WSL containers is now generally available(blogs.windows.com) |
WSL containers is now generally available(blogs.windows.com) |
It launches a Linux vm which then runs the container(s).
That said, this is just another example of Microsoft's extend and extinguish past behavior.
It replaces the need to install docker and mess with a lot of hackery instead with an officially first party supported linux container subsystem.
Edit: and since I forgot to mention a key value-add of this is that it's integrated with group policy, defender etc so you can limit specific users or groups or OUs, etc to running specific containers or to exposing specific resources/network devices/hardware/etc to WSL at all. It makes managing all of it no different than managing any other part of an enterprise windows setup.
And likewise WSL has native antivirus/anti-intrusion instrumentation hooks via a Microsoft Defender for Endpoint/MDE plugin to WSL so that unlike with docker, etc you don't get a sudden blindspot that's non-trivial to monitor (or that comes with a heavy perf penalty).
With WSL, you can control which Windows dirs are accessible (read or read-write). you can easily clone new VMs (distros ) as a new instance.
WSL containers adds convenience and consistency to the manual steps I was doing before.
for example: a primary debian developer env, a second Debian maintainer/developer instance, multiple alpine containers (for each agent stack, one with cloud keys, one with messaging keys).
This adds a very feature rich vm and container experience on top of WSL2 , which was great to begin with.