Microsoft makes WSL Containers generally available, bringing Linux containers to Windows

New wslc.exe CLI, enterprise security controls and VS Code integration land as Docker Compose-style support remains in the works

By LineZotpaper
Published
Read Time2 min
Microsoft has made WSL Containers generally available, extending the Windows Subsystem for Linux beyond running Linux distributions to natively build, run and deploy Linux containers on Windows. The feature, delivered by running wsl --update, introduces a new wslc.exe command-line tool and an API that lets native Windows apps launch and interact with Linux containers programmatically.

The general availability release adds several capabilities missing during the preview period, including restarting containers, copying files in and out, health checks, network connect and disconnect commands, real-time container events, mount support and configurable storage locations.

Microsoft said the new API unlocks scenarios such as running local AI workloads or using cloud-based containerized applications locally. The company also ships container.exe as a built-in alias, so developers can run familiar container commands without learning a new interface.

The release brings enterprise controls as well. WSL Containers integrates with Microsoft Defender for Endpoint, allowing security teams to see process, file and network activity inside containers and relate it back to the Windows host. Microsoft Intune can disable WSL Containers entirely or restrict developers to images from approved container registries.

"With container registry allow lists, administrators can define approved registries and help ensure developers only pull container images from that list, that meet organizational security and compliance requirements," Microsoft noted.

Microsoft is also working with the developer ecosystem. VS Code Dev Containers can use wslc as their default driver, while Aspire and the VS Code Containers extension now support WSL Containers.

The most requested missing feature, Docker Compose-style support, is next. "Our aim is for wsl compose up to work with your existing compose.yaml files, unchanged," Microsoft said. "We've started on this and hope to share more soon."

Microsoft is also working on WSL's underlying networking and cross-OS file performance. The company says WSL Containers can already deliver up to 2x faster performance when accessing Windows files from Linux environments.

§

Analysis

Why This Matters

  • Gives Windows developers a first-party route to run Linux containers without relying on separate third-party tools, potentially reshaping daily container workflows.
  • Brings container workloads, including local AI development, into a managed Windows environment with security controls aimed at enterprise adoption.
  • The promised wsl compose up support, when it lands, could make the feature a practical replacement for existing compose-based setups.

Background

WSL has been Microsoft's compatibility layer for running Linux environments on Windows, popular with developers who want a Linux toolchain without leaving the Windows desktop or running a full virtual machine. Historically, running Linux containers on Windows relied on separate tooling such as Docker Desktop, which uses a Linux backend virtual machine. WSL Containers aims to fold this capability deeper into Windows itself, with management, security and registry controls attached.

Key Perspectives

Developers: Gain a first-party way to build and run Linux containers with integration into VS Code and support for local AI workloads. The commitment to keep existing compose.yaml files working unchanged is central to adoption. IT and security administrators: Defender for Endpoint visibility and Intune policy controls, including registry allow lists, offer governance over which container images developers can pull and run. Critics/Skeptics: Docker Compose support remains missing despite being the most requested feature, so the tool may not yet replace established container workflows. Real-world performance and networking maturity will need verification beyond Microsoft's own benchmarks.

What to Watch

  • Timing of wsl compose up and whether it works with existing compose.yaml files unchanged.
  • Adoption of wslc as the default driver in VS Code Dev Containers and broader ecosystem uptake.
  • Independent validation of the claimed 2x faster file access performance in production workloads.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.