Microsoft Releases WSL Containers With Windows Security Controls—but Compose Must Wait
The release brings Linux container activity into Windows management tools and changes how sessions, files and networking work. Support for existing Compose files remains a roadmap goal.
WSL Containers is now generally available with controls that bring container activity into Microsoft’s Windows security and device-management systems. Its per-user session design aims to strengthen isolation, and Microsoft says its networking model supports compatibility with VPNs and firewalls. Native Windows applications can also launch containers through an API, including for local AI workloads. The main workflow gap is Compose: Microsoft has started work toward running existing compose.yaml files unchanged, but has not given a release date.
01
The command-line tool wslc.exe builds, runs, and deploys Linux containers; container.exe is a built-in alias.
02
Each session has its own VHD for container state, while Windows-folder volumes use virtiofs, which Microsoft says is about twice as fast as Plan 9.
03
Microsoft Defender for Endpoint can surface container process, file, and network activity and link it to the Windows host.
Microsoftreleased WSL Containers on September 29, bringing Linux container workflows into Windows security and management tools. But the move out of preview does not complete its workflow ambitions: Compose support, which Microsoft calls the top feature request, remains planned rather than available in this release.
Developers can get the generally available release by updating Windows Subsystem for Linux, or WSL. Its command-line tool, wslc.exe, builds, runs and deploys Linux containers, with container.exe as a built-in alias. An API also lets native Windows applications run containers programmatically; Microsoft names local AI workloads as one intended use.
wsl --update
Microsoft’s companion architecture deep dive explains a key departure from WSL. The privileged Windows service, wslservice.exe, creates virtual machines but does not retain ownership of them. Instead, it creates wslcsession.exe, a child process running on behalf of the user. That process creates containers, mounts directories and binds networking ports. Microsoft says separating sessions into different processes strengthens isolation, while moving their operations into a less privileged process reinforces security boundaries.
Each session has its own virtual hard disk, or VHD, storing state such as images, containers, networks and volumes. Container volumes hold data outside scratch space, which is discarded when a container is deleted. Windows-folder volumes use virtiofs to share files with the Linux virtual machine before attaching them to containers. Microsoft says virtiofs is about twice as fast as Plan 9. Alternatively, VHD-backed volumes provide a native Linux filesystem or enforce a size limit.
Networking uses a new model called Consommé. Traffic leaves the virtual machine through a Windows process running for the session’s user. Microsoft says that makes traffic behave like traffic from a regular Windows process, supporting compatibility with VPNs and firewalls.
The release extends Microsoft Defender for Endpoint’s WSL plugin to containers. It can surface process, file and network activity and connect that activity to the Windows host. Intune administrators can enable or disable WSL Containers and restrict image pulls to approved registries. Those controls accompany developer additions including container health checks, real-time activity events, restart commands and a configurable storage path for the default session.
For Compose, Microsoft says work has started. Its goal is for wsl compose up to accept existing compose.yaml files unchanged, but it gives no delivery date. VS Code dev container support and Aspire integration are already listed among the release’s ecosystem connections.
Reader comments
Newest comments first. Replies stay oldest first.