· via Hacker News – Front Page (hnrss.org)
Microsoft ships WSL containers to general availability with CLI, API and enterprise controls
Microsoft's WSL containers feature has reached general availability, bringing a wslc CLI, a Windows API for running Linux containers programmatically, and Intune and Defender governance controls.

Microsoft has moved WSL containers from public preview to general availability, making the feature a supported way to build and run Linux containers directly on Windows. According to a September 29 post on the Windows Developer Blog, which surfaced on the Hacker News front page, the release arrives via wsl --update or the latest download from Microsoft's GitHub repository. Microsoft frames the release as part of a broader effort to make Windows a primary home for Linux workloads as AI, cloud-native development and open-source ecosystems increasingly converge on Linux.
What arrives with GA
The feature ships in two parts. The first is a command-line tool, wslc.exe, which also answers to the alias container.exe and handles building, running and deploying Linux containers. The second is an API that lets native Windows applications run Linux containers programmatically — Microsoft points to local AI workloads and locally executed cloud containerized applications as example scenarios.
New commands and capabilities
Since the preview, Microsoft says its focus has been on everyday container workflows, better visibility into running environments, and management at scale. The GA release adds:
wslc container restart, pluswslc container cpfor copying files in and out via tar archiveswslc system infofor an at-a-glance view of the container environmentwslc network connectandwslc network disconnectfor attaching and detaching containers from networks, whilewslc network createnow accepts arbitrary network driver optionswslc events, which streams container activity in real time- Container health checks
- A
--stop-timeoutflag onwslc createandwslc run, including-1for an infinite timeout, alongside--mountsupport on both commands - A configurable storage path for the default
wslcsession, so container data can sit on whichever drive the user prefers
Enterprise manageability
The release also extends Microsoft Intune and Microsoft Defender for Endpoint (MDE) integrations in WSL to container workflows. The MDE plugin for WSL now covers containers as well: it reports process, file and network activity inside WSL containers and links that activity back to the Windows host, so security teams can investigate suspicious behavior without a separate workflow. On the Intune side, administrators get a setting called "Allow WSL containers access" to switch the entire feature on or off, and a "WSL containers registry allow list" that restricts image pulls to approved registries — a control aimed at organizations that need to govern which images enter their environment.
Ecosystem integrations
Partner and community projects are already building on the feature. VS Code dev containers can use wslc as their default driver, .NET's Aspire treats WSL Containers as a first-class container runtime, and a popular VS Code container extension has added wslc support. Beyond editors, the blog lists Lazywslc, a terminal dashboard for managing containers; WSL Container Desktop, a WinUI 3 app that manages containers, k3s Kubernetes and registries; and WSLc remote, a small wrapper script for invoking wslc from inside WSL distributions.
Compose support and platform work ahead
The most requested missing capability is compose, and Microsoft says adding wslc compose is the focus of its next iterations, with the goal that existing compose.yaml files work unchanged. In parallel, the team is investigating core WSL improvements around networking and cross-OS file performance. The blog claims wslc delivers up to twice the performance when accessing Windows files from Linux environments — a common bottleneck — and introduces a new "consomme" network mode, enabled for container workflows, to improve networking compatibility across developer and enterprise scenarios.
Why it matters
Until now, running Linux containers on Windows typically meant depending on a separate runtime such as Docker Desktop. Baking containers into WSL — with a CLI, an API for native Windows apps, health checks and networking controls — turns the capability into part of the platform itself, which matters for the growing set of AI and cloud-native tooling that assumes a Linux foundation. The governance angle is just as significant: Defender visibility and Intune registry allow-listing give corporate IT a way to permit containers on Windows without surrendering the controls applied everywhere else. Microsoft's stated ambition is for Linux on Windows to graduate from a developer convenience into a managed execution platform for AI and cloud-native workloads, and a general availability release with enterprise tooling attached is a concrete step in that direction.
- #wsl
- #containers
- #windows
- #linux
- #devops