Microsoft Makes WSL Containers Generally Available, Shipping the wslc.exe CLI and a Windows API in WSL 3.0.1
Microsoft's open-source WSL containers feature reached general availability on September 29 with WSL 3.0.1, adding a Docker-style wslc.exe CLI, a Windows API, and enterprise controls.
Overview
Microsoft has made WSL Containers (WSLC) generally available, giving the Windows Subsystem for Linux its own container platform, according to heise online. The feature ships in WSL 3.0.1, whose GitHub release page is dated September 29 and states “WSLc is generally available.” Microsoft’s engineering blog says the code is open source and hosted in the microsoft/WSL repository on GitHub.
What Shipped
The command-line tool wslc.exe builds and starts Linux containers directly on Windows, and Windows applications can do the same through an API. Because wslc.exe is part of WSL, heise reports, no separate container engine needs to be installed. Its commands, such as wslc run, wslc build and wslc container list, are based on Docker syntax, and the CLI can also be invoked under the alias container.exe.
The API for Windows application developers is distributed as the NuGet package Microsoft.WSL.Containers for C, C# and C++, per heise.
Heise reports that Microsoft introduced WSL Containers at the Build 2026 conference in early June, with a first public preview on June 29 in WSL 2.9.3. Since then, according to heise, the feature gained wslc container restart, wslc container cp (which copies files via tar archives), wslc system info, and wslc events for streaming container activity in real time. Health checks are now supported, and the storage path of the default session can be set manually.
Architecture
A Microsoft Windows Command Line blog post by Pierre Boulay describes a two-process design: client processes call wslservice.exe, which creates child processes called wslcsession.exe that run with user privileges and keep sessions isolated from one another. The post describes virtiofs, used to share Windows paths, as approximately twice as fast as plan9 for file-system interoperability. Networking uses a model called Consommé, which routes virtual machine traffic through a Windows user-level process on behalf of the session owner; the post says this keeps compatibility with VPNs and firewalls.
Enterprise Controls and Ecosystem
Help Net Security reports that administrators can use Intune to enable or disable the feature and to restrict image pulls to approved registries, and that Microsoft Defender for Endpoint now covers WSL containers. Heise names the two Intune settings as “Allow WSL containers access” and “WSL containers registry allow list.”
VS Code Dev Containers and Aspire can use WSL containers as their container runtime, according to Help Net Security. Heise also lists community tools including the terminal dashboard Lazywslc and the WinUI 3 application WSL Container Desktop.
What We Don’t Know
Compose support is the notable gap. Help Net Security describes it as the top feature request, and Microsoft intends for existing compose.yaml files to run unchanged. Heise adds that Microsoft has not provided a timeline.