As of recent times (discovered in 2025...) Kali actually is publishing GenericCloud images. They can be downloaded here. These just work - like every other distro. They are a minimal kali-install, with no GUI, and a very limited amount of tools installed. It can be tailored as per the user's needs, following this documentation.
Kali Linux is not maintaining their own desktop-enabled cloud images. Therefore we need to create them manually. To create a Kali image, follow this article. The image is built with tightvncserver enabled for the root user, with a default password ("kaliVNC"). Cloud-init is configured to not disable the root user. This makes it possible to SSH into the root account, and the keypair injected from Openstack will be valid for root login.
This article describes how to build the image on a Linux computer, with KVM/libvirt running locally.
sudo apt update && sudo apt upgrade. Reboot if necessary.apt install cloud-initdatasource_list: [ OpenStack, ConfigDrive, Ec2 ] to /etc/cloud/cloud.cfg.d/99_openstack.cfgsystemctl enable cloud-initsystemctl enable cloud-final/etc/default/grub, and make sure that the variable GRUB_CMDLINE_LINUX_DEFAULT contains console=ttyS0 console=tty0 (if there's other content in this variable that's fine. Just add this to the end of the string.quietupdate-grubsystemctl enable sshtightvncserver and dbus-x11vncservervncserver -kill :1Create /usr/local/bin/vncserv and paste this content
#!/bin/bash
PATH="$PATH:/usr/bin"
DISPLAY="1"
DEPTH="24"
GEOMETRY="1280x960"
OPTIONS="-depth ${DEPTH} -geometry ${GEOMETRY} :${DISPLAY}"
case "$1" in
start)
/usr/bin/vncserver ${OPTIONS}
;;
stop)
/usr/bin/vncserver -kill :${DISPLAY}
;;
restart)
$0 stop
$0 start
;;
esac
exit 0 |
chmod 755 /usr/local/bin/vncservCreate /lib/systemd/system/vncserv.service and paste this content
[Unit] Description=VNC Server [Service] Type=forking ExecStart=/usr/local/bin/vncserv start ExecStop=/usr/local/bin/vncserv stop ExecReload=/usr/local/bin/vncserv restart User=kali [Install] WantedBy=multi-user.target |
Run systemctl daemon-reload; systemctl enable vncserv
virt-sysprep -d <vm-name>