a load balancer as a front end to the Apache HTTP Server and microservices, you must include the fully qualified domain name of the load balancer in the list of host names.

Last updated: May 20, 2026