deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (hnrss.org)

Microsoft ships WSL containers to general availability with CLI, API and enterprise controls

Microsoft's WSL containers feature has reached general availability, bringing a wslc CLI, a Windows API for running Linux containers programmatically, and Intune and Defender governance controls.

Microsoft ships WSL containers to general availability with CLI, API and enterprise controls

Microsoft has moved WSL containers from public preview to general availability, making the feature a supported way to build and run Linux containers directly on Windows. According to a September 29 post on the Windows Developer Blog, which surfaced on the Hacker News front page, the release arrives via wsl --update or the latest download from Microsoft's GitHub repository. Microsoft frames the release as part of a broader effort to make Windows a primary home for Linux workloads as AI, cloud-native development and open-source ecosystems increasingly converge on Linux.

What arrives with GA

The feature ships in two parts. The first is a command-line tool, wslc.exe, which also answers to the alias container.exe and handles building, running and deploying Linux containers. The second is an API that lets native Windows applications run Linux containers programmatically — Microsoft points to local AI workloads and locally executed cloud containerized applications as example scenarios.

New commands and capabilities

Since the preview, Microsoft says its focus has been on everyday container workflows, better visibility into running environments, and management at scale. The GA release adds:

  • wslc container restart, plus wslc container cp for copying files in and out via tar archives
  • wslc system info for an at-a-glance view of the container environment
  • wslc network connect and wslc network disconnect for attaching and detaching containers from networks, while wslc network create now accepts arbitrary network driver options
  • wslc events, which streams container activity in real time
  • Container health checks
  • A --stop-timeout flag on wslc create and wslc run, including -1 for an infinite timeout, alongside --mount support on both commands
  • A configurable storage path for the default wslc session, so container data can sit on whichever drive the user prefers

Enterprise manageability

The release also extends Microsoft Intune and Microsoft Defender for Endpoint (MDE) integrations in WSL to container workflows. The MDE plugin for WSL now covers containers as well: it reports process, file and network activity inside WSL containers and links that activity back to the Windows host, so security teams can investigate suspicious behavior without a separate workflow. On the Intune side, administrators get a setting called "Allow WSL containers access" to switch the entire feature on or off, and a "WSL containers registry allow list" that restricts image pulls to approved registries — a control aimed at organizations that need to govern which images enter their environment.

Ecosystem integrations

Partner and community projects are already building on the feature. VS Code dev containers can use wslc as their default driver, .NET's Aspire treats WSL Containers as a first-class container runtime, and a popular VS Code container extension has added wslc support. Beyond editors, the blog lists Lazywslc, a terminal dashboard for managing containers; WSL Container Desktop, a WinUI 3 app that manages containers, k3s Kubernetes and registries; and WSLc remote, a small wrapper script for invoking wslc from inside WSL distributions.

Compose support and platform work ahead

The most requested missing capability is compose, and Microsoft says adding wslc compose is the focus of its next iterations, with the goal that existing compose.yaml files work unchanged. In parallel, the team is investigating core WSL improvements around networking and cross-OS file performance. The blog claims wslc delivers up to twice the performance when accessing Windows files from Linux environments — a common bottleneck — and introduces a new "consomme" network mode, enabled for container workflows, to improve networking compatibility across developer and enterprise scenarios.

Why it matters

Until now, running Linux containers on Windows typically meant depending on a separate runtime such as Docker Desktop. Baking containers into WSL — with a CLI, an API for native Windows apps, health checks and networking controls — turns the capability into part of the platform itself, which matters for the growing set of AI and cloud-native tooling that assumes a Linux foundation. The governance angle is just as significant: Defender visibility and Intune registry allow-listing give corporate IT a way to permit containers on Windows without surrendering the controls applied everywhere else. Microsoft's stated ambition is for Linux on Windows to graduate from a developer convenience into a managed execution platform for AI and cloud-native workloads, and a general availability release with enterprise tooling attached is a concrete step in that direction.

  • #wsl
  • #containers
  • #windows
  • #linux
  • #devops

Related posts