BookmarkSubscribeRSS Feed

Private Docker Publishing Destination and SAS Container Runtime Example – Part 1: The Concept

Started 2 weeks ago by
Modified 2 weeks ago by
Views 91

Bogdan Teleuca and Mike Goddard have posted extensively about publishing SAS models and decisions to container destinations, particularly on Microsoft Azure. Here, I’m going to illustrate how to use the Private Docker publishing destination to publish a SAS decision—the same applies to a SAS model—and then run it using SAS Container Runtime (or SCR), in a completely cloud-provider-agnostic environment.

 

 

What are we going to achieve?

 

The ultimate goal is to run a SAS model or SAS decision against input data in the most lightweight way possible, independently of SAS Viya.

 

That’s where SAS Container Runtime (SCR) comes into play. It provides a lightweight runtime environment for executing SAS models and decisions packaged as container images.

 

Note: SAS Container Runtime is used for SAS models and decisions. Python and R models use a different type of container, but the overall principles are similar. Since the focus of this example is on SAS assets, we’ll concentrate on SAS Container Runtime.

 

In our environment, which does not rely on Azure or any other specific cloud provider, we have:

 

  • A Kubernetes cluster where SAS Viya is deployed.
  • A Private Docker registry where we want to build and store dedicated container images embedding the SAS intelligence from our models or decisions.
  • A container runtime environment where we can run those models and decisions in a very lightweight fashion.
  • Optionally, another Kubernetes cluster, independent of SAS Viya, where those models and decisions can be deployed in a more enterprise-ready and scalable way.

 

The following diagram illustrates the different components and the overall workflow.

 

nir_post_112_01_scr_workflow.png

Select any image to see a larger version.
Mobile users: To view the images, select the "Full" version at the bottom of the page.

 

 

The workflow

 

The workflow illustrated above can be broken down into four main steps:

 

  1. As part of model or decision development, we publish a SAS model or decision to the configured Private Docker publishing destination. This builds a container image containing the SAS model or decision and pushes it to the Private Docker registry.
  2. After publishing, we can validate the model or decision using the Publishing Validation capability. The published image is pulled from the registry and run against a Kubernetes cluster. This can be the Kubernetes cluster hosting SAS Viya or another Kubernetes cluster. This step is optional.
  3. We then start moving into the production side of things. At its simplest, we can pull the published image and run it using a container runtime, provide some input data, and retrieve the resulting scores or decisions. This gives us a lightweight way of running our SAS intelligence independently of SAS Viya.
  4. Alternatively, we can deploy and run those containers using Kubernetes for a more structured, governed, and scalable production environment. This could again be the SAS Viya Kubernetes cluster or a completely separate Kubernetes cluster.

 

We won’t cover that last scenario here, as it involves additional deployment considerations.

 

However, the course SAS® Container Runtime: Architecture and Deployment on Azure Cloud illustrates what is required to deploy and run these models and decisions in Kubernetes on Microsoft Azure. While Azure-specific, many of the underlying concepts apply to other Kubernetes environments as well.

 

For this example, we’ll focus primarily on the lightweight approach: publishing our SAS decision as a container image and running that image directly using a container runtime.

 

 

What do we need?

 

Now that we’ve set the scene, let’s identify the information we need to complete the process.

 

For the Private Docker publishing destination, we need:

 

  • Base repository URL: the container registry location (URI) where the generated container images will be published.
  • Docker registry user ID: a user ID with permission to connect to and push images to the container registry.
  • Docker registry password: the password associated with that user ID.

 

For the optional Publishing Validation step, we also need access to a Kubernetes cluster:

 

  • Kubernetes URL: the URL of the Kubernetes cluster where the published container image can be run for validation.
  • Kubernetes key: a client private key used to connect to the Kubernetes cluster.
  • Kubernetes certificate: the client certificate associated with the private key.

 

The Kubernetes key and certificate are usually found in the kubeconfig file and can be provided by a Kubernetes administrator. Make sure to use a key and certificate with an appropriate scope (for example, permissions to deploy containers) on your cluster.

 

We now have everything we need: we understand the architecture and workflow, and we have gathered the credentials and configuration details required to put it into practice.

 

In Part 2, we’ll move from theory to practice and walk through the steps required to configure the publishing destination, publish the SAS decision, and run it using SAS Container Runtime.

 

A big thank you to Adam Bullock for his help and insights on this topic.

 

Thanks for reading!

 

 

Find more articles from SAS Global Enablement and Learning here.

Contributors
Version history
Last update:
2 weeks ago
Updated by:

Viya Copilot Motion Graphic.gifViya Copilot Motion Graphic

Ready to see what SAS Viya Copilot can do?

Visit the Tips & Tricks page for setup guidance, demos, and practical examples that show how Copilot supports your workflows.

Get Started →

SAS AI and Machine Learning Courses

The rapid growth of AI technologies is driving an AI skills gap and demand for AI talent. Ready to grow your AI literacy? SAS offers free ways to get started for beginners, business leaders, and analytics professionals of all skill levels. Your future self will thank you.

Get started

Article Tags