WSL containers is now generally available

WSL stands at the forefront of our dedication to transforming Windows into the premier environment for building, running, and managing Linux workloads. As the realms of AI, cloud-native development, containers, and open-source ecosystems increasingly converge on Linux, a growing number of developers are opting to execute these workloads directly on their Windows devices. Today marks a significant milestone in this journey with the general availability of a new feature: WSL containers.

To explore this new capability, users can simply execute wsl --update in their terminal or download the latest release from GitHub. This will unlock access to:

  • WSL containers CLI: Utilize wslc.exe to seamlessly build, run, and deploy Linux containers on Windows, or employ its built-in alias container.exe for familiar container commands.
  • WSL containers API: Access functions that allow for programmatic execution of Linux containers within native Windows applications, paving the way for scenarios such as running local AI workloads or utilizing cloud-based containerized applications locally.

For those interested in a more in-depth understanding of how WSL containers are constructed, their operational mechanics, and the underlying architecture, further insights can be found in our WSL containers architecture blog.

New commands and capabilities

Since the public preview, we have diligently refined WSL containers, focusing on simplifying daily container workflows, enhancing visibility into running environments, and providing the flexibility necessary for managing containers at scale. The general availability release introduces several new commands and capabilities across container lifecycle management, networking, and observability. Here are some highlights, with the full change logs available on our releases page:

  • wslc container restart — Restart a running container.
  • wslc container cp — Copy files in and out via tar archive.
  • wslc system info — Get a quick overview of your container environment’s state.
  • wslc network connect and wslc network disconnect — Attach and detach containers from networks.
  • wslc network create now supports arbitrary network driver options.
  • wslc events — Stream real-time container activity.
  • Container health checks are now supported.
  • --stop-timeout on wslc create and wslc run, including -1 for an infinite timeout.
  • --mount support during wslc create and wslc run.
  • A configurable storage path for the default wslc session, allowing users to designate their preferred drive for container storage.

In addition to these new commands and enhancements, we have also prioritized enabling organizations to adopt WSL containers with the necessary governance and security controls for production environments.

Enterprise manageability for WSL containers

This release expands the integration of Microsoft Intune and Microsoft Defender for Endpoint (MDE) within WSL to encompass container workflows as well. The existing MDE plugin for WSL has been enhanced to include support for containers, allowing MDE to surface process, file, and network activity from WSL containers and link that activity back to the Windows host. This integration aids security teams in investigating suspicious activity without necessitating a separate security workflow.

Microsoft Intune has introduced controls to enable or disable WSL container access and restrict image pulls to approved registries. New settings specific to the WSL container feature can now be found on your Intune dashboard:

  • Allow WSL containers access — Manage access to the entire WSL containers feature.
  • WSL containers registry allow list — Organizations can enforce stronger controls over the container images introduced into their environment. Administrators can define approved registries, ensuring developers only pull container images that meet organizational security and compliance standards.

For further details on setting up WSL for your organization, please refer to the WSL enterprise documentation.

Partner and community integrations

Partners and community contributors are actively integrating WSL containers into the editors, terminals, and desktop tools that developers already utilize, enhancing support for wslc within existing projects or facilitating the creation of new ones. We extend our gratitude for the fantastic community contributions that continue to enrich the ecosystem surrounding WSL containers.

  • VS Code dev container support: Leverage wslc as your default driver for creating and interacting with VS Code dev containers.
  • Aspire: Aspire now utilizes WSL Containers as a first-class container runtime.
  • VS Code container extension: A widely used extension for managing containers in VS Code now supports wslc.
  • Lazywslc: A TUI dashboard designed for managing your WSL containers.
  • WSL Container Desktop: A WinUI 3 desktop application for managing WSL containers, Kubernetes (k3s), and container registries.
  • WSLc remote: A simple wrapper script to execute wslc from within WSL distributions.

What’s next for WSL

Looking ahead, we envision Linux on Windows evolving beyond a mere development environment into a strategic execution platform for AI and cloud-native workloads, fully integrated within the enterprise security, management, and governance frameworks of Windows. Our commitment to enhancing the broader WSL experience remains steadfast, with two specific items on our roadmap highlighted in the context of this release.

Adding wslc compose

Our foremost feature request for WSLc is the addition of compose support, which will be a primary focus in our upcoming iterations. Our goal is to ensure that wsl compose up functions seamlessly with your existing compose.yaml files, unchanged. We have already begun work on this and look forward to sharing more soon.

WSL fundamental improvements

We are also actively exploring enhancements to core platform capabilities for WSL, including networking and cross-OS file performance. Users can already experience some of this progress with wslc, which supports up to 2x faster performance when accessing Windows files from Linux environments, effectively alleviating one of the most common cross-OS bottlenecks. The introduction of the new consomme network mode, designed for container workflows, further enhances networking compatibility across both developer and enterprise scenarios.

These foundational improvements benefit not only WSL distributions and WSL containers but also other container technologies built upon WSL, reflecting our broader initiative to create a more seamless and integrated experience for Linux on Windows.

We extend our heartfelt thanks to the developers who participated in the preview, provided feedback, and contributed to the enhancement of WSL containers. We encourage you to report any technical issues or feature requests at the WSL GitHub repository, and to learn more about WSL through the official documentation. We invite you to bring your next project to WSL containers and collaborate with us in shaping the future of this innovative platform. Our ongoing investment in performance, compatibility, and integration will continue to position Windows as an exceptional environment for building with Linux.

Winsage
WSL containers is now generally available