mirror of
https://github.com/CyberMind-FR/secubox-deb.git
synced 2026-07-29 22:07:24 +00:00
Build System: - Add image/lib/common.sh with shared build functions - Add profiles for vm-x64, x64-live, rpi400, espressobin-v7 - Add BUILD-SYSTEM.md documentation - Add splash screens (boot.png, tui-splash.sh, kiosk-loading.sh) - Add Plymouth theme for boot splash Package Dependencies: - Fix python3-uvicorn -> python3-uvicorn | python3-pip - Fix python3-fastapi -> python3-fastapi | python3-pip - Fix python3-httpx -> python3-httpx | python3-pip - Allows packages to install when pip-provided deps are used Documentation: - Add Build-System.md wiki page - Update _Sidebar.md with build system links - Add VM-Testing.md improvements Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
4.6 KiB
4.6 KiB
SecuBox-DEB VM Testing Guide
Test SecuBox images in QEMU or VirtualBox before deploying to hardware.
Available Images
| Image | Size | Format | Use Case |
|---|---|---|---|
secubox-vm-x64-bookworm.img |
4GB | RAW | QEMU direct boot |
secubox-vm-x64-bookworm.vdi |
~1.3GB | VDI | VirtualBox |
secubox-live-amd64-bookworm.img |
8GB | RAW | USB Live boot |
QEMU Testing
Prerequisites
# Debian/Ubuntu
sudo apt install qemu-system-x86 ovmf
# Check KVM support
lsmod | grep kvm
With KVM (Hardware Acceleration)
qemu-system-x86_64 \
-m 4096 \
-enable-kvm \
-cpu host \
-smp 4 \
-drive file=output/secubox-vm-x64-bookworm.img,format=raw,if=virtio \
-bios /usr/share/ovmf/OVMF.fd \
-net nic,model=virtio \
-net user,hostfwd=tcp::9443-:443,hostfwd=tcp::2222-:22 \
-vga virtio \
-display gtk \
-name "SecuBox-DEB"
Without KVM (Software Emulation)
For nested virtualization or systems without KVM:
qemu-system-x86_64 \
-m 2048 \
-cpu qemu64 \
-smp 2 \
-drive file=output/secubox-vm-x64-bookworm.img,format=raw,if=virtio \
-bios /usr/share/ovmf/OVMF.fd \
-net nic,model=virtio \
-net user,hostfwd=tcp::9443-:443,hostfwd=tcp::2222-:22 \
-vga std \
-display gtk \
-name "SecuBox-DEB (TCG)"
Headless Mode (Server)
qemu-system-x86_64 \
-m 4096 \
-enable-kvm \
-cpu host \
-smp 4 \
-drive file=output/secubox-vm-x64-bookworm.img,format=raw,if=virtio \
-bios /usr/share/ovmf/OVMF.fd \
-net nic,model=virtio \
-net user,hostfwd=tcp::9443-:443,hostfwd=tcp::2222-:22 \
-nographic \
-serial mon:stdio
Access Points
Once booted:
| Service | URL/Command |
|---|---|
| Web UI | https://localhost:9443 |
| SSH | ssh -p 2222 root@localhost |
Default credentials: root / secubox
VirtualBox Testing
Convert Image to VDI
qemu-img convert -f raw -O vdi \
output/secubox-vm-x64-bookworm.img \
output/secubox-vm-x64-bookworm.vdi
Create VM via CLI
# Create VM
VBoxManage createvm --name "SecuBox-DEB" --ostype "Debian_64" --register
# Configure VM
VBoxManage modifyvm "SecuBox-DEB" \
--memory 4096 \
--cpus 4 \
--firmware efi \
--nic1 nat \
--natpf1 "ssh,tcp,,2222,,22" \
--natpf1 "https,tcp,,9443,,443"
# Attach storage
VBoxManage storagectl "SecuBox-DEB" --name "SATA" --add sata --controller IntelAhci
VBoxManage storageattach "SecuBox-DEB" --storagectl "SATA" --port 0 --device 0 \
--type hdd --medium output/secubox-vm-x64-bookworm.vdi
# Start VM
VBoxManage startvm "SecuBox-DEB"
Create VM via GUI
- New VM: Name:
SecuBox-DEB, Type: Linux, Version: Debian (64-bit) - Memory: 4096 MB minimum
- Hard disk: Use existing - select
secubox-vm-x64-bookworm.vdi - Settings > System: Enable EFI
- Settings > Network: NAT with port forwarding:
- SSH: Host 2222 → Guest 22
- HTTPS: Host 9443 → Guest 443
ARM Images (QEMU)
ESPRESSObin v7 / Generic ARM64
qemu-system-aarch64 \
-M virt \
-cpu cortex-a72 \
-m 2048 \
-smp 4 \
-drive file=output/secubox-espressobin-v7-bookworm.img,format=raw,if=virtio \
-bios /usr/share/qemu-efi-aarch64/QEMU_EFI.fd \
-net nic,model=virtio \
-net user,hostfwd=tcp::9443-:443,hostfwd=tcp::2222-:22 \
-nographic
Raspberry Pi 400
qemu-system-aarch64 \
-M raspi4b \
-m 4096 \
-drive file=output/secubox-rpi-arm64-bookworm.img,format=raw,if=sd \
-net nic -net user,hostfwd=tcp::9443-:443,hostfwd=tcp::2222-:22 \
-nographic
Verification Checklist
After boot, verify:
# Connect via SSH
ssh -p 2222 root@localhost
# Check SecuBox services
systemctl status nginx
systemctl status secubox-*
# Check web UI
curl -sk https://localhost:9443 | head -20
# Check version
cat /etc/secubox/version
Troubleshooting
KVM Not Available
Could not access KVM kernel module: No such file or directory
Solution: Use TCG mode (remove -enable-kvm -cpu host) or enable virtualization in BIOS.
EFI Boot Fails
No bootable device
Solution: Ensure OVMF/UEFI firmware is installed:
sudo apt install ovmf # x86_64
sudo apt install qemu-efi-aarch64 # ARM64
Port Already in Use
Could not set up host forwarding rule 'tcp::9443-:443'
Solution: Use different host ports:
-net user,hostfwd=tcp::19443-:443,hostfwd=tcp::12222-:22
Performance Tips
- Use KVM when available (10-100x faster)
- virtio drivers for disk and network
- Allocate sufficient RAM (4GB recommended)
- Use SSD for image storage
SecuBox-DEB v1.6.0 - CyberMind