
Scripts to build Kali cloud images (fork of https://salsa.debian.org/cloud-team/debian-cloud-images)
Kali Linux cloud image builder via FAI (Fully Automatic Installation), forked from Debian Cloud Images.
These are the same build-scripts that the Kali team uses to generate the official Kali Linux cloud images, found on kali.org/get-kali/.
For more information, please see: kali.org/docs/cloud/ as well as kali.org/docs/troubleshooting/common-cloud-setup/.
Build your Kali, today!
We recommend building on a Linux-based host, which matches the desired architecture.
There are various ways to get ready to use kali-cloud build-script. You can either:
build.sh - Build straight from your machinebuild-in-container.sh - Build from within a container (such as Docker or Podman) For build.sh to work, it will require super user access (e.g. sudo or a rootful container). However, KVM isn't required.
First install git, and make sure that the repository is cloned locally:
$ sudo apt-get install --no-install-recommends \
git ca-certificates
$ git clone https://gitlab.com/kalilinux/build-scripts/kali-cloud.git
$ cd ./kali-cloud/
To build directly on your host, with build.sh, install the build dependencies:
$ sudo apt-get install --no-install-recommends \
python3-minimal libpython3-stdlib python3-yaml python3-libcloud python3-marshmallow python3-httpx python3-pytest \
fai-server fai-setup-storage \
sudo \
qemu-utils qemu-user-binfmt \
fdisk \
udev \
dosfstools \
apt-utils \
debsums
NOTE: Depending on the age of the OS version, you may need to use qemu-user-static (legacy) rather than qemu-user-binfmt (modern/current/up-to-date).
NOTE: qemu-user-static/qemu-user-binfmt is only required if you are building cross-architecture (e.g. amd64 host, building an arm64 image).
Now you can use ./build.sh, which will build a Kali cloud image straight on your machine.
If you are NOT using Kali as the base OS, you will need to install Kali's kali-archive-keyring in order for fai to fetch Kali's packages.
$ sudo apt-get install --no-install-recommends \
wget ca-certificates
$ wget https://http.kali.org/pool/main/k/kali-archive-keyring/kali-archive-keyring_20YY.X_all.deb
$ sudo apt-get install ./kali-archive-keyring_*_all.deb
NOTE: Replace 20YY.X with the values shown here, in kali-archive-keyring.
Now you can follow Build From The Host (Kali) to install build dependencies.
We will skip over setting up any container software.
If you prefer to build from within a container, you will need to install and configure either docker or podman on your machine.
docker requires the user to be added to the Docker group, or using the root account (e.g. $ sudo ./build-in-container.sh).podman has been tested with rootful (e.g. $ sudo ./build-in-container.sh). If run rootless, build-in-container.sh will attempt to elevate itself via sudo, or fall back to reconfiguring the podman machine as rootful, see Known Limitations.build-in-container.sh is a wrapper on top of build.sh. It detects which OCI-compliant container engine to use, takes care of creating the container image if missing, and then it starts the container to perform the build from within.
You have three ways to provide the container image:
$ # Option #1 - Automated build (recommended)
$ ./build-in-container.sh
$ ./build-in-container.sh --force # If you need to rebuild the image from scratch
$
$
$
$ # Option #2 - Manual build
$ docker build -t kali-build/kali-cloud .
$ # ...OR...
$ podman build -t kali-build/kali-cloud .
$
$
$
$ # Option #3 - Use the pre-generated
$ docker pull registry.gitlab.com/kalilinux/build-scripts/kali-cloud:latest
$ docker tag registry.gitlab.com/kalilinux/build-scripts/kali-cloud:latest kali-build/kali-cloud
$ # ...OR...
$ podman pull registry.gitlab.com/kalilinux/build-scripts/kali-cloud:latest
$ podman tag registry.gitlab.com/kalilinux/build-scripts/kali-cloud:latest kali-build/kali-cloud
$
$ # ...then point the build at it:
$ ./build-in-container.sh # Locally built (automated or manual)
$ IMAGE=registry.gitlab.com/kalilinux/build-scripts/kali-cloud:latest ./build-in-container.sh # Pre-generated
If you have both docker and podman installed, build-in-container.sh will default to using podman. To change this, prefix CONTAINER=docker before ./build-in-container.sh:
$ CONTAINER=docker ./build-in-container.sh [...]
Now you can use ./build-in-container.sh (rather than ./build.sh), to build an image.
$ ./build.sh --help
Usage: build.sh [OPTIONS]
Build a Kali Linux Cloud image.
Build options:
-a, --arch ARCH Build an image for this architecture (default: amd64)
Supported: amd64 arm64
-b, --branch BRANCH Kali branch used to build the image (default: kali-rolling)
Supported: kali-rolling kali-dev kali-last-snapshot
-k, --keep Keep intermediary build artifacts
-m, --mirror URL Mirror used to build the image (default: http://http.kali.org/kali)
-o, --output DIR Output directory (default: /home/kali/kali-cloud/output)
-v, --variant VARIANT Cloud platform/target image to build (default: genericcloud)
Supported: genericcloud azure ec2 gce generic nocloud
-x, --version VERSION What to name the image release as (default: rolling)
-z, --zip Compress image after the build
-h, --help Show this help and exit
Cloud options:
-H, --hostname HOSTNAME Set system host name (default: kali)
-P, --packages PKGS Install extra packages (comma/space separated list)
-s, --size SIZE Size of the disk image in GB (default: ...depends on --variant)
-T, --toolset TOOLSET The selection of tools to include in the image (default: default)
Supported: default minimal
Apt caching proxy:
Auto-detected: localhost:3142 (apt-cacher-ng), localhost:8000 (squid-deb-proxy).
If detected and --mirror is not set, the mirror is routed via the proxy.