Trending: On-device modelsSearch
iHeartGeek
iTECH

WSL containers reach general availability with wslc.exe

Microsoft's Linux container tooling for Windows leaves preview with a new CLI, container health checks and Intune controls for IT teams.

A PowerShell window running a wslc image ls command and a wslc run command that prints a cow through the cowsay utility

Microsoft has taken WSL containers out of preview, giving Windows a supported way to build and run Linux containers without keeping a separate Linux box around. The feature is generally available from 29 September, and existing users can collect it with a single wsl --update in a terminal or by downloading the latest release from the project's repository.

What actually ships

Two pieces matter. The first is wslc.exe, a command-line tool for building, running and deploying Linux containers on Windows, which also installs a container.exe alias so familiar container commands work unchanged. The second is a WSL containers API that lets native Windows applications drive Linux containers programmatically. Microsoft's own examples for that API are running local AI workloads and running containerised cloud applications on a laptop.

The distance between preview and general availability is mostly command coverage. This release adds container restart, a cp command that moves files in and out through a tar archive, system info for an at-a-glance view of the container environment, network connect and disconnect, arbitrary driver options for network create, and an events stream for live container activity. Container health checks arrive too, along with a stop timeout that accepts -1 for no timeout at all, mount support during create and run, and a configurable storage path so images can live on whichever drive you choose.

The governance layer is the real news

Microsoft has extended its existing Windows Subsystem for Linux integration in Microsoft Defender for Endpoint to cover containers, which means process, file and network activity inside a WSL container can be surfaced back to the Windows host and investigated in the same place as everything else. Intune picks up settings to switch WSL containers on or off and to restrict image pulls to approved registries. Those two additions are what turn the feature into something a corporate platform team can permit on a managed laptop.

The architecture underneath is deliberately different from WSL's. Rather than keeping ownership of the virtual machine, the privileged wslservice.exe now spawns a per-user wslcsession.exe that performs session operations such as creating containers, mounting directories and binding ports in a less privileged process. Each session gets its own storage VHD, container volumes are backed by virtiofs shares, and networking runs through a purpose-built model Microsoft calls Consomme.

Our opinion

Windows has been the awkward second home for container work for a decade, and the honest reading of this release is that the containers are the least interesting part of it. Microsoft has shipped several ways to run Linux code on Windows already, and each one arrived with the same promise and a polite request to migrate. What is new is that this version comes with a story a security team can accept: container activity in Defender, and registry allow-listing in Intune. Adoption on managed corporate laptops has always been a governance problem rather than a technical one, and this is the first time Microsoft has addressed it head on.

The sceptical case writes itself, though. wslc is now the fifth container-shaped interface Microsoft has asked developers to learn after WSL 1, WSL 2, Hyper-V and Docker Desktop, and the winner of that contest has never been the fastest runtime, only the one that survives the next reorganisation. The API for local AI workloads looks like the real bet: if developers start running models in Linux containers on Windows machines as a matter of routine, the CLI is incidental and the platform bet pays off. If that does not happen, WSL containers is a tidier way to do something most Windows developers already had three options for.