Kali Linux 虚拟机(VM)镜像构建器,通过 debos(配合 fakemachine 和 KVM)实现。
这些正是 Kali 团队 用于生成官方 Kali Linux VM 镜像的相同 构建脚本,可在 kali.org/get-kali/ 找到。
如需更多信息,请参阅:kali.org/docs/virtualization/。
立即构建 你的 Kali!
我们建议在与目标架构匹配的 Linux 主机上进行构建。
有多种方式可以准备好使用 kali-vm 构建脚本。你可以选择:
要使此脚本正常工作,它需要 KVM。不过,不需要超级用户权限。 我们将跳过在 BIOS/UEFI 中启用 KVM 的步骤。
需要 KVM 的原因是,构建实际上是在一个虚拟机(VM)内进行的,该虚拟机由构建工具 debos 即时创建。 Debos 底层使用 fakemachine,而后者又依赖 QEMU+KVM。
首先安装 git,并确保仓库已克隆到本地:```console
$ sudo apt-get install --no-install-recommends
git ca-certificates
$ git clone https://gitlab.com/kalilinux/build-scripts/kali-vm.git
$ cd ./kali-vm/
- - -
由于 QEMU/KVM 的要求,你必须属于 `kvm` 组。
你可以通过以下方式检查:```console
$ # Not a part of the group
$ grep kvm /etc/group
kvm:x:104:
$
$ # In the group
$ grep kvm /etc/group
kvm:x:104:kali
$
如果返回的行中没有出现你的用户名(例如 kali),说明你不在该组中,你必须将自己添加到 kvm 组。
你可以通过执行以下命令来完成:```console
$ sudo adduser $USER kvm
然后**注销并重新登录**以使更改生效。 <!-- 这不是关闭终端应用并重新打开,而是注销 Xfce! -->
...或者```console
$ newgrp kvm
要使用 build.sh 直接在主机上构建,请安装构建依赖项:```console
$ sudo apt-get install --no-install-recommends
debos
linux-image-amd64
parted
dosfstools e2fsprogs
zerofree
7zip bmap-tools qemu-utils xz-utils
xkb-data
<!-- This should match what is in: [Dockerfile](https://gitlab.com/kalilinux/build-scripts/kali-vm/-/blob/main/Dockerfile) & [kali.org/docs/virtualization/](https://www.kali.org/docs/virtualization/)
Alt: $ sudo apt-get install 7zip debos dosfstools qemu-utils zerofree
xkb-data is optional, just helps to validate settings - doesn't take up that much space
-->
- - -
现在你可以使用 `./build.sh`,它将直接在你的机器上构建 Kali VM 镜像。
### 在容器内构建
_我们将跳过任何容器软件的设置。_
如果你更愿意在容器内构建,你需要在你的机器上安装并配置 `docker` 或 `podman`。
- `docker` 要求将用户添加到 Docker 组,或使用 root 账户(例如 `$ sudo ./build-in-container.sh`)。
- `podman` 已经过测试,既支持 rootful(例如 `$ sudo ./build-in-container.sh`)也支持 rootless(例如 `$ ./build-in-container.sh`)。Rootless 额外需要 `crun`(例如 `$ sudo apt install crun`),因为 `runc` 无法从用户命名空间访问 `/dev/kvm`。
- - -
`build-in-container.sh` 是 `build.sh` 之上的一个包装器。它会检测要使用哪个符合 OCI 标准的容器引擎,负责在缺失时创建[容器镜像](https://gitlab.com/kalilinux/build-scripts/kali-vm/-/blob/main/Dockerfile),然后启动容器以在容器内执行构建。
你有三种方式提供容器镜像:```console
$ # Option #1 - Automated build (recommended)
$ ./build-in-container.sh
$ ./build-in-container.sh --force # If you need to rebuild the image from scratch
$
$
$
$ # Option #2 - Manual build
$ docker build -t kali-build/kali-vm .
$ # ...OR...
$ podman build -t kali-build/kali-vm .
$
$
$
$ # Option #3 - Use the pre-generated
$ docker pull registry.gitlab.com/kalilinux/build-scripts/kali-vm:latest
$ docker tag registry.gitlab.com/kalilinux/build-scripts/kali-vm:latest kali-build/kali-vm
$ # ...OR...
$ podman pull registry.gitlab.com/kalilinux/build-scripts/kali-vm:latest
$ podman tag registry.gitlab.com/kalilinux/build-scripts/kali-vm:latest kali-build/kali-vm
$
$ # ...then point the build at it:
$ ./build-in-container.sh # Locally built (automated or manual)
$ IMAGE=registry.gitlab.com/kalilinux/build-scripts/kali-vm:latest ./build-in-container.sh # Pre-generated
如果你同时安装了 docker 和 podman,build-in-container.sh 将默认使用 podman。要更改此设置,请在 ./build-in-container.sh 前加上 CONTAINER=docker:```console
$ CONTAINER=docker ./build-in-container.sh [...]
- - -
现在你可以使用 `./build-in-container.sh`(而不是 `./build.sh`)来构建镜像。
## 帮助```console
$ ./build.sh --help
Usage: build.sh [OPTIONS] [-- <debos options>]
Build a Kali Linux VM image.
Build options:
-a, --arch ARCH Build an image for this architecture (default: amd64)
Supported: amd64
-b, --branch BRANCH Kali branch used to build the image (default: kali-rolling)
Supported: kali-rolling kali-dev kali-last-snapshot
-f, --format FORMAT Format to export the image to (default: ...depends on --variant)
Supported: hyperv ova ovf qemu raw vagrant virtualbox vmware
-k, --keep Keep intermediary build artifacts
-m, --mirror URL Mirror used to build the image (default: http://http.kali.org/kali)
-o, --output DIR Output directory (default: /home/kali/kali-vm/output)
-r, --rootfs ROOTFS Rootfs to use to build the image (default: none)
-v, --variant VARIANT Variant of image to build, see below for details (default: generic)
Supported: generic hyperv qemu rootfs virtualbox vmware
-x, --version VERSION What to name the image release as (default: rolling)
-z, --zip Compress image and metadata files after the build
-h, --help Show this help and exit
VM options:
-D, --desktop DESKTOP Desktop environment installed in the image (default: xfce)
Supported: xfce e17 gnome i3 kde lxde mate none
-H, --hostname HOSTNAME Set system host name (default: kali)
-K, --keyboard KEYBOARD Set keyboard layout (default: us)
See README.md for details
-L, --locale LOCALE Set locale (default: en_US.UTF-8)
-P, --packages PKGS Install extra packages (comma/space separated list)
-s, --size SIZE Size of the disk image in GB (default: 86)
-S, --swap SWAP Swap as a partition, a file, or none (default: file)
Supported: partition file none
-T, --toolset TOOLSET The selection of tools to include in the image (default: default)
Supported: default everything headless large none
-U, --userpass USERPASS Username and password, separated by a colon (default: kali:kali)
-Z, --timezone TIMEZONE Set timezone (default: America/New_York)
Use "same" as the value for -K/-L/-Z to inherit the host's current setting.
The different variants of images are:
generic Image with all virtualization support pre-installed, default format: raw
hyperv Image pre-configured for Hyper-V "Enhanced Session Mode", default format: hyperv
qemu Image with QEMU and SPICE guest agents pre-installed, default format: qemu
rootfs Not an image, a root filesystem (no bootloader/kernel), packed in a .tar.gz
virtualbox Image with VirtualBox guest utilities pre-installed, default format: virtualbox
vmware Image with Open VM Tools pre-installed, default format: vmware
The different formats are:
hyperv VHDX disk image, powershell install scripts
ova streamOptimized VMDK disk image, OVF metadata file, packed in an OVA archive
ovf monolithicSparse VMDK disk image, OVF metadata file
qemu QCOW2 disk image, no metadata
raw sparse disk image, no metadata
vagrant underlying variant's disk image, metadata.json + Vagrantfile, packed in a box archive
virtualbox VDI disk image, .vbox metadata file
vmware 2GbMaxExtentSparse VMDK disk image, VMX metadata file
Apt caching proxy:
Auto-detected: localhost:3142 (apt-cacher-ng), localhost:8000 (squid-deb-proxy).
If detected and http_proxy is not set, http_proxy is exported automatically.