feat: add Kali Selkies desktop stack with AMD GPU accel and persistence - #2
Merged
Merged
Conversation
Optional linuxserver/docker-baseimage-selkies Kali container with AMD/Vulkan GPU passthrough for a Radeon 780M (no CUDA), documented CPU/llvmpipe fallback, the host /home/jond bind-mounted in, and persisted /config + /opt so manually installed .deb apps (e.g. Obsidian) survive recreation. Skips no-new-privileges since Kali's toolkit depends on sudo — documented in AGENTS.md and HARD-WON-GOTCHAS.md alongside the rest of the service reference and setup docs. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
kali-desktopservice: LinuxServer Selkies-based Kali Linux desktop (linuxserver/docker-baseimage-selkies), off by default in the rootinclude:./dev/dri(DRINODE/DRI_NODE, no CUDA — NVIDIA-only), with a documented CPU/Mesa-llvmpipe fallback./home/jond; persists/configand/optso manually installed.debapps (e.g. Obsidian) survive--force-recreate, with both a root-free and anapt/dpkginstall path documented.no-new-privileges:true(breakssudo, which Kali's toolkit depends on), offset by loopback-bound ports — documented inAGENTS.mdanddocs/HARD-WON-GOTCHAS.md.README.md,.env.example,.gitignore, and the rootdocker-compose.ymlto match this repo's existing service conventions.Test plan
docker compose configvalidated standalone (kali-desktop/) and as part of the full stack with the service temporarily enabled — both clean.docker compose up -d kali-desktopon the target host and confirm the desktop loads athttps://localhost:3011.Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com