Windows Subsystem for Linux (WSL) is a feature of Windows that allows you to run a Linux environment on your Windows machine, without the need for a separate virtual machine or dual booting -- https://learn.microsoft.com/en-us/windows/wsl/about
it's a linux container but through WSL and natively integrated into windows. that's basically it.
It replaces the need to install docker and mess with a lot of hackery instead with an officially first party supported linux container subsystem.
Edit: and since I forgot to mention a key value-add of this is that it's integrated with group policy, defender etc so you can limit specific users or groups or OUs, etc to running specific containers. It makes managing all of it no different than managing any other part of an enterprise windows setup.
And likewise WSL has native antivirus/anti-intrusion instrumentation hooks via a Microsoft Defender for Endpoint/MDE plugin to WSL so that unlike with docker, etc you don't get a sudden blindspot that's non-trivial to monitor (or that comes with a heavy perf penalty).
6 comments:
In case anyone was curious, this works like docker desktop on Windows.
It launches a Linux vm which then runs the container(s).
Can someone explain what the use case for this is?
Windows Subsystem for Linux (WSL) is a feature of Windows that allows you to run a Linux environment on your Windows machine, without the need for a separate virtual machine or dual booting -- https://learn.microsoft.com/en-us/windows/wsl/about
it's a linux container but through WSL and natively integrated into windows. that's basically it.
It replaces the need to install docker and mess with a lot of hackery instead with an officially first party supported linux container subsystem.
Edit: and since I forgot to mention a key value-add of this is that it's integrated with group policy, defender etc so you can limit specific users or groups or OUs, etc to running specific containers. It makes managing all of it no different than managing any other part of an enterprise windows setup.
And likewise WSL has native antivirus/anti-intrusion instrumentation hooks via a Microsoft Defender for Endpoint/MDE plugin to WSL so that unlike with docker, etc you don't get a sudden blindspot that's non-trivial to monitor (or that comes with a heavy perf penalty).
Nobody cares.
I think a lot of people in enterprise environments do.