Microsoft Opens Up Windows Subsystem for Linux Containers to All Users
Microsoft has made its Windows Subsystem for Linux Containers (WSLC) available to everyone. This move comes after WSL containers were in public preview, and now they have reached general availability.
The new release includes a dedicated command-line tool called wslc.exe, which allows users to manage Linux container workflows on Windows. The tool also ships with a built-in alias called container.exe for those who prefer that syntax.
In addition to the command-line tool, Microsoft has also introduced a Windows API that gives native Windows applications the ability to spin up and manage containers directly from code. This includes new commands such as wslc events for tracking container activity and flags like --mount and --stop-timeout on create and run operations.
For networking, WSLC uses a model called Consommé, which allows container traffic to leave the virtual machine as Ethernet frames and be picked up by a Windows process running under the calling user's account. This process handles DNS, routing, and port mapping, allowing traffic to pass through VPNs and firewalls like any other Windows process.
For organizations, Microsoft Intune has gained two new settings specific to WSL containers. The first allows administrators to enable or disable access to the WSLC feature across managed devices, while the second restricts image pulls to a defined set of approved sources.
Microsoft Defender for Endpoint's WSL plugin has also been extended to cover container activity, allowing it to retrieve process, file, and network events from inside WSLC and connect them back to the Windows host.