<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can we use internal IP within organization network for ingress LoadBalancer for SAS Viya on AKS? in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Can-we-use-internal-IP-within-organization-network-for-ingress/m-p/986596#M30799</link>
    <description>The Viya platform does not require it be publicly accessible, but using SCIM from Entra ID as you mention would require this unless you use a provisioning agent that is part of the internal network:&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/app-provisioning/on-premises-scim-provisioning" target="_blank"&gt;https://learn.microsoft.com/en-us/entra/identity/app-provisioning/on-premises-scim-provisioning&lt;/A&gt;</description>
    <pubDate>Tue, 21 Apr 2026 12:47:40 GMT</pubDate>
    <dc:creator>gwootton</dc:creator>
    <dc:date>2026-04-21T12:47:40Z</dc:date>
    <item>
      <title>Can we use internal IP within organization network for ingress LoadBalancer for SAS Viya on AKS?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Can-we-use-internal-IP-within-organization-network-for-ingress/m-p/986433#M30792</link>
      <description>&lt;DIV&gt;&lt;P&gt;Hello All, Good Afternoon&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I would like to check and align on the possibility of using an &lt;STRONG&gt;internal IP within the organization network&lt;/STRONG&gt; for the ingress &lt;CODE&gt;LoadBalancer&lt;/CODE&gt; when deploying &lt;STRONG&gt;SAS Viya on Azure Kubernetes Service (AKS)&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Currently, SAS Viya is deployed using the standard SAS‑recommended approach, where the ingress controller is exposed through a Kubernetes &lt;CODE&gt;LoadBalancer&lt;/CODE&gt; service backed by an &lt;STRONG&gt;external (public) Azure Load Balancer&lt;/STRONG&gt;. This is the model documented and supported by SAS.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The question raised is whether we can instead expose the ingress controller using an internal&lt;STRONG&gt;&amp;nbsp;Azure Load Balancer with a private IP&lt;/STRONG&gt;, allowing access only from within the corporate network (for example, via VNet peering, VPN, or ExpressRoute), and thereby avoiding public exposure.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;From an Azure and AKS perspective, using an internal load balancer for ingress is technically possible. However, there are several points that would need careful consideration:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SAS documentation does not explicitly describe or validate the use of an internal (private) cloud load balancer for SAS Viya ingress.&lt;/LI&gt;&lt;LI&gt;The current environment uses integrations such as &lt;STRONG&gt;SCIM with Microsoft Entra ID&lt;/STRONG&gt;, which rely on external reachability. Using an internal‑only ingress may require additional network architecture (for example, private connectivity or specific routing) to ensure these integrations continue to function.&lt;/LI&gt;&lt;LI&gt;Switching from an external to an internal ingress cannot be performed in place and would likely require a &lt;STRONG&gt;redeployment&lt;/STRONG&gt; with revised ingress configuration.&lt;/LI&gt;&lt;LI&gt;This approach would fall outside the standard, documented SAS deployment model and would therefore require additional validation and confirmation of supportability.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Before proceeding further, it would be helpful to clarify:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Whether internal‑only access is a strict requirement&lt;/LI&gt;&lt;LI&gt;Whether the additional design and validation effort is acceptable&lt;/LI&gt;&lt;LI&gt;Whether we should seek explicit confirmation from SAS regarding support for this deployment model&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please let me know your thoughts or if you would like to discuss this further in a dedicated session.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;BR /&gt;&lt;STRONG&gt;Asif&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 16 Apr 2026 11:56:49 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Can-we-use-internal-IP-within-organization-network-for-ingress/m-p/986433#M30792</guid>
      <dc:creator>Asif_Ali_Khan</dc:creator>
      <dc:date>2026-04-16T11:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use internal IP within organization network for ingress LoadBalancer for SAS Viya on AKS?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Can-we-use-internal-IP-within-organization-network-for-ingress/m-p/986596#M30799</link>
      <description>The Viya platform does not require it be publicly accessible, but using SCIM from Entra ID as you mention would require this unless you use a provisioning agent that is part of the internal network:&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/app-provisioning/on-premises-scim-provisioning" target="_blank"&gt;https://learn.microsoft.com/en-us/entra/identity/app-provisioning/on-premises-scim-provisioning&lt;/A&gt;</description>
      <pubDate>Tue, 21 Apr 2026 12:47:40 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Can-we-use-internal-IP-within-organization-network-for-ingress/m-p/986596#M30799</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2026-04-21T12:47:40Z</dc:date>
    </item>
  </channel>
</rss>

