- Add build-kali-arm64 CI job using native ubuntu-24.04-arm runner
- Reuse existing Dockerfile.kali (all packages available on ARM64)
- Add policy-rc.d workaround to prevent service startup during build
- Add pentestagent-kali-arm64 docker-compose service (profile: kali-arm64)
The kali-arm64 image is tagged as :kali-arm64 in GHCR.
Why:
- Persist artifacts to /app/loot so container outputs remain available when mounted.
- Avoid mandatory host chown; make chown opt-in via CHOWN_ON_START to prevent accidental ownership changes.
- Bind msfrpcd to 127.0.0.1 by default and add EXPOSE_MSF_RPC opt-in to avoid exposing RPC to host network.
- Replace crashing assertion on missing default model with a friendly CLI/TUI error path.
- Add .dockerignore to reduce build context and avoid copying unnecessary files.