Official pre-built OCI VM images (Ubuntu, Debian, Android), the Windows artifact, and the os-image/ build harness.
Pre-built OS images are hosted on GitHub Container Registry.
Multi-arch (linux/amd64, linux/arm64).
| Image | Tag | IMAGE_NAME |
|---|---|---|
| Ubuntu 22.04 (Jammy) | 22.04 |
ghcr.io/cocoonstack/cocoon/ubuntu:22.04 |
| Ubuntu 24.04 (Noble) | 24.04 |
ghcr.io/cocoonstack/cocoon/ubuntu:24.04 |
| Ubuntu 24.04 + Chrome | 24.04-chrome |
ghcr.io/cocoonstack/cocoon/ubuntu:24.04-chrome |
| Ubuntu 24.04 + Xfce | 24.04-xface |
ghcr.io/cocoonstack/cocoon/ubuntu:24.04-xface |
| Ubuntu 24.04 + PicoClaw | 24.04-picoclaw |
ghcr.io/cocoonstack/cocoon/ubuntu:24.04-picoclaw |
Multi-arch (linux/amd64, linux/arm64). Built from os-image/debian/13/ with
the Debian 13 cloud kernel, Cocoon boot and networking hooks, and the
checksum-verified agent.
| Image | Tag | IMAGE_NAME |
|---|---|---|
| Debian 13 (Trixie) | 13 |
ghcr.io/cocoonstack/cocoon/debian:13 |
The three bare android/ tags run Android via Redroid directly as PID 1 in the VM — no Ubuntu/systemd layer — and are linux/amd64 only; the 16.0-gms-h264 image is Ubuntu-based, builds under ubuntu/ on the default multi-arch matrix, and behaves like the Ubuntu images below.
| Image | Tag | IMAGE_NAME |
|---|---|---|
| Android 14 | 14.0 |
ghcr.io/cocoonstack/cocoon/android:14.0 |
| Android 15 | 15.0 |
ghcr.io/cocoonstack/cocoon/android:15.0 |
| Android 15 + GMS + ARM translation | 15.0-gms |
ghcr.io/cocoonstack/cocoon/android:15.0-gms |
| Android 16 + GMS + H.264 (README) | 16.0-gms-h264 |
ghcr.io/cocoonstack/cocoon/android:16.0-gms-h264 |
Access via adb connect <vm-ip>:5555 or scrcpy -s <vm-ip>:5555 --no-audio.
The 16.0-gms-h264 image is Ubuntu+Redroid-based (built from os-image/ubuntu/22.04-redroid-16.0-gms-h264/), unlike the bare os-image/android/ family above.
The 15.0-gms variant adds Google Play services (GmsCore, Play Store, GSF)
and libndk_translation so arm64-only APKs run on the x86_64 host. It runs
ordinary arm64 apps (verified with Meituan). It does not run apps whose
native layer hooks JNI or self-checks for tampering (WeChat, QQ, Alipay,
banking, most anti-cheat games): the translator’s proxied JNIEnv breaks those
assumptions and they crash at startup — an x86 binary-translation limit, not a
config gap. Hardened arm64 apps need an arm64 host running the plain 15.0
image (no translation). See os-image/android/15.0-gms/README.md.
linux/amd64 only. Build automation and pre-built images are maintained in cocoonstack/windows.
Pre-built images are published to GHCR as split qcow2 parts (each part ≤ 1.9 GiB to stay within the GHCR per-layer limit):
ghcr.io/cocoonstack/windows/win11:25h2 # moving alias, latest good build
ghcr.io/cocoonstack/windows/win11:25h2-<YYYYMMDD> # dated immutable tag
The Windows image is published as an OCI artifact (split qcow2 parts pushed via ORAS), not a runnable OCI container image — use oras pull (not cocoon image pull or docker pull).
Pull and import into Cocoon:
# 1. Pull split parts via oras (https://oras.land)
oras pull ghcr.io/cocoonstack/windows/win11:25h2
# 2. Verify the split parts
sha256sum -c SHA256SUMS
# 3. Import the parts into Cocoon in order
cocoon image import win11-25h2 windows-11-25h2.qcow2.*.qcow2.part
cocoon vm run --windows --name win11 --cpu 4 --memory 4G win11-25h2
See cocoonstack/windows for build steps and version requirements.
IMAGE_NAME="ghcr.io/cocoonstack/cocoon/ubuntu:24.04" bash start.sh # run from os-image/ in the repo
IMAGE_NAME is required: start.sh has no default image.
IMAGE_NAME="ghcr.io/cocoonstack/cocoon/android:14.0" bash start.sh # run from os-image/ in the repo
Every official OS image bakes the following on top of its base distro:
cocoon vm exec (kubectl-style stdin/stdout/stderr/exit, no SSH/network dependency). Ubuntu and Debian (and the Ubuntu-based android:16.0-gms-h264) use a systemd unit; the three bare android/ tags use /system/etc/init/cocoon-agent.rc.android/ tags) — /system/etc/init/cocoon-power.rc. redroid’s early-init removes /dev/input, so nothing would read the ACPI power button; the service recreates the button’s node and turns a press into an Android shutdown, so cocoon vm stop powers the guest off cleanly instead of waiting out stop_timeout_seconds.android:16.0-gms-h264) — openssh-server enabled with PermitRootLogin yes. Default credentials are root:cocoon. SSH covers the human-on-keyboard case while cocoon-agent handles control-plane traffic.Default credentials apply to fresh VMs. If you fork an image you should rotate the root password and (if you keep sshd) flip PermitRootLogin back to no once you have a non-root sudoer.
All Ubuntu and Debian images configure systemd-networkd with ClientIdentifier=mac in their DHCP settings. This ensures that when a VM is cloned from a snapshot, each clone uses its unique MAC address as the DHCP client identifier instead of the machine-id-derived DUID. Without this, clones from the same snapshot share an identical DUID and dnsmasq treats them as a single client, causing IP conflicts.
The setting is applied in two places per family:
os-image/ubuntu/network.sh and os-image/debian/network.sh — the initramfs DHCP fallback path20-wired.network — the default systemd-networkd config/dev/kvm must be writable)jq, wget, mkfs.erofs, mkfs.ext4 (start.sh installs any that are missing via sudo apt-get)sudo required on every run to set CAP_NET_ADMIN on the hypervisor binaryIMAGE_NAME in a daemonless manner via cranevmlinuz) and initramfs (initrd.img) from the image, and compresses the rootfs into EROFSVisit the GitHub Packages page for the full list of images and tags:
https://github.com/orgs/cocoonstack/packages?repo_name=cocoon