Apple's Native Containers on macOS: What They Change for Running Kali Linux
Apple introduced a powerful new feature in WWDC 25—native containerization for macOS, which allows users to run Open Container Initiative (OCI) images like Kali Linux using lightweight virtual machines. This means cybersecurity professionals can now spin up secure, fast Kali environments directly on macOS Sequoia (15) without needing Docker Desktop. The system leverages Apple Silicon and provides stronger isolation, faster cold starts, and compatibility with popular OCI images. Full support is expected with macOS Tahoe (26), bridging the gap between Mac users and Linux-based security tools.
Quick answer: Apple's open-source container tool runs OCI Linux containers on Apple silicon Macs, giving each container its own lightweight VM instead of sharing one VM like Docker Desktop. You can run the kalilinux/kali-rolling image with it, but it has no desktop, so keep a full Kali VM for network-level labs.
Key takeaways
- Apple container runs each OCI container in its own lightweight VM; it needs Apple silicon.
- Kali's official image supports ARM64, so it runs on Apple silicon.
- It suits quick command-line work, not a full graphical or bridged-network lab.
- The software is new; verify requirements and commands against the project README.
What Apple announced
At WWDC 2025 Apple introduced two open-source projects for running Linux containers on a Mac: container, a command-line tool, and Containerization, the Swift framework underneath it. Both are published on GitHub (apple/container). They run standard OCI container images, so images from public registries work.
The key design difference from Docker Desktop is isolation. Docker on a Mac runs all containers inside one shared Linux VM. Apple's tool starts a small, lightweight virtual machine for each container. The idea is a stronger boundary between containers and faster start-up, and it is built on Apple's Virtualization framework.
What you need
- A Mac with Apple silicon. Intel Macs are not supported.
- A recent macOS. The tool was previewed on macOS 15 with networking limitations. Apple recommends macOS 26 or later for the full feature set, so check the project README for the current requirement.
- The installer package from the project's GitHub releases page. Read the README for the current install method rather than trusting an older command.
Running Kali with it
Kali publishes an official container image, kalilinux/kali-rolling, which supports ARM64, so it runs on Apple silicon. After installation, start the system service and run the image:
container system start
container run --rm -it kalilinux/kali-rolling
The first command may offer to download a recommended Linux kernel. Accept it. To keep your work between runs, mount a folder from your Mac:
container run --rm -it -v "$PWD":/work -w /work kalilinux/kali-rolling
The Kali container image is small and does not include the full toolset (see the Kali documentation for metapackage names). Install what you need inside it:
apt update
apt install -y kali-tools-top10 # or kali-linux-headless for a larger set
Options and syntax may change between releases of the tool, so use container --help and the README as the final authority.
How it compares with other ways to run Kali on a Mac
| Apple container | Docker Desktop | UTM, VMware Fusion or Parallels VM | |
|---|---|---|---|
| Model | One lightweight VM per container | All containers in one shared VM | One full VM with its own desktop |
| Graphical Kali desktop | No | No | Yes |
| Network control | Container networking behind the host | Container networking via Docker's VM | Bridged and host-only adapters possible |
| Best for | Quick command-line tools, scripts, isolated experiments | Existing Docker workflows | Full labs, wireless and network-level testing |
What it does not change for security work
- It is not a full lab. Many exercises need a desktop, bridged networking, raw packet access on your LAN or USB adapters. A container sitting behind the Mac's networking is a poor fit for those. Use a VM for them.
- Tools run in a container, not on the host. That is good for isolation of untrusted tools, but check how file mounts expose your Mac's folders. Mount only the directory you need.
- It is new software. Expect changes, bugs and gaps. Check the project's issues and release notes.
- Authorisation still applies. Scan or test only systems you own or have written permission to test.
A sensible way to use it
Use Apple container for quick tasks such as running Nmap against a lab VM, parsing files with command-line tools or testing a script in a clean Kali environment. Keep a proper Kali VM for long engagements and anything graphical. Treat a container as disposable: save results to a mounted folder and expect everything else to disappear when it exits with --rm.
Next steps
To learn Kali properly, see the KLCP course. If containers are new to you, Docker training covers the concepts these tools share. Related reading: running Kali on macOS with Apple's containerization.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0