Developers

Microsoft Brings WSL Containers Out of Preview, Adds Native Windows Integration

Microsoft has transitioned Windows Subsystem for Linux containers from public preview to general availability, introducing new command-line tools, APIs, and management features for developers running containerized workloads on Windows.

3 min read
Microsoft Has Made WSL Containers Available to Everyone

Through a pair of blog announcements, Microsoft has elevated Windows Subsystem for Linux containers (WSLC) from experimental status to full general availability. The release introduces wslc.exe, a purpose-built command-line utility designed to streamline Linux container operations on Windows systems. An alternative command name, container.exe, is also included as a built-in alias for users who prefer that naming convention.

Alongside the command-line tool, a Windows API has been released that enables native Windows applications to instantiate and control containers programmatically. The update also brings fresh capabilities, including wslc events for monitoring container behavior, plus new --mount and --stop-timeout parameters for create and run operations.

Container networking operates through a new architecture called Consommé, which routes container traffic out of the virtual machine as raw Ethernet frames to a Windows process running under the user's credentials. This process manages DNS resolution, routing decisions, and port forwarding, allowing traffic to traverse VPNs and firewalls as if it were any standard Windows network activity.

For enterprise deployments, Microsoft Intune now includes two configuration options tailored to WSLC. Administrators can toggle WSLC access on or off across their managed device fleet, and they can establish a container registry allow list that limits image downloads to a curated collection of trusted registries.

Microsoft Defender for Endpoint's WSL plugin has been expanded to track container operations. The security tool can now harvest process, file, and network telemetry from within WSLC containers and correlate that data with activity on the Windows host system.

Understanding WSLC

WSL, short for Windows Subsystem for Linux, provides a mechanism for developers to execute Linux environments natively on Windows machines without partitioning disks or maintaining separate Linux installations.

Beginning with WSL 2, the subsystem has incorporated an actual Linux kernel running inside a controlled virtual machine, granting developers access to the full suite of Linux utilities, distributions, and terminal-based workflows directly from their Windows desktop.

WSLC builds on this foundation by introducing a specialized layer for constructing and orchestrating Linux containers within the existing WSL infrastructure, transforming container-based development into a first-class capability of the platform.

The implementation segregates container operations from the main WSL service by channeling them through a dedicated child process called wslcsession.exe, which executes under the invoking user's security context. This design ensures each user session remains isolated, and container operations execute at a lower privilege level than the WSL service itself.

For developers already embedded in WSL workflows, containerized applications can now coexist in the same environment without requiring external tooling. The exposed Windows API simultaneously permits conventional Windows applications to engage with containers through code.

Getting Started

Executing wsl --update in a terminal window retrieves the most recent WSL version, which incorporates WSL containers. Following the update, wslc becomes immediately available for use.

For comprehensive details on the changes and access to the underlying code, consult the WSL 3.0.1 release page on GitHub.

Source: It's FOSS News · Reporting supplemented by The Silicon Ledger staff.