Apple's Native Containers on macOS: What They Change for Running Kali Linux

Apple introduced a powerful new feature in WWDC 25—native containerization for macOS, which allows users to run Open Container Initiative (OCI) images like Kali Linux using lightweight virtual machines. This means cybersecurity professionals can now spin up secure, fast Kali environments directly on macOS Sequoia (15) without needing Docker Desktop. The system leverages Apple Silicon and provides stronger isolation, faster cold starts, and compatibility with popular OCI images. Full support is expected with macOS Tahoe (26), bridging the gap between Mac users and Linux-based security tools.

Jul 30, 2025 - 10:10
Updated: 6 days ago
108.7k
Apple's Native Containers on macOS: What They Change for Running Kali Linux

Quick answer: Apple's open-source container tool runs OCI Linux containers on Apple silicon Macs, giving each container its own lightweight VM instead of sharing one VM like Docker Desktop. You can run the kalilinux/kali-rolling image with it, but it has no desktop, so keep a full Kali VM for network-level labs.

Key takeaways

  • Apple container runs each OCI container in its own lightweight VM; it needs Apple silicon.
  • Kali's official image supports ARM64, so it runs on Apple silicon.
  • It suits quick command-line work, not a full graphical or bridged-network lab.
  • The software is new; verify requirements and commands against the project README.

What Apple announced

At WWDC 2025 Apple introduced two open-source projects for running Linux containers on a Mac: container, a command-line tool, and Containerization, the Swift framework underneath it. Both are published on GitHub (apple/container). They run standard OCI container images, so images from public registries work.

The key design difference from Docker Desktop is isolation. Docker on a Mac runs all containers inside one shared Linux VM. Apple's tool starts a small, lightweight virtual machine for each container. The idea is a stronger boundary between containers and faster start-up, and it is built on Apple's Virtualization framework.

What you need

  • A Mac with Apple silicon. Intel Macs are not supported.
  • A recent macOS. The tool was previewed on macOS 15 with networking limitations. Apple recommends macOS 26 or later for the full feature set, so check the project README for the current requirement.
  • The installer package from the project's GitHub releases page. Read the README for the current install method rather than trusting an older command.

Running Kali with it

Kali publishes an official container image, kalilinux/kali-rolling, which supports ARM64, so it runs on Apple silicon. After installation, start the system service and run the image:

container system start
container run --rm -it kalilinux/kali-rolling

The first command may offer to download a recommended Linux kernel. Accept it. To keep your work between runs, mount a folder from your Mac:

container run --rm -it -v "$PWD":/work -w /work kalilinux/kali-rolling

The Kali container image is small and does not include the full toolset (see the Kali documentation for metapackage names). Install what you need inside it:

apt update
apt install -y kali-tools-top10 # or kali-linux-headless for a larger set

Options and syntax may change between releases of the tool, so use container --help and the README as the final authority.

How it compares with other ways to run Kali on a Mac

Apple containerDocker DesktopUTM, VMware Fusion or Parallels VM
ModelOne lightweight VM per containerAll containers in one shared VMOne full VM with its own desktop
Graphical Kali desktopNoNoYes
Network controlContainer networking behind the hostContainer networking via Docker's VMBridged and host-only adapters possible
Best forQuick command-line tools, scripts, isolated experimentsExisting Docker workflowsFull labs, wireless and network-level testing

What it does not change for security work

  • It is not a full lab. Many exercises need a desktop, bridged networking, raw packet access on your LAN or USB adapters. A container sitting behind the Mac's networking is a poor fit for those. Use a VM for them.
  • Tools run in a container, not on the host. That is good for isolation of untrusted tools, but check how file mounts expose your Mac's folders. Mount only the directory you need.
  • It is new software. Expect changes, bugs and gaps. Check the project's issues and release notes.
  • Authorisation still applies. Scan or test only systems you own or have written permission to test.

A sensible way to use it

Use Apple container for quick tasks such as running Nmap against a lab VM, parsing files with command-line tools or testing a script in a clean Kali environment. Keep a proper Kali VM for long engagements and anything graphical. Treat a container as disposable: save results to a mounted folder and expect everything else to disappear when it exits with --rm.

Next steps

To learn Kali properly, see the KLCP course. If containers are new to you, Docker training covers the concepts these tools share. Related reading: running Kali on macOS with Apple's containerization.

Frequently Asked Questions

It is an open-source command-line tool from Apple that runs OCI Linux containers on Apple silicon Macs. Each container runs in its own lightweight virtual machine, built on Apple's Containerization framework.

Not for simple command-line use. Apple's container tool can run the Kali image directly. Docker Desktop is still useful for existing Docker workflows, and a VM is better for full graphical or network-level labs.

No. It requires an Apple silicon Mac. Intel Mac users should keep using Docker Desktop or a virtual machine to run Kali, as the new tool does not support their hardware.

It was previewed on macOS 15 with networking limitations, and Apple recommends macOS 26 or later for full support. Check the project's README for the current requirement before installing.

Start the service with container system start, then run container run --rm -it kalilinux/kali-rolling. Mount a folder with -v to keep files, and install the tools you need inside the container with apt.

No. It is lighter and quick for command-line tasks, but it lacks a desktop and the network flexibility of a VM. Use a full VM for wireless, bridged-network and graphical testing.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.