The general availability release adds several capabilities missing during the preview period, including restarting containers, copying files in and out, health checks, network connect and disconnect commands, real-time container events, mount support and configurable storage locations.
Microsoft said the new API unlocks scenarios such as running local AI workloads or using cloud-based containerized applications locally. The company also ships container.exe as a built-in alias, so developers can run familiar container commands without learning a new interface.
The release brings enterprise controls as well. WSL Containers integrates with Microsoft Defender for Endpoint, allowing security teams to see process, file and network activity inside containers and relate it back to the Windows host. Microsoft Intune can disable WSL Containers entirely or restrict developers to images from approved container registries.
"With container registry allow lists, administrators can define approved registries and help ensure developers only pull container images from that list, that meet organizational security and compliance requirements," Microsoft noted.
Microsoft is also working with the developer ecosystem. VS Code Dev Containers can use wslc as their default driver, while Aspire and the VS Code Containers extension now support WSL Containers.
The most requested missing feature, Docker Compose-style support, is next. "Our aim is for wsl compose up to work with your existing compose.yaml files, unchanged," Microsoft said. "We've started on this and hope to share more soon."
Microsoft is also working on WSL's underlying networking and cross-OS file performance. The company says WSL Containers can already deliver up to 2x faster performance when accessing Windows files from Linux environments.