diff --git a/.dockerignore b/.dockerignore
index 4a56f2e..8645f94 100644
--- a/.dockerignore
+++ b/.dockerignore
@@ -3,5 +3,4 @@
diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS
index 9081854..b7fac27 100644
--- a/.github/CODEOWNERS
+++ b/.github/CODEOWNERS
@@ -13,8 +13,5 @@
 daemon/graphdriver/windows/**           @johnstep @jhowardmsft
 daemon/logger/awslogs/**                @samuelkarp  
 hack/**                                 @tianon
-hack/integration-cli-on-swarm/**        @AkihiroSuda
-integration-cli/**                      @vdemeester
-integration/**                          @vdemeester
 plugin/**                               @cpuguy83
 project/**                              @thaJeztah
diff --git a/.gitignore b/.gitignore
index 392bf96..abad293 100644
--- a/.gitignore
+++ b/.gitignore
@@ -3,6 +3,7 @@
 #  please consider a global .gitignore
@@ -19,6 +20,6 @@
diff --git a/Dockerfile b/Dockerfile
index fb4a386..4acc649 100644
--- a/Dockerfile
+++ b/Dockerfile
@@ -72,17 +72,6 @@
 	   esac \
 	&& rm -rf "$GOPATH"
-FROM base AS docker-py
-# Get the "docker-py" source so we can run their integration tests
-ENV DOCKER_PY_COMMIT ac922192959870774ad8428344d9faa0555f7ba6
-RUN git clone /build \
-	&& cd /build \
-	&& git checkout -q $DOCKER_PY_COMMIT
 FROM base AS swagger
 # Install go-swagger for validating swagger.yaml
 ENV GO_SWAGGER_COMMIT c28258affb0b6251755d92489ef685af8d4ff3eb
@@ -93,7 +82,6 @@
 	&& go build -o /build/swagger \
 	&& rm -rf "$GOPATH"
 FROM base AS frozen-images
 RUN apt-get update && apt-get install -y jq ca-certificates --no-install-recommends
 # Get useful and necessary Hub images so we can "docker load" locally instead of pulling
@@ -144,6 +132,12 @@
 COPY hack/dockerfile/install/$INSTALL_BINARY_NAME.installer ./
+FROM base AS gotestsum
+COPY hack/dockerfile/install/ ./
+COPY hack/dockerfile/install/$INSTALL_BINARY_NAME.installer ./
 FROM base AS dockercli
 COPY hack/dockerfile/install/ ./
@@ -186,25 +180,14 @@
 	jq \
 	libcap2-bin \
 	libdevmapper-dev \
-# libffi-dev and libssl-dev appear to be required for compiling paramiko on s390x/ppc64le
-	libffi-dev \
-	libssl-dev \
 	libudev-dev \
 	libsystemd-dev \
 	binutils-mingw-w64 \
 	g++-mingw-w64-x86-64 \
 	net-tools \
 	pigz \
-	python-backports.ssl-match-hostname \
-	python-dev \
-# python-cffi appears to be required for compiling paramiko on s390x/ppc64le
-	python-cffi \
-	python-mock \
-	python-pip \
-	python-requests \
-	python-setuptools \
-	python-websocket \
-	python-wheel \
+	python3-pip \
+	python3-setuptools \
 	thin-provisioning-tools \
 	vim \
 	vim-common \
@@ -213,9 +196,13 @@
 	bzip2 \
 	xz-utils \
+RUN pip3 install yamllint==1.16.0
 COPY --from=swagger /build/swagger* /usr/local/bin/
 COPY --from=frozen-images /build/ /docker-frozen-images
 COPY --from=gometalinter /build/ /usr/local/bin/
+COPY --from=gotestsum /build/ /usr/local/bin/
 COPY --from=tomlv /build/ /usr/local/bin/
 COPY --from=vndr /build/ /usr/local/bin/
 COPY --from=tini /build/ /usr/local/bin/
@@ -225,16 +212,6 @@
 COPY --from=dockercli /build/ /usr/local/cli
 COPY --from=registry /build/registry* /usr/local/bin/
 COPY --from=criu /build/ /usr/local/
-COPY --from=docker-py /build/ /docker-py
-# TODO: This is for the docker-py tests, which shouldn't really be needed for
-# this image, but currently CI is expecting to run this image. This should be
-# split out into a separate image, including all the `python-*` deps installed
-# above.
-RUN cd /docker-py \
-	&& pip install docker-pycreds==0.4.0 \
-	&& pip install paramiko==2.4.2 \
-	&& pip install yamllint==1.5.0 \
-	&& pip install -r test-requirements.txt
 ENV PATH=/usr/local/cli:$PATH
 ENV DOCKER_BUILDTAGS apparmor seccomp selinux
diff --git a/Jenkinsfile b/Jenkinsfile
new file mode 100644
index 0000000..eb52655
--- /dev/null
+++ b/Jenkinsfile
@@ -0,0 +1,712 @@
+pipeline {
+    agent none
+    options {
+        buildDiscarder(logRotator(daysToKeepStr: '30'))
+        timeout(time: 2, unit: 'HOURS')
+        timestamps()
+    }
+    parameters {
+        booleanParam(name: 'unit_validate', defaultValue: true, description: 'x86 unit tests and vendor check')
+        booleanParam(name: 'janky', defaultValue: true, description: 'x86 Build/Test')
+        booleanParam(name: 'z', defaultValue: true, description: 'IBM Z (s390x) Build/Test')
+        booleanParam(name: 'powerpc', defaultValue: true, description: 'PowerPC (ppc64le) Build/Test')
+        booleanParam(name: 'windowsRS1', defaultValue: false, description: 'Windows 2016 (RS1) Build/Test')
+        booleanParam(name: 'windowsRS5', defaultValue: false, description: 'Windows 2019 (RS5) Build/Test')
+    }
+    environment {
+        DOCKER_BUILDKIT     = '1'
+        DOCKER_GRAPHDRIVER  = 'overlay2'
+        APT_MIRROR          = ''
+        CHECK_CONFIG_COMMIT = '78405559cfe5987174aa2cb6463b9b2c1b917255'
+        TIMEOUT             = '120m'
+    }
+    stages {
+        stage('Build') {
+            parallel {
+                stage('unit-validate') {
+                    when {
+                        beforeAgent true
+                        expression { params.unit_validate }
+                    }
+                    agent { label 'amd64 && ubuntu-1804 && overlay2' }
+                    stages {
+                        stage("Print info") {
+                            steps {
+                                sh 'docker version'
+                                sh 'docker info'
+                                sh '''
+                                echo " version: ${CHECK_CONFIG_COMMIT}"
+                                curl -fsSL -o ${WORKSPACE}/ "${CHECK_CONFIG_COMMIT}/contrib/" \
+                                && bash ${WORKSPACE}/ || true
+                                '''
+                            }
+                        }
+                        stage("Build dev image") {
+                            steps {
+                                sh 'docker build --force-rm --build-arg APT_MIRROR -t docker:${GIT_COMMIT} .'
+                            }
+                        }
+                        stage("Validate") {
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  -v "$WORKSPACE/.git:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_EXPERIMENTAL \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  docker:${GIT_COMMIT} \
+                                  hack/validate/default
+                                '''
+                            }
+                        }
+                        stage("Docker-py") {
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_EXPERIMENTAL \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  docker:${GIT_COMMIT} \
+                                  hack/ \
+                                    dynbinary-daemon \
+                                    test-docker-py
+                                '''
+                            }
+                            post {
+                                always {
+                                    junit testResults: 'bundles/test-docker-py/junit-report.xml', allowEmptyResults: true
+                                    sh '''
+                                    echo "Ensuring container killed."
+                                    docker rm -vf docker-pr$BUILD_NUMBER || true
+                                    '''
+                                    sh '''
+                                    echo 'Chowning /workspace to jenkins user'
+                                    docker run --rm -v "$WORKSPACE:/workspace" busybox chown -R "$(id -u):$(id -g)" /workspace
+                                    '''
+                                    sh '''
+                                    echo 'Creating docker-py-bundles.tar.gz'
+                                    tar -czf docker-py-bundles.tar.gz bundles/test-docker-py/*.xml bundles/test-docker-py/*.log
+                                    '''
+                                    archiveArtifacts artifacts: 'docker-py-bundles.tar.gz'
+                                }
+                            }
+                        }
+                        stage("Static") {
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  docker:${GIT_COMMIT} \
+                                  hack/ binary-daemon
+                                '''
+                            }
+                        }
+                        stage("Cross") {
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  docker:${GIT_COMMIT} \
+                                  hack/ cross
+                                '''
+                            }
+                        }
+                        // needs to be last stage that calls for the junit report to work
+                        stage("Unit tests") {
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_EXPERIMENTAL \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  docker:${GIT_COMMIT} \
+                                  hack/test/unit
+                                '''
+                            }
+                            post {
+                                always {
+                                    junit testResults: 'bundles/junit-report.xml', allowEmptyResults: true
+                                }
+                            }
+                        }
+                        stage("Validate vendor") {
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/.git:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_EXPERIMENTAL \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  docker:${GIT_COMMIT} \
+                                  hack/validate/vendor
+                                '''
+                            }
+                        }
+                        stage("Build e2e image") {
+                            steps {
+                                sh '''
+                                echo "Building e2e image"
+                                docker build --build-arg DOCKER_GITCOMMIT=${GIT_COMMIT} -t moby-e2e-test -f Dockerfile.e2e .
+                                '''
+                            }
+                        }
+                    }
+                    post {
+                        always {
+                            sh '''
+                            echo 'Ensuring container killed.'
+                            docker rm -vf docker-pr$BUILD_NUMBER || true
+                            '''
+                            sh '''
+                            echo 'Chowning /workspace to jenkins user'
+                            docker run --rm -v "$WORKSPACE:/workspace" busybox chown -R "$(id -u):$(id -g)" /workspace
+                            '''
+                            sh '''
+                            echo 'Creating unit-bundles.tar.gz'
+                            tar -czvf unit-bundles.tar.gz bundles/junit-report.xml bundles/go-test-report.json bundles/profile.out
+                            '''
+                            archiveArtifacts artifacts: 'unit-bundles.tar.gz'
+                        }
+                        cleanup {
+                            sh 'make clean'
+                            deleteDir()
+                        }
+                    }
+                }
+                stage('janky') {
+                    when {
+                        beforeAgent true
+                        expression { params.janky }
+                    }
+                    agent { label 'amd64 && ubuntu-1804 && overlay2' }
+                    stages {
+                        stage("Print info") {
+                            steps {
+                                sh 'docker version'
+                                sh 'docker info'
+                                sh '''
+                                echo " version: ${CHECK_CONFIG_COMMIT}"
+                                curl -fsSL -o ${WORKSPACE}/ "${CHECK_CONFIG_COMMIT}/contrib/" \
+                                && bash ${WORKSPACE}/ || true
+                                '''
+                            }
+                        }
+                        stage("Build dev image") {
+                            steps {
+                                sh '''
+                                # todo: include ip_vs in base image
+                                sudo modprobe ip_vs
+                                docker build --force-rm --build-arg APT_MIRROR -t docker:${GIT_COMMIT} .
+                                '''
+                            }
+                        }
+                        stage("Run tests") {
+                            steps {
+                                sh '''#!/bin/bash
+                                # bash is needed so 'jobs -p' works properly
+                                # it also accepts setting inline envvars for functions without explicitly exporting
+                                run_tests() {
+                                        [ -n "$TESTDEBUG" ] && rm= || rm=--rm;
+                                        docker run $rm -t --privileged \
+                                          -v "$WORKSPACE/bundles:/go/src/" \
+                                          -v "$WORKSPACE/.git:/go/src/" \
+                                          --name "$CONTAINER_NAME" \
+                                          -e KEEPBUNDLE=1 \
+                                          -e TESTDEBUG \
+                                          -e TESTFLAGS \
+                                          -e TEST_INTEGRATION_DEST \
+                                          -e TEST_SKIP_INTEGRATION \
+                                          -e TEST_SKIP_INTEGRATION_CLI \
+                                          -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                          -e DOCKER_GRAPHDRIVER \
+                                          -e TIMEOUT \
+                                          docker:${GIT_COMMIT} \
+                                          hack/ \
+                                            "$1" \
+                                            test-integration
+                                }
+                                trap "exit" INT TERM
+                                trap 'pids=$(jobs -p); echo "Remaining pids to kill: [$pids]"; [ -z "$pids" ] || kill $pids' EXIT
+                                CONTAINER_NAME=docker-pr$BUILD_NUMBER
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  -v "$WORKSPACE/.git:/go/src/" \
+                                  --name ${CONTAINER_NAME}-build \
+                                  -e DOCKER_EXPERIMENTAL \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  docker:${GIT_COMMIT} \
+                                  hack/ \
+                                    dynbinary-daemon
+                                # flaky + integration
+                                TEST_INTEGRATION_DEST=1 CONTAINER_NAME=${CONTAINER_NAME}-1 TEST_SKIP_INTEGRATION_CLI=1 run_tests test-integration-flaky &
+                                # integration-cli first set
+                                TEST_INTEGRATION_DEST=2 CONTAINER_NAME=${CONTAINER_NAME}-2 TEST_SKIP_INTEGRATION=1 TESTFLAGS="-check.f ^(DockerSuite|DockerNetworkSuite|DockerHubPullSuite|DockerRegistrySuite|DockerSchema1RegistrySuite|DockerRegistryAuthTokenSuite|DockerRegistryAuthHtpasswdSuite)" run_tests &
+                                # integration-cli second set
+                                TEST_INTEGRATION_DEST=3 CONTAINER_NAME=${CONTAINER_NAME}-3 TEST_SKIP_INTEGRATION=1 TESTFLAGS="-check.f ^(DockerSwarmSuite|DockerDaemonSuite|DockerExternalVolumeSuite)" run_tests &
+                                set +x
+                                c=0
+                                for job in $(jobs -p); do
+                                        wait ${job} || c=$?
+                                done
+                                exit $c
+                                '''
+                            }
+                        }
+                    }
+                    post {
+                        always {
+                            sh '''
+                            echo "Ensuring container killed."
+                            docker rm -vf docker-pr$BUILD_NUMBER || true
+                            '''
+                            sh '''
+                            echo "Chowning /workspace to jenkins user"
+                            docker run --rm -v "$WORKSPACE:/workspace" busybox chown -R "$(id -u):$(id -g)" /workspace
+                            '''
+                            sh '''
+                            echo "Creating janky-bundles.tar.gz"
+                            # exclude overlay2 directories
+                            find bundles -path '*/root/*overlay2' -prune -o -type f \\( -name '*.log' -o -name '*.prof' \\) -print | xargs tar -czf janky-bundles.tar.gz
+                            '''
+                            archiveArtifacts artifacts: 'janky-bundles.tar.gz'
+                        }
+                        cleanup {
+                            sh 'make clean'
+                            deleteDir()
+                        }
+                    }
+                }
+                stage('z') {
+                    when {
+                        beforeAgent true
+                        expression { params.z }
+                    }
+                    agent { label 's390x-ubuntu-1604' }
+                    // s390x machines run on Docker 18.06, and buildkit has some bugs on that version
+                    environment { DOCKER_BUILDKIT = '0' }
+                    stages {
+                        stage("Print info") {
+                            steps {
+                                sh 'docker version'
+                                sh 'docker info'
+                                sh '''
+                                echo " version: ${CHECK_CONFIG_COMMIT}"
+                                curl -fsSL -o ${WORKSPACE}/ "${CHECK_CONFIG_COMMIT}/contrib/" \
+                                && bash ${WORKSPACE}/ || true
+                                '''
+                            }
+                        }
+                        stage("Build dev image") {
+                            steps {
+                                sh '''
+                                docker build --force-rm --build-arg APT_MIRROR -t docker:${GIT_COMMIT} -f Dockerfile .
+                                '''
+                            }
+                        }
+                        stage("Unit tests") {
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_EXPERIMENTAL \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  docker:${GIT_COMMIT} \
+                                  hack/test/unit
+                                '''
+                            }
+                            post {
+                                always {
+                                    junit testResults: 'bundles/junit-report.xml', allowEmptyResults: true
+                                }
+                            }
+                        }
+                        stage("Integration tests") {
+                            environment { TEST_SKIP_INTEGRATION_CLI = '1' }
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_EXPERIMENTAL \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  -e TEST_SKIP_INTEGRATION_CLI \
+                                  -e TIMEOUT \
+                                  docker:${GIT_COMMIT} \
+                                  hack/ \
+                                    dynbinary \
+                                    test-integration
+                                '''
+                            }
+                        }
+                    }
+                    post {
+                        always {
+                            sh '''
+                            echo "Ensuring container killed."
+                            docker rm -vf docker-pr$BUILD_NUMBER || true
+                            '''
+                            sh '''
+                            echo "Chowning /workspace to jenkins user"
+                            docker run --rm -v "$WORKSPACE:/workspace" busybox chown -R "$(id -u):$(id -g)" /workspace
+                            '''
+                            sh '''
+                            echo "Creating s390x-integration-bundles.tar.gz"
+                            # exclude overlay2 directories
+                            find bundles -path '*/root/*overlay2' -prune -o -type f \\( -name '*.log' -o -name '*.prof' \\) -print | xargs tar -czf s390x-integration-bundles.tar.gz
+                            '''
+                            archiveArtifacts artifacts: 's390x-integration-bundles.tar.gz'
+                        }
+                        cleanup {
+                            sh 'make clean'
+                            deleteDir()
+                        }
+                    }
+                }
+                stage('z-master') {
+                    when {
+                        beforeAgent true
+                        branch 'master'
+                        expression { params.z }
+                    }
+                    agent { label 's390x-ubuntu-1604' }
+                    // s390x machines run on Docker 18.06, and buildkit has some bugs on that version
+                    environment { DOCKER_BUILDKIT = '0' }
+                    stages {
+                        stage("Print info") {
+                            steps {
+                                sh 'docker version'
+                                sh 'docker info'
+                                sh '''
+                                echo " version: ${CHECK_CONFIG_COMMIT}"
+                                curl -fsSL -o ${WORKSPACE}/ "${CHECK_CONFIG_COMMIT}/contrib/" \
+                                && bash ${WORKSPACE}/ || true
+                                '''
+                            }
+                        }
+                        stage("Build dev image") {
+                            steps {
+                                sh '''
+                                docker build --force-rm --build-arg APT_MIRROR -t docker:${GIT_COMMIT} -f Dockerfile .
+                                '''
+                            }
+                        }
+                        stage("Integration-cli tests") {
+                            environment { TEST_SKIP_INTEGRATION = '1' }
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  -e TEST_SKIP_INTEGRATION \
+                                  -e TIMEOUT \
+                                  docker:${GIT_COMMIT} \
+                                  hack/ \
+                                    dynbinary \
+                                    test-integration
+                                '''
+                            }
+                        }
+                    }
+                    post {
+                        always {
+                            sh '''
+                            echo "Ensuring container killed."
+                            docker rm -vf docker-pr$BUILD_NUMBER || true
+                            '''
+                            sh '''
+                            echo "Chowning /workspace to jenkins user"
+                            docker run --rm -v "$WORKSPACE:/workspace" busybox chown -R "$(id -u):$(id -g)" /workspace
+                            '''
+                            sh '''
+                            echo "Creating s390x-integration-cli-bundles.tar.gz"
+                            find bundles -path '*/root/*overlay2' -prune -o -type f \\( -name '*.log' -o -name '*.prof' \\) -print | xargs tar -czf s390x-integration-cli-bundles.tar.gz
+                            '''
+                            archiveArtifacts artifacts: 's390x-integration-cli-bundles.tar.gz'
+                        }
+                        cleanup {
+                            sh 'make clean'
+                            deleteDir()
+                        }
+                    }
+                }
+                stage('powerpc') {
+                    when {
+                        beforeAgent true
+                        expression { params.powerpc }
+                    }
+                    agent { label 'ppc64le-ubuntu-1604' }
+                    // power machines run on Docker 18.06, and buildkit has some bugs on that version
+                    environment { DOCKER_BUILDKIT = '0' }
+                    stages {
+                        stage("Print info") {
+                            steps {
+                                sh 'docker version'
+                                sh 'docker info'
+                                sh '''
+                                echo " version: ${CHECK_CONFIG_COMMIT}"
+                                curl -fsSL -o ${WORKSPACE}/ "${CHECK_CONFIG_COMMIT}/contrib/" \
+                                && bash ${WORKSPACE}/ || true
+                                '''
+                            }
+                        }
+                        stage("Build dev image") {
+                            steps {
+                                sh 'docker build --force-rm --build-arg APT_MIRROR -t docker:${GIT_COMMIT} -f Dockerfile .'
+                            }
+                        }
+                        stage("Unit tests") {
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_EXPERIMENTAL \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  docker:${GIT_COMMIT} \
+                                  hack/test/unit
+                                '''
+                            }
+                            post {
+                                always {
+                                    junit testResults: 'bundles/junit-report.xml', allowEmptyResults: true
+                                }
+                            }
+                        }
+                        stage("Integration tests") {
+                            environment { TEST_SKIP_INTEGRATION_CLI = '1' }
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_EXPERIMENTAL \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  -e TEST_SKIP_INTEGRATION_CLI \
+                                  -e TIMEOUT \
+                                  docker:${GIT_COMMIT} \
+                                  hack/ \
+                                    dynbinary \
+                                    test-integration
+                                '''
+                            }
+                        }
+                    }
+                    post {
+                        always {
+                            sh '''
+                            echo "Ensuring container killed."
+                            docker rm -vf docker-pr$BUILD_NUMBER || true
+                            '''
+                            sh '''
+                            echo "Chowning /workspace to jenkins user"
+                            docker run --rm -v "$WORKSPACE:/workspace" busybox chown -R "$(id -u):$(id -g)" /workspace
+                            '''
+                            sh '''
+                            echo "Creating powerpc-integration-bundles.tar.gz"
+                            # exclude overlay2 directories
+                            find bundles -path '*/root/*overlay2' -prune -o -type f \\( -name '*.log' -o -name '*.prof' \\) -print | xargs tar -czf powerpc-integration-bundles.tar.gz
+                            '''
+                            archiveArtifacts artifacts: 'powerpc-integration-bundles.tar.gz'
+                        }
+                        cleanup {
+                            sh 'make clean'
+                            deleteDir()
+                        }
+                    }
+                }
+                stage('powerpc-master') {
+                    when {
+                        beforeAgent true
+                        branch 'master'
+                        expression { params.powerpc }
+                    }
+                    agent { label 'ppc64le-ubuntu-1604' }
+                    // power machines run on Docker 18.06, and buildkit has some bugs on that version
+                    environment { DOCKER_BUILDKIT = '0' }
+                    stages {
+                        stage("Print info") {
+                            steps {
+                                sh 'docker version'
+                                sh 'docker info'
+                                sh '''
+                                echo " version: ${CHECK_CONFIG_COMMIT}"
+                                curl -fsSL -o ${WORKSPACE}/ "${CHECK_CONFIG_COMMIT}/contrib/" \
+                                && bash ${WORKSPACE}/ || true
+                                '''
+                            }
+                        }
+                        stage("Build dev image") {
+                            steps {
+                                sh 'docker build --force-rm --build-arg APT_MIRROR -t docker:${GIT_COMMIT} -f Dockerfile .'
+                            }
+                        }
+                        stage("Integration-cli tests") {
+                            environment { TEST_SKIP_INTEGRATION = '1' }
+                            steps {
+                                sh '''
+                                docker run --rm -t --privileged \
+                                  -v "$WORKSPACE/bundles:/go/src/" \
+                                  --name docker-pr$BUILD_NUMBER \
+                                  -e DOCKER_GITCOMMIT=${GIT_COMMIT} \
+                                  -e DOCKER_GRAPHDRIVER \
+                                  -e TEST_SKIP_INTEGRATION \
+                                  -e TIMEOUT \
+                                  docker:${GIT_COMMIT} \
+                                  hack/ \
+                                    dynbinary \
+                                    test-integration
+                                '''
+                            }
+                        }
+                    }
+                    post {
+                        always {
+                            sh '''
+                            echo "Ensuring container killed."
+                            docker rm -vf docker-pr$BUILD_NUMBER || true
+                            '''
+                            sh '''
+                            echo "Chowning /workspace to jenkins user"
+                            docker run --rm -v "$WORKSPACE:/workspace" busybox chown -R "$(id -u):$(id -g)" /workspace
+                            '''
+                            sh '''
+                            echo "Creating powerpc-integration-cli-bundles.tar.gz"
+                            find bundles -path '*/root/*overlay2' -prune -o -type f \\( -name '*.log' -o -name '*.prof' \\) -print | xargs tar -czf powerpc-integration-cli-bundles.tar.gz
+                            '''
+                            archiveArtifacts artifacts: 'powerpc-integration-cli-bundles.tar.gz'
+                        }
+                        cleanup {
+                            sh 'make clean'
+                            deleteDir()
+                        }
+                    }
+                }
+                stage('windowsRS1') {
+                    when {
+                        beforeAgent true
+                        expression { params.windowsRS1 }
+                    }
+                    agent {
+                        node {
+                            label 'windows-rs1'
+                            customWorkspace 'c:\\gopath\\src\\\\docker\\docker'
+                        }
+                    }
+                    stages {
+                        stage("Print info") {
+                            steps {
+                                sh 'docker version'
+                                sh 'docker info'
+                            }
+                        }
+                        stage("Run tests") {
+                            steps {
+                                powershell '''
+                                $ErrorActionPreference = 'Stop'
+                                .\\hack\\ci\\windows.ps1
+                                exit $LastExitCode
+                                '''
+                            }
+                        }
+                    }
+                }
+                stage('windowsRS5-process') {
+                    when {
+                        beforeAgent true
+                        expression { params.windowsRS5 }
+                    }
+                    agent {
+                        node {
+                            label 'windows-rs5'
+                            customWorkspace 'c:\\gopath\\src\\\\docker\\docker'
+                        }
+                    }
+                    stages {
+                        stage("Print info") {
+                            steps {
+                                sh 'docker version'
+                                sh 'docker info'
+                            }
+                        }
+                        stage("Run tests") {
+                            steps {
+                                powershell '''
+                                $ErrorActionPreference = 'Stop'
+                                .\\hack\\ci\\windows.ps1
+                                exit $LastExitCode
+                                '''
+                            }
+                        }
+                    }
+                }
+            }
+        }
+    }
diff --git a/Makefile b/Makefile
index f9fed3e..a8f5ad9 100644
--- a/Makefile
+++ b/Makefile
@@ -47,11 +47,18 @@
 	-e TIMEOUT \
@@ -102,9 +109,6 @@
 define \n
@@ -172,8 +176,13 @@
 test-integration-cli: test-integration ## (DEPRECATED) use test-integration
+	@echo Both integrations suites skipped per environment variables
 test-integration: build ## run the integration tests
 	$(DOCKER_RUN_DOCKER) hack/ dynbinary test-integration
 test-integration-flaky: build ## run the stress test for all new integration tests
 	$(DOCKER_RUN_DOCKER) hack/ dynbinary test-integration-flaky
@@ -202,18 +211,3 @@
 		-e 'REDOC_OPTIONS=hide-hostname="true" lazy-rendering' \
 		-p $(SWAGGER_DOCS_PORT):80 \
-build-integration-cli-on-swarm: build ## build images and binary for running integration-cli on Swarm in parallel
-	@echo "Building hack/integration-cli-on-swarm (if build fails, please refer to hack/integration-cli-on-swarm/"
-	go build -buildmode=pie -o ./hack/integration-cli-on-swarm/integration-cli-on-swarm ./hack/integration-cli-on-swarm/host
-	docker build -t $(INTEGRATION_CLI_MASTER_IMAGE) hack/integration-cli-on-swarm/agent
-	$(eval tmp := integration-cli-worker-tmp)
-# We mount pkgcache, but not bundle (bundle needs to be baked into the image)
-# For avoiding bakings DOCKER_GRAPHDRIVER and so on to image, we cannot use $(DOCKER_ENVS) here
-	docker run -t -d --name $(tmp) -e DOCKER_GITCOMMIT -e BUILDFLAGS --privileged $(DOCKER_IMAGE) top
-	docker exec $(tmp) hack/ build-integration-test-binary dynbinary
-	docker exec $(tmp) go build -buildmode=pie -o /worker
-	docker commit -c 'ENTRYPOINT ["/worker"]' $(tmp) $(INTEGRATION_CLI_WORKER_IMAGE)
-	docker rm -f $(tmp)
diff --git a/hack/ci/experimental b/hack/ci/experimental
index 9ccbc84..10297c7 100755
--- a/hack/ci/experimental
+++ b/hack/ci/experimental
@@ -2,7 +2,7 @@
 # Entrypoint for jenkins experimental CI
 set -eu -o pipefail
 hack/ \
 	binary-daemon \
diff --git a/hack/ci/janky b/hack/ci/janky
index 88cb9d9..ec48165 100755
--- a/hack/ci/janky
+++ b/hack/ci/janky
@@ -4,10 +4,6 @@
-bash <(curl -s \
-    -f coverage.txt \
-    -C "$GIT_SHA1" || \
-    echo 'Codecov failed to upload'
 hack/ \
 	binary-daemon \
diff --git a/hack/dind b/hack/dind
index 3254f9d..4188c1b 100755
--- a/hack/dind
+++ b/hack/dind
@@ -1,4 +1,4 @@
-#!/usr/bin/env bash
 set -e
 # DinD: a wrapper script which allows docker to be run inside a docker container.
diff --git a/hack/dockerfile/install/containerd.installer b/hack/dockerfile/install/containerd.installer
index 8b15eb8..e9f9e4a 100755
--- a/hack/dockerfile/install/containerd.installer
+++ b/hack/dockerfile/install/containerd.installer
@@ -28,9 +28,9 @@
-	mkdir -p ${PREFIX}
+	mkdir -p "${PREFIX}"
-	cp bin/containerd ${PREFIX}/containerd
-	cp bin/containerd-shim ${PREFIX}/containerd-shim
-	cp bin/ctr ${PREFIX}/ctr
+	cp bin/containerd "${PREFIX}/containerd"
+	cp bin/containerd-shim "${PREFIX}/containerd-shim"
+	cp bin/ctr "${PREFIX}/ctr"
diff --git a/hack/dockerfile/install/dockercli.installer b/hack/dockerfile/install/dockercli.installer
index ae3aa0d..03435fe 100755
--- a/hack/dockerfile/install/dockercli.installer
+++ b/hack/dockerfile/install/dockercli.installer
@@ -8,14 +8,13 @@
 	arch=$(uname -m)
 	# No official release of these platforms
-	if [[ "$arch" != "x86_64" ]] && [[ "$arch" != "s390x" ]]; then
+	if [ "$arch" != "x86_64" ] && [ "$arch" != "s390x" ]; then
-	curl -Ls $url/$DOCKERCLI_CHANNEL/$arch/docker-$DOCKERCLI_VERSION.tgz | \
-	tar -xz docker/docker
+	curl -Ls "${url}/${DOCKERCLI_CHANNEL}/${arch}/docker-${DOCKERCLI_VERSION}.tgz" | tar -xz docker/docker
 	mkdir -p ${PREFIX}
 	mv docker/docker ${PREFIX}/
 	rmdir docker
@@ -27,5 +26,5 @@
 	git checkout -q "v$DOCKERCLI_VERSION"
 	mkdir -p "$GOPATH/src/"
 	mv components/cli "$GOPATH/src/"
-	go build -buildmode=pie -o ${PREFIX}/docker
+	go build -buildmode=pie -o "${PREFIX}/docker" ""
diff --git a/hack/dockerfile/install/gometalinter.installer b/hack/dockerfile/install/gometalinter.installer
index d921fd7..461850f 100755
--- a/hack/dockerfile/install/gometalinter.installer
+++ b/hack/dockerfile/install/gometalinter.installer
@@ -7,6 +7,6 @@
 	go get -d
 	cd "$GOPATH/src/"
 	git checkout -q "$GOMETALINTER_COMMIT"
-	go build -buildmode=pie -o ${PREFIX}/gometalinter
-	GOBIN=${PREFIX} ${PREFIX}/gometalinter --install
+	go build -buildmode=pie -o "${PREFIX}/gometalinter" ""
+	GOBIN=${PREFIX} "${PREFIX}/gometalinter" --install
diff --git a/hack/dockerfile/install/gotestsum.installer b/hack/dockerfile/install/gotestsum.installer
new file mode 100755
index 0000000..032f46f
--- /dev/null
+++ b/hack/dockerfile/install/gotestsum.installer
@@ -0,0 +1,11 @@
+install_gotestsum() {
+	echo "Installing gotestsum version $GOTESTSUM_COMMIT"
+	go get -d
+	cd "$GOPATH/src/"
+	git checkout -q "$GOTESTSUM_COMMIT"
+	go build -buildmode=pie -o "${PREFIX}/gotestsum" ''
diff --git a/hack/dockerfile/install/ b/hack/dockerfile/install/
index a0ff09d..5e4a396 100755
--- a/hack/dockerfile/install/
+++ b/hack/dockerfile/install/
@@ -26,5 +26,5 @@
 	exit 1
-. $dir/$bin.installer
-install_$bin "$@"
+. ${dir}/${bin}.installer
+install_${bin} "$@"
diff --git a/hack/dockerfile/install/proxy.installer b/hack/dockerfile/install/proxy.installer
index 0dc73ba..1b286c5 100755
--- a/hack/dockerfile/install/proxy.installer
+++ b/hack/dockerfile/install/proxy.installer
@@ -32,7 +32,7 @@
 	git clone "$GOPATH/src/"
 	cd "$GOPATH/src/"
 	git checkout -q "$LIBNETWORK_COMMIT"
-	go build $BUILD_MODE -ldflags="$PROXY_LDFLAGS" -o ${PREFIX}/docker-proxy
+	go build ${BUILD_MODE} -ldflags="$PROXY_LDFLAGS" -o ${PREFIX}/docker-proxy
diff --git a/hack/dockerfile/install/runc.installer b/hack/dockerfile/install/runc.installer
index a8156db..dd9950f 100755
--- a/hack/dockerfile/install/runc.installer
+++ b/hack/dockerfile/install/runc.installer
@@ -25,6 +25,6 @@
 	make BUILDTAGS="$RUNC_BUILDTAGS" "$target"
-	mkdir -p ${PREFIX}
-	cp runc ${PREFIX}/runc
+	mkdir -p "${PREFIX}"
+	cp runc "${PREFIX}/runc"
diff --git a/hack/dockerfile/install/tini.installer b/hack/dockerfile/install/tini.installer
index 34f43f1..c622357 100755
--- a/hack/dockerfile/install/tini.installer
+++ b/hack/dockerfile/install/tini.installer
@@ -9,6 +9,6 @@
 	git checkout -q "$TINI_COMMIT"
 	cmake .
 	make tini-static
-	mkdir -p ${PREFIX}
-	cp tini-static ${PREFIX}/docker-init
+	mkdir -p "${PREFIX}"
+	cp tini-static "${PREFIX}/docker-init"
diff --git a/hack/dockerfile/install/tomlv.installer b/hack/dockerfile/install/tomlv.installer
index c926454..52f7931 100755
--- a/hack/dockerfile/install/tomlv.installer
+++ b/hack/dockerfile/install/tomlv.installer
@@ -8,5 +8,5 @@
 	echo "Install tomlv version $TOMLV_COMMIT"
 	git clone "$GOPATH/src/"
 	cd "$GOPATH/src/" && git checkout -q "$TOMLV_COMMIT"
-	go build -v -buildmode=pie -o ${PREFIX}/tomlv
+	go build -v -buildmode=pie -o "${PREFIX}/tomlv" ""
diff --git a/hack/dockerfile/install/vndr.installer b/hack/dockerfile/install/vndr.installer
index e6a94e7..d53fada 100755
--- a/hack/dockerfile/install/vndr.installer
+++ b/hack/dockerfile/install/vndr.installer
@@ -7,5 +7,5 @@
 	git clone "$GOPATH/src/"
 	cd "$GOPATH/src/"
 	git checkout -q "$VNDR_COMMIT"
-	go build -buildmode=pie -v -o ${PREFIX}/vndr .
+	go build -buildmode=pie -v -o "${PREFIX}/vndr" .
diff --git a/hack/ b/hack/
index a01a573..90a01df 100755
--- a/hack/
+++ b/hack/
@@ -2,26 +2,26 @@
 set -eu
 swagger generate model -f api/swagger.yaml \
-    -t api -m types --skip-validator -C api/swagger-gen.yaml \
-    -n ErrorResponse \
-    -n GraphDriverData \
-    -n IdResponse \
-    -n ImageDeleteResponseItem \
-    -n ImageSummary \
-    -n Plugin -n PluginDevice -n PluginMount -n PluginEnv -n PluginInterfaceType \
-    -n Port \
-    -n ServiceUpdateResponse \
-    -n Volume
+	-t api -m types --skip-validator -C api/swagger-gen.yaml \
+	-n ErrorResponse \
+	-n GraphDriverData \
+	-n IdResponse \
+	-n ImageDeleteResponseItem \
+	-n ImageSummary \
+	-n Plugin -n PluginDevice -n PluginMount -n PluginEnv -n PluginInterfaceType \
+	-n Port \
+	-n ServiceUpdateResponse \
+	-n Volume
 swagger generate operation -f api/swagger.yaml \
-    -t api -a types -m types -C api/swagger-gen.yaml \
-    -T api/templates --skip-responses --skip-parameters --skip-validator \
-    -n Authenticate \
-    -n ContainerChanges \
-    -n ContainerCreate \
-    -n ContainerTop \
-    -n ContainerUpdate \
-    -n ContainerWait \
-    -n ImageHistory \
-    -n VolumeCreate \
-    -n VolumeList
+	-t api -a types -m types -C api/swagger-gen.yaml \
+	-T api/templates --skip-responses --skip-parameters --skip-validator \
+	-n Authenticate \
+	-n ContainerChanges \
+	-n ContainerCreate \
+	-n ContainerTop \
+	-n ContainerUpdate \
+	-n ContainerWait \
+	-n ImageHistory \
+	-n VolumeCreate \
+	-n VolumeList
diff --git a/hack/integration-cli-on-swarm/ b/hack/integration-cli-on-swarm/
deleted file mode 100644
index 852b36c..0000000
--- a/hack/integration-cli-on-swarm/
+++ /dev/null
@@ -1,68 +0,0 @@
-# Integration Testing on Swarm
-IT on Swarm allows you to execute integration test in parallel across a Docker Swarm cluster
-## Architecture
-### Master service
-  - Works as a funker caller
-  - Calls a worker funker (`-worker-service`) with a chunk of `-check.f` filter strings (passed as a file via `-input` flag, typically `/mnt/input`)
-### Worker service
-  - Works as a funker callee
-  - Executes an equivalent of `TESTFLAGS=-check.f TestFoo|TestBar|TestBaz ... make test-integration` using the bind-mounted API socket (`docker.sock`)
-### Client
-  - Controls master and workers via `docker stack`
-  - No need to have a local daemon
-Typically, the master and workers are supposed to be running on a cloud environment,
-while the client is supposed to be running on a laptop, e.g. Docker for Mac/Windows.
-## Requirement
-  - Docker daemon 1.13 or later
-  - Private registry for distributed execution with multiple nodes
-## Usage
-### Step 1: Prepare images
-    $ make build-integration-cli-on-swarm
-Following environment variables are known to work in this step:
-Note: during the transition into Moby Project, you might need to create a symbolic link `$GOPATH/src/` to `$GOPATH/src/`. 
-### Step 2: Execute tests
-    $ ./hack/integration-cli-on-swarm/integration-cli-on-swarm -replicas 40 -push-worker-image YOUR_REGISTRY.EXAMPLE.COM/integration-cli-worker:latest 
-Following environment variables are known to work in this step:
-#### Flags
-Basic flags:
- - `-replicas N`: the number of worker service replicas. i.e. degree of parallelism.
- - `-chunks N`: the number of chunks. By default, `chunks` == `replicas`.
- - `-push-worker-image REGISTRY/IMAGE:TAG`: push the worker image to the registry. Note that if you have only single node and hence you do not need a private registry, you do not need to specify `-push-worker-image`.
-Experimental flags for mitigating makespan nonuniformity:
- - `-shuffle`: Shuffle the test filter strings
-Flags for debugging IT on Swarm itself:
- - `-rand-seed N`: the random seed. This flag is useful for deterministic replaying. By default(0), the timestamp is used.
- - `-filters-file FILE`: the file contains `-check.f` strings. By default, the file is automatically generated.
- - `-dry-run`: skip the actual workload
- - `keep-executor`: do not auto-remove executor containers, which is used for running privileged programs on Swarm
diff --git a/hack/integration-cli-on-swarm/agent/Dockerfile b/hack/integration-cli-on-swarm/agent/Dockerfile
deleted file mode 100644
index 1ae228f..0000000
--- a/hack/integration-cli-on-swarm/agent/Dockerfile
+++ /dev/null
@@ -1,6 +0,0 @@
-# this Dockerfile is solely used for the master image.
-# Please refer to the top-level Makefile for the worker image.
-FROM golang:1.7
-ADD . /go/src/
-RUN go build -buildmode=pie -o /master
-ENTRYPOINT ["/master"]
diff --git a/hack/integration-cli-on-swarm/agent/master/call.go b/hack/integration-cli-on-swarm/agent/master/call.go
deleted file mode 100644
index dab9c67..0000000
--- a/hack/integration-cli-on-swarm/agent/master/call.go
+++ /dev/null
@@ -1,132 +0,0 @@
-package main
-import (
-	"encoding/json"
-	"fmt"
-	"log"
-	"strings"
-	"sync"
-	"sync/atomic"
-	"time"
-	""
-	""
-const (
-	// funkerRetryTimeout is for the issue
-	// When all the funker replicas are busy in their own job, we cannot connect to funker.
-	funkerRetryTimeout  = 1 * time.Hour
-	funkerRetryDuration = 1 * time.Second
-// ticker is needed for some CI (e.g., on Travis, job is aborted when no output emitted for 10 minutes)
-func ticker(d time.Duration) chan struct{} {
-	t := time.NewTicker(d)
-	stop := make(chan struct{})
-	go func() {
-		for {
-			select {
-			case <-t.C:
-				log.Printf("tick (just for keeping CI job active) per %s", d.String())
-			case <-stop:
-				t.Stop()
-			}
-		}
-	}()
-	return stop
-func executeTests(funkerName string, testChunks [][]string) error {
-	tickerStopper := ticker(9*time.Minute + 55*time.Second)
-	defer func() {
-		close(tickerStopper)
-	}()
-	begin := time.Now()
-	log.Printf("Executing %d chunks in parallel, against %q", len(testChunks), funkerName)
-	var wg sync.WaitGroup
-	var passed, failed uint32
-	for chunkID, tests := range testChunks {
-		log.Printf("Executing chunk %d (contains %d test filters)", chunkID, len(tests))
-		wg.Add(1)
-		go func(chunkID int, tests []string) {
-			defer wg.Done()
-			chunkBegin := time.Now()
-			result, err := executeTestChunkWithRetry(funkerName, types.Args{
-				ChunkID: chunkID,
-				Tests:   tests,
-			})
-			if result.RawLog != "" {
-				for _, s := range strings.Split(result.RawLog, "\n") {
-					log.Printf("Log (chunk %d): %s", chunkID, s)
-				}
-			}
-			if err != nil {
-				log.Printf("Error while executing chunk %d: %v",
-					chunkID, err)
-				atomic.AddUint32(&failed, 1)
-			} else {
-				if result.Code == 0 {
-					atomic.AddUint32(&passed, 1)
-				} else {
-					atomic.AddUint32(&failed, 1)
-				}
-				log.Printf("Finished chunk %d [%d/%d] with %d test filters in %s, code=%d.",
-					chunkID, passed+failed, len(testChunks), len(tests),
-					time.Since(chunkBegin), result.Code)
-			}
-		}(chunkID, tests)
-	}
-	wg.Wait()
-	// TODO: print actual tests rather than chunks
-	log.Printf("Executed %d chunks in %s. PASS: %d, FAIL: %d.",
-		len(testChunks), time.Since(begin), passed, failed)
-	if failed > 0 {
-		return fmt.Errorf("%d chunks failed", failed)
-	}
-	return nil
-func executeTestChunk(funkerName string, args types.Args) (types.Result, error) {
-	ret, err := funker.Call(funkerName, args)
-	if err != nil {
-		return types.Result{}, err
-	}
-	tmp, err := json.Marshal(ret)
-	if err != nil {
-		return types.Result{}, err
-	}
-	var result types.Result
-	err = json.Unmarshal(tmp, &result)
-	return result, err
-func executeTestChunkWithRetry(funkerName string, args types.Args) (types.Result, error) {
-	begin := time.Now()
-	for i := 0; time.Since(begin) < funkerRetryTimeout; i++ {
-		result, err := executeTestChunk(funkerName, args)
-		if err == nil {
-			log.Printf("executeTestChunk(%q, %d) returned code %d in trial %d", funkerName, args.ChunkID, result.Code, i)
-			return result, nil
-		}
-		if errorSeemsInteresting(err) {
-			log.Printf("Error while calling executeTestChunk(%q, %d), will retry (trial %d): %v",
-				funkerName, args.ChunkID, i, err)
-		}
-		// TODO: non-constant sleep
-		time.Sleep(funkerRetryDuration)
-	}
-	return types.Result{}, fmt.Errorf("could not call executeTestChunk(%q, %d) in %v", funkerName, args.ChunkID, funkerRetryTimeout)
-//  errorSeemsInteresting returns true if err does not seem about
-func errorSeemsInteresting(err error) bool {
-	boringSubstrs := []string{"connection refused", "connection reset by peer", "no such host", "transport endpoint is not connected", "no route to host"}
-	errS := err.Error()
-	for _, boringS := range boringSubstrs {
-		if strings.Contains(errS, boringS) {
-			return false
-		}
-	}
-	return true
diff --git a/hack/integration-cli-on-swarm/agent/master/master.go b/hack/integration-cli-on-swarm/agent/master/master.go
deleted file mode 100644
index a0d9a0d..0000000
--- a/hack/integration-cli-on-swarm/agent/master/master.go
+++ /dev/null
@@ -1,65 +0,0 @@
-package main
-import (
-	"errors"
-	"flag"
-	"io/ioutil"
-	"log"
-	"strings"
-func main() {
-	if err := xmain(); err != nil {
-		log.Fatalf("fatal error: %v", err)
-	}
-func xmain() error {
-	workerService := flag.String("worker-service", "", "Name of worker service")
-	chunks := flag.Int("chunks", 0, "Number of chunks")
-	input := flag.String("input", "", "Path to input file")
-	randSeed := flag.Int64("rand-seed", int64(0), "Random seed")
-	shuffle := flag.Bool("shuffle", false, "Shuffle the input so as to mitigate makespan nonuniformity")
-	flag.Parse()
-	if *workerService == "" {
-		return errors.New("worker-service unset")
-	}
-	if *chunks == 0 {
-		return errors.New("chunks unset")
-	}
-	if *input == "" {
-		return errors.New("input unset")
-	}
-	tests, err := loadTests(*input)
-	if err != nil {
-		return err
-	}
-	testChunks := chunkTests(tests, *chunks, *shuffle, *randSeed)
-	log.Printf("Loaded %d tests (%d chunks)", len(tests), len(testChunks))
-	return executeTests(*workerService, testChunks)
-func chunkTests(tests []string, numChunks int, shuffle bool, randSeed int64) [][]string {
-	// shuffling (experimental) mitigates makespan nonuniformity
-	// Not sure this can cause some locality problem..
-	if shuffle {
-		shuffleStrings(tests, randSeed)
-	}
-	return chunkStrings(tests, numChunks)
-func loadTests(filename string) ([]string, error) {
-	b, err := ioutil.ReadFile(filename)
-	if err != nil {
-		return nil, err
-	}
-	var tests []string
-	for _, line := range strings.Split(string(b), "\n") {
-		s := strings.TrimSpace(line)
-		if s != "" {
-			tests = append(tests, s)
-		}
-	}
-	return tests, nil
diff --git a/hack/integration-cli-on-swarm/agent/master/set.go b/hack/integration-cli-on-swarm/agent/master/set.go
deleted file mode 100644
index d28c41d..0000000
--- a/hack/integration-cli-on-swarm/agent/master/set.go
+++ /dev/null
@@ -1,28 +0,0 @@
-package main
-import (
-	"math/rand"
-// chunkStrings chunks the string slice
-func chunkStrings(x []string, numChunks int) [][]string {
-	var result [][]string
-	chunkSize := (len(x) + numChunks - 1) / numChunks
-	for i := 0; i < len(x); i += chunkSize {
-		ub := i + chunkSize
-		if ub > len(x) {
-			ub = len(x)
-		}
-		result = append(result, x[i:ub])
-	}
-	return result
-// shuffleStrings shuffles strings
-func shuffleStrings(x []string, seed int64) {
-	r := rand.New(rand.NewSource(seed))
-	for i := range x {
-		j := r.Intn(i + 1)
-		x[i], x[j] = x[j], x[i]
-	}
diff --git a/hack/integration-cli-on-swarm/agent/master/set_test.go b/hack/integration-cli-on-swarm/agent/master/set_test.go
deleted file mode 100644
index c172562..0000000
--- a/hack/integration-cli-on-swarm/agent/master/set_test.go
+++ /dev/null
@@ -1,63 +0,0 @@
-package main
-import (
-	"fmt"
-	"reflect"
-	"testing"
-	"time"
-func generateInput(inputLen int) []string {
-	var input []string
-	for i := 0; i < inputLen; i++ {
-		input = append(input, fmt.Sprintf("s%d", i))
-	}
-	return input
-func testChunkStrings(t *testing.T, inputLen, numChunks int) {
-	t.Logf("inputLen=%d, numChunks=%d", inputLen, numChunks)
-	input := generateInput(inputLen)
-	result := chunkStrings(input, numChunks)
-	t.Logf("result has %d chunks", len(result))
-	var inputReconstructedFromResult []string
-	for i, chunk := range result {
-		t.Logf("chunk %d has %d elements", i, len(chunk))
-		inputReconstructedFromResult = append(inputReconstructedFromResult, chunk...)
-	}
-	if !reflect.DeepEqual(input, inputReconstructedFromResult) {
-		t.Fatal("input != inputReconstructedFromResult")
-	}
-func TestChunkStrings_4_4(t *testing.T) {
-	testChunkStrings(t, 4, 4)
-func TestChunkStrings_4_1(t *testing.T) {
-	testChunkStrings(t, 4, 1)
-func TestChunkStrings_1_4(t *testing.T) {
-	testChunkStrings(t, 1, 4)
-func TestChunkStrings_1000_8(t *testing.T) {
-	testChunkStrings(t, 1000, 8)
-func TestChunkStrings_1000_9(t *testing.T) {
-	testChunkStrings(t, 1000, 9)
-func testShuffleStrings(t *testing.T, inputLen int, seed int64) {
-	t.Logf("inputLen=%d, seed=%d", inputLen, seed)
-	x := generateInput(inputLen)
-	shuffleStrings(x, seed)
-	t.Logf("shuffled: %v", x)
-func TestShuffleStrings_100(t *testing.T) {
-	testShuffleStrings(t, 100, time.Now().UnixNano())
diff --git a/hack/integration-cli-on-swarm/agent/types/types.go b/hack/integration-cli-on-swarm/agent/types/types.go
deleted file mode 100644
index fc598f0..0000000
--- a/hack/integration-cli-on-swarm/agent/types/types.go
+++ /dev/null
@@ -1,18 +0,0 @@
-package types
-// Args is the type for funker args
-type Args struct {
-	// ChunkID is an unique number of the chunk
-	ChunkID int `json:"chunk_id"`
-	// Tests is the set of the strings that are passed as `-check.f` filters
-	Tests []string `json:"tests"`
-// Result is the type for funker result
-type Result struct {
-	// ChunkID corresponds to Args.ChunkID
-	ChunkID int `json:"chunk_id"`
-	// Code is the exit code
-	Code   int    `json:"code"`
-	RawLog string `json:"raw_log"`
diff --git a/hack/integration-cli-on-swarm/agent/vendor.conf b/hack/integration-cli-on-swarm/agent/vendor.conf
deleted file mode 100644
index efd6d6d..0000000
--- a/hack/integration-cli-on-swarm/agent/vendor.conf
+++ /dev/null
@@ -1,2 +0,0 @@
-# dependencies specific to worker (i.e. are not vendored here eaa0a2e06f30e72c9a0b7f858951e581e26ef773
diff --git a/hack/integration-cli-on-swarm/agent/vendor/ b/hack/integration-cli-on-swarm/agent/vendor/
deleted file mode 100644
index 75191a4..0000000
--- a/hack/integration-cli-on-swarm/agent/vendor/
+++ /dev/null
@@ -1,191 +0,0 @@
-   limitations under the License.
diff --git a/hack/make.ps1 b/hack/make.ps1
index be60c08..6ff7a7f 100644
--- a/hack/make.ps1
+++ b/hack/make.ps1
@@ -327,19 +327,16 @@
 # Run the integration tests
 Function Run-IntegrationTests() {
     $env:DOCKER_INTEGRATION_DAEMON_DEST = $root + "\bundles\tmp"
-    $dirs =  Get-ChildItem -Path integration -Directory -Recurse
+    $dirs = go list -test -f '{{- if ne .ForTest `"`" -}}{{- .Dir -}}{{- end -}}' .\integration\...
     $integration_api_dirs = @()
     ForEach($dir in $dirs) {
-        $RelativePath = "." + $dir.FullName -replace "$($PWD.Path -replace "\\","\\")",""
-        If ($RelativePath -notmatch '(^.\\integration($|\\internal)|\\testdata)') {
-            $integration_api_dirs += $dir
-            Write-Host "Building test suite binary $RelativePath"
-            go test -c -o "$RelativePath\test.exe" $RelativePath
-        }
+        $integration_api_dirs += $dir
+        Write-Host "Building test suite binary $dir"
+        go test -c -o "$dir\test.exe" $dir
     ForEach($dir in $integration_api_dirs) {
-        Set-Location $dir.FullName
+        Set-Location $dir
         Write-Host "Running $($PWD.Path)"
         $pinfo = New-Object System.Diagnostics.ProcessStartInfo
         $pinfo.FileName = "$($PWD.Path)\test.exe"
diff --git a/hack/ b/hack/
index 62c72a0..58efc74 100755
--- a/hack/
+++ b/hack/
@@ -148,16 +148,7 @@
 ORIG_BUILDFLAGS=( -tags "autogen netgo osusergo static_build $DOCKER_BUILDTAGS" -installsuffix netgo )
 # see for why -installsuffix is necessary here
-# Test timeout.
-if [ "${DOCKER_ENGINE_GOARCH}" == "arm64" ] || [ "${DOCKER_ENGINE_GOARCH}" == "arm" ]; then
-	: ${TIMEOUT:=10m}
-elif [ "${DOCKER_ENGINE_GOARCH}" == "windows" ]; then
-	: ${TIMEOUT:=8m}
-	: ${TIMEOUT:=5m}
diff --git a/hack/make/.binary b/hack/make/.binary
index 010c2c1..ff33e18 100644
--- a/hack/make/.binary
+++ b/hack/make/.binary
@@ -68,7 +68,7 @@
 	" \
 echo "Created binary: $DEST/$BINARY_FULLNAME"
diff --git a/hack/make/.go-autogen b/hack/make/.go-autogen
index ea8a32f..0afd559 100644
--- a/hack/make/.go-autogen
+++ b/hack/make/.go-autogen
@@ -67,7 +67,7 @@
 	[ ! -z $GITCOMMIT ]    && defs="$defs -D DOCKER_COMMIT=\"$GITCOMMIT\""
 	function makeres {
+		${WINDRES} \
 			-i hack/make/.resources-windows/$1 \
 			-o $3 \
 			-F $2 \
@@ -76,7 +76,7 @@
+	${WINDMC} \
 		hack/make/.resources-windows/ \
 		-h autogen/winresources/tmp \
 		-r autogen/winresources/tmp
diff --git a/hack/make/.integration-daemon-start b/hack/make/.integration-daemon-start
index dabcfbe..34a2c87 100644
--- a/hack/make/.integration-daemon-start
+++ b/hack/make/.integration-daemon-start
@@ -20,7 +20,7 @@
 # This is a temporary hack for split-binary mode. It can be removed once
 # is merged into docker master
 if [ "$(go env GOOS)" = 'windows' ]; then
-       return
+	return
 if [ -z "$DOCKER_TEST_HOST" ]; then
@@ -86,8 +86,8 @@
 			--storage-driver "$DOCKER_GRAPHDRIVER" \
 			--pidfile "$DEST/" \
 			--userland-proxy="$DOCKER_USERLANDPROXY" \
-			$storage_params \
-			$extra_params \
+			${storage_params} \
+			${extra_params} \
 				&> "$DEST/docker.log"
 	) &
@@ -97,7 +97,7 @@
 # give it a little time to come up so it's "ready"
 echo "INFO: Waiting for daemon to start..."
-while ! $TEST_CLIENT_BINARY version &> /dev/null; do
+while ! ${TEST_CLIENT_BINARY} version &> /dev/null; do
 	(( tries-- ))
 	if [ $tries -le 0 ]; then
 		printf "\n"
@@ -106,7 +106,7 @@
 			echo >&2 "  check $DEST/docker.log for details"
 			echo >&2 "error: daemon at $DOCKER_HOST fails to '$TEST_CLIENT_BINARY version':"
-			$TEST_CLIENT_BINARY version >&2 || true
+			${TEST_CLIENT_BINARY} version >&2 || true
 			# Additional Windows CI debugging as this is a common error as of
 			# January 2016
 			if [ "$(go env GOOS)" = 'windows' ]; then
diff --git a/hack/make/.integration-daemon-stop b/hack/make/.integration-daemon-stop
index c1d43e1..63f7f36 100644
--- a/hack/make/.integration-daemon-stop
+++ b/hack/make/.integration-daemon-stop
@@ -10,6 +10,8 @@
 		if ! wait "$pid"; then
 			echo >&2 "warning: PID $pid from $pidFile had a nonzero exit code"
+		root=$(dirname "$pidFile")/root
+		umount "$root" || true
 	if [ -z "$DOCKER_TEST_HOST" ]; then
diff --git a/hack/make/.integration-test-helpers b/hack/make/.integration-test-helpers
index 149b653..abe6947 100644
--- a/hack/make/.integration-test-helpers
+++ b/hack/make/.integration-test-helpers
@@ -5,7 +5,19 @@
 #     TESTFLAGS='-check.f DockerSuite.TestBuild*' ./hack/ binary test-integration
-if [ -z $MAKEDIR ]; then
+if [[ "${TESTFLAGS}" = *-check.f* ]]; then
+	echo Skipping integration tests since TESTFLAGS includes integration-cli only flags
+if [[ "${TESTFLAGS}" = ** ]]; then
+	echo Skipping integration-cli tests since TESTFLAGS includes integration only flags
+if [ -z ${MAKEDIR} ]; then
 	export MAKEDIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
 source "$MAKEDIR/.go-autogen"
@@ -15,31 +27,34 @@
-	find ./integration -type d |
-	grep -vE '(^./integration($|/internal)|/testdata)')"}
+integration_api_dirs=${TEST_INTEGRATION_DIR:-"$(go list  -test -f '{{- if ne .ForTest "" -}}{{- .Dir -}}{{- end -}}'  ./integration/...)"}
 run_test_integration() {
-	[[ "$TESTFLAGS" != *-check.f* ]] && run_test_integration_suites
-	run_test_integration_legacy_suites
+	set_platform_timeout
+	if [ -z "${TEST_SKIP_INTEGRATION}" ]; then
+		run_test_integration_suites
+	fi
+	if [ -z "${TEST_SKIP_INTEGRATION_CLI}" ]; then
+		run_test_integration_legacy_suites
+	fi
 run_test_integration_suites() {
-	local flags="-test.v -test.timeout=${TIMEOUT} $TESTFLAGS"
-	for dir in $integration_api_dirs; do
+	local flags="-test.v -test.timeout=${TIMEOUT} $TESTFLAGS ${TESTFLAGS_INTEGRATION}"
+	for dir in ${integration_api_dirs}; do
 		if ! (
-			cd $dir
-			echo "Running $PWD"
-			test_env ./test.main $flags
+			cd "$dir"
+			echo "Running $PWD flags=${flags}"
+			test_env ./test.main ${flags}
 		); then exit 1; fi
 run_test_integration_legacy_suites() {
-		flags="-check.v -check.timeout=${TIMEOUT} -test.timeout=360m $TESTFLAGS"
+		flags="-check.v -check.timeout=${TIMEOUT} -test.timeout=360m $TESTFLAGS ${TESTFLAGS_INTEGRATION_CLI}"
 		cd integration-cli
-		echo "Running $PWD"
+		echo "Running $PWD flags=${flags}"
 		test_env ./test.main $flags
@@ -49,10 +64,14 @@
 		echo "Skipping building test binaries; as DOCKER_INTEGRATION_TESTS_VERIFIED is set"
-	build_test_suite_binary ./integration-cli "test.main"
-	for dir in $integration_api_dirs; do
-		build_test_suite_binary "$dir" "test.main"
-	done
+	if [ -z "${TEST_SKIP_INTEGRATION_CLI}" ]; then
+		build_test_suite_binary ./integration-cli "test.main"
+	fi
+	if [ -z "${TEST_SKIP_INTEGRATION}" ]; then
+		for dir in ${integration_api_dirs}; do
+			build_test_suite_binary "$dir" "test.main"
+		done
+	fi
 # Build a binary for a test suite package
@@ -70,7 +89,7 @@
 repeat() {
-	for i in $(seq 1 $TEST_REPEAT); do
+	for i in $(seq 1 ${TEST_REPEAT}); do
 		echo "Running integration-test (iteration $i)"
@@ -104,10 +123,9 @@
 error_on_leaked_containerd_shims() {
-	if [ "$(go env GOOS)" == 'windows' ]; then
+	if [ "$(go env GOOS)" = 'windows' ]; then
@@ -115,8 +133,28 @@
 	            awk '$2 == "containerd-shim" && $4 ~ /.*\/bundles\/.*\/test-integration/ { print $1 }')
 	if [ -n "$leftovers" ]; then
 		ps aux
-		kill -9 $leftovers 2> /dev/null
+		kill -9 ${leftovers} 2> /dev/null
 		echo "!!!! WARNING you have left over shim(s), Cleanup your test !!!!"
 		exit 1
+set_platform_timeout() {
+	# Test timeout.
+	if [ "${DOCKER_ENGINE_GOARCH}" = "arm64" ] || [ "${DOCKER_ENGINE_GOARCH}" = "arm" ]; then
+		: ${TIMEOUT:=10m}
+	elif [ "${DOCKER_ENGINE_GOARCH}" = "windows" ]; then
+		: ${TIMEOUT:=8m}
+	else
+		: ${TIMEOUT:=5m}
+	fi
+	if [ "${TEST_REPEAT}" -gt 1 ]; then
+		# TIMEOUT needs to take TEST_REPEAT into account, or a premature time out may happen.
+		# The following ugliness will:
+		# - remove last character (usually 'm' from '10m')
+		# - multiply by testcount
+		# - add last character back
+		TIMEOUT=$((${TIMEOUT::-1} * ${TEST_REPEAT}))${TIMEOUT:$((${#TIMEOUT}-1)):1}
+	fi
diff --git a/hack/make/build-integration-test-binary b/hack/make/build-integration-test-binary
index bbd5a22..698717f0 100755
--- a/hack/make/build-integration-test-binary
+++ b/hack/make/build-integration-test-binary
@@ -1,5 +1,5 @@
 #!/usr/bin/env bash
-# required by `make build-integration-cli-on-swarm`
+# required by
 set -e
 source hack/make/.integration-test-helpers
diff --git a/hack/make/cross b/hack/make/cross
index 497f02a..47cb667 100644
--- a/hack/make/cross
+++ b/hack/make/cross
@@ -2,28 +2,28 @@
 set -e
 # if we have our linux/amd64 version compiled, let's symlink it in
-if [ -x "$DEST/../binary-daemon/dockerd-$VERSION" ]; then
+if [ -x "${DEST}/../binary-daemon/dockerd-${VERSION}" ]; then
 	arch=$(go env GOHOSTARCH)
 	mkdir -p "$DEST/linux/${arch}"
-		cd "$DEST/linux/${arch}"
+		cd "${DEST}/linux/${arch}"
 		ln -sf ../../../binary-daemon/* ./
-	echo "Created symlinks:" "$DEST/linux/${arch}/"*
+	echo "Created symlinks:" "${DEST}/linux/${arch}/"*
-for platform in $DOCKER_CROSSPLATFORMS; do
+for platform in ${DOCKER_CROSSPLATFORMS}; do
 		export KEEPDEST=1
-		export DEST="$DEST/$platform" # bundles/VERSION/cross/GOOS/GOARCH/docker-VERSION
+		export DEST="${DEST}/${platform}" # bundles/VERSION/cross/GOOS/GOARCH/docker-VERSION
 		export GOOS=${platform%/*}
 		export GOARCH=${platform##*/}
-		echo "Cross building: $DEST"
-		mkdir -p "$DEST"
-		ABS_DEST="$(cd "$DEST" && pwd -P)"
+		echo "Cross building: ${DEST}"
+		mkdir -p "${DEST}"
+		ABS_DEST="$(cd "${DEST}" && pwd -P)"
 		source "${MAKEDIR}/binary-daemon"
 		source "${MAKEDIR}/cross-platform-dependent"
diff --git a/hack/make/cross-platform-dependent b/hack/make/cross-platform-dependent
index 52632c3..21824ed 100644
--- a/hack/make/cross-platform-dependent
+++ b/hack/make/cross-platform-dependent
@@ -1,6 +1,6 @@
 #!/usr/bin/env bash
 set -e
-if [ $platform == "windows/amd64" ]; then
+if [ ${platform} == "windows/amd64" ]; then
 	source "${MAKEDIR}/containerutility"
diff --git a/hack/make/dynbinary b/hack/make/dynbinary
index 981e505..2424046 100644
--- a/hack/make/dynbinary
+++ b/hack/make/dynbinary
@@ -3,8 +3,7 @@
 # This script exists as backwards compatibility for CI
-    DEST="${DEST}-daemon"
-    ABS_DEST="${ABS_DEST}-daemon"
-    . hack/make/dynbinary-daemon
+	DEST="${DEST}-daemon"
+	ABS_DEST="${ABS_DEST}-daemon"
+	. hack/make/dynbinary-daemon
diff --git a/hack/make/run b/hack/make/run
index 3254280..eff7dd9 100644
--- a/hack/make/run
+++ b/hack/make/run
@@ -35,10 +35,10 @@
 args="--debug \
 	--host tcp://${listen_port} --host unix:///var/run/docker.sock \
-	--storage-driver "$DOCKER_GRAPHDRIVER" \
-	--userland-proxy="$DOCKER_USERLANDPROXY" \
+	--storage-driver "${DOCKER_GRAPHDRIVER}" \
+	--userland-proxy="${DOCKER_USERLANDPROXY}" \
 	$storage_params \
-echo dockerd $args
-exec dockerd $args
+echo dockerd ${args}
+exec dockerd ${args}
diff --git a/hack/make/test-docker-py b/hack/make/test-docker-py
index b30879e..9625f47 100644
--- a/hack/make/test-docker-py
+++ b/hack/make/test-docker-py
@@ -3,18 +3,62 @@
 source hack/make/.integration-test-helpers
-# subshell so that we can export PATH without breaking other things
+# The commit or tag to use for testing
+# TODO docker 17.06 cli client used in CI fails to build using a sha;
+# unable to prepare context: unable to 'git clone' to temporary context directory: error fetching: error: no such remote ref ead0bb9e08c13dd3d1712759491eee06bf5a5602
+#: exit status 128
+: "${DOCKER_PY_COMMIT:=4.0.2}"
+# custom options to pass py.test
+# TODO remove these skip once we update to a docker-py version that has,,
+--deselect=tests/integration/ \
+--deselect=tests/integration/ \
+--deselect=tests/integration/ \
+--deselect=tests/integration/ \
+--deselect=tests/integration/ \
+--junitxml=${DEST}/junit-report.xml \
 	bundle .integration-daemon-start
-	dockerPy='/docker-py'
-	[ -d "$dockerPy" ] || {
-		dockerPy="$DEST/docker-py"
-		git clone "$dockerPy"
-	}
+	docker_host_scheme=$(echo "${DOCKER_HOST}" | cut -d: -f1 -)
-	# exporting PYTHONPATH to import "docker" from our local docker-py
-	test_env PYTHONPATH="$dockerPy" py.test --junitxml="$DEST/results.xml" "$dockerPy/tests/integration"
+	case "${docker_host_scheme}" in
+		unix)
+			# trim the tcp:// scheme, and bind-mount the docker socket into the container
+			run_opts="--mount type=bind,src=${DOCKER_HOST#unix://},dst=/var/run/docker.sock"
+			;;
+		tcp)
+			# run container in host-mode networking so that it can connect to the
+			# daemon from the current networking namespace (e.g., to connect to localhost)
+			run_opts="--network=host -e DOCKER_HOST=${DOCKER_HOST}"
+			;;
+		*)
+			echo "WARN: Skipping test-docker-py: connecting to docker daemon using ${docker_host_scheme} (${DOCKER_HOST}) not supported"
+			bundle .integration-daemon-stop
+			return 0
+	esac
+	docker_py_image="docker-sdk-python3:${DOCKER_PY_COMMIT}"
+	if ! docker image inspect "dockerPyImage" &> /dev/null; then
+		echo INFO: Building ${docker_py_image}...
+		(
+			[ -n "${TESTDEBUG}" ] && set -x
+			[ -z "${TESTDEBUG}" ] && build_opts="--quiet"
+			[ -f /.dockerenv ] || build_opts="${build_opts} --network=host"
+			# shellcheck disable=SC2086
+			exec docker build ${build_opts} -t "${docker_py_image}" -f tests/Dockerfile "${DOCKER_PY_COMMIT}"
+		)
+	fi
+	echo INFO: Starting docker-py tests...
+	(
+		[ -n "${TESTDEBUG}" ] && set -x
+		# shellcheck disable=SC2086,SC2140
+		exec docker run --rm ${run_opts} --mount type=bind,"src=${ABS_DEST}","dst=/src/${DEST}" "${docker_py_image}" pytest ${PY_TEST_OPTIONS} tests/integration
+	)
 	bundle .integration-daemon-stop
 ) 2>&1 | tee -a "$DEST/test.log"
diff --git a/hack/make/test-integration b/hack/make/test-integration
index c807cd4..039afc9 100755
--- a/hack/make/test-integration
+++ b/hack/make/test-integration
@@ -1,14 +1,26 @@
 #!/usr/bin/env bash
 set -e -o pipefail
+if [ -n "$TEST_INTEGRATION_DEST" ]; then
+	mkdir -p "$DEST"
 source hack/make/.integration-test-helpers
+if [ ! -z "${TEST_SKIP_INTEGRATION}" ] && [ ! -z "${TEST_SKIP_INTEGRATION_CLI}" ]; then
+	echo integration and integration-cli skipped according to env vars
+	exit 0
+	env
 	bundle .integration-daemon-start
 	bundle .integration-daemon-setup
-	local testexit=0
+	testexit=0
 	( repeat run_test_integration ) || testexit=$?
 	# Always run cleanup, even if the subshell fails
@@ -16,6 +28,6 @@
-	exit $testexit
+	exit ${testexit}
 ) 2>&1 | tee -a "$DEST/test.log"
diff --git a/hack/make/test-integration-flaky b/hack/make/test-integration-flaky
index 14fb034..a613d6c 100644
--- a/hack/make/test-integration-flaky
+++ b/hack/make/test-integration-flaky
@@ -3,13 +3,13 @@
 source hack/validate/.validate
-    validate_diff --diff-filter=ACMR --unified=0 -- 'integration/*_test.go' |
-    grep -E '^(\+func )(.*)(\*testing)' || true
+	validate_diff --diff-filter=ACMR --unified=0 -- 'integration/*_test.go' |
+	grep -E '^(\+func )(.*)(\*testing)' || true
 if [ -z "$new_tests" ]; then
-    echo 'No new tests added to integration.'
-    return
+	echo 'No new tests added to integration.'
+	return
@@ -18,20 +18,12 @@
 echo "Running stress test for them."
-    TESTARRAY=$(echo "$new_tests" | sed 's/+func //' | awk -F'\\(' '{print $1}' | tr '\n' '|')
-    # Note: TEST_REPEAT will make the test suite run 5 times, restarting the daemon
-    # whereas testcount will make each test run 5 times in a row under the same daemon.
-    # This will make a total of 25 runs for each test in TESTARRAY.
-    export TEST_REPEAT=5
-    local testcount=5
-    # However, TIMEOUT needs to take testcount into account, or a premature time out may happen.
-    # The following ugliness will:
-    # - remove last character (usually 'm' from '10m')
-    # - multiply by testcount
-    # - add last character back
-    export TIMEOUT=$((${TIMEOUT::-1} * $testcount))${TIMEOUT:$((${#TIMEOUT}-1)):1}
-    export TESTFLAGS="-test.count $testcount ${TESTARRAY%?}"
-    echo "Using test flags: $TESTFLAGS"
-    source hack/make/test-integration
+	TESTARRAY=$(echo "$new_tests" | sed 's/+func //' | awk -F'\\(' '{print $1}' | tr '\n' '|')
+	# Note: TEST_REPEAT will make the test suite run 5 times, restarting the daemon
+	# and each test will run 5 times in a row under the same daemon.
+	# This will make a total of 25 runs for each test in TESTARRAY.
+	export TEST_REPEAT=5
+	export TESTFLAGS="-test.count ${TEST_REPEAT} ${TESTARRAY%?}"
+	echo "Using test flags: $TESTFLAGS"
+	source hack/make/test-integration
diff --git a/hack/test/ b/hack/test/
index 122d58f..6463f2f 100755
--- a/hack/test/
+++ b/hack/test/
@@ -2,7 +2,7 @@
 set -e -u -o pipefail
 ARCH=$(uname -m)
-if [ "$ARCH" == "x86_64" ]; then
+if [ "$ARCH" = "x86_64" ]; then
@@ -17,8 +17,13 @@
 	grep -vE '(^/tests/integration($|/internal)|/testdata)')"}
 run_test_integration() {
-	[[ "$TESTFLAGS" != *-check.f* ]] && run_test_integration_suites
-	run_test_integration_legacy_suites
+	set_platform_timeout
+	if [[ "$TESTFLAGS" != *-check.f* ]]; then
+		run_test_integration_suites
+	fi
+	if [[ "$TESTFLAGS" != ** ]]; then
+		run_test_integration_legacy_suites
+	fi
 run_test_integration_suites() {
@@ -68,5 +73,16 @@
+set_platform_timeout() {
+	# Test timeout.
+	if [ "${DOCKER_ENGINE_GOARCH}" = "arm64" ] || [ "${DOCKER_ENGINE_GOARCH}" = "arm" ]; then
+		: ${TIMEOUT:=10m}
+	elif [ "${DOCKER_ENGINE_GOARCH}" = "windows" ]; then
+		: ${TIMEOUT:=8m}
+	else
+		: ${TIMEOUT:=5m}
+	fi
 sh /scripts/
diff --git a/hack/test/unit b/hack/test/unit
index ac27f68..1aea06c 100755
--- a/hack/test/unit
+++ b/hack/test/unit
@@ -1,34 +1,28 @@
 #!/usr/bin/env bash
-# Run unit tests
+# Run unit tests and create report
 # TESTFLAGS - add additional test flags. Ex:
-#   TESTFLAGS="-v -run TestBuild" hack/test/unit
+#   TESTFLAGS='-v -run TestBuild' hack/test/unit
 # TESTDIRS - run tests for specified packages. Ex:
-#    TESTDIRS="./pkg/term" hack/test/unit
+#   TESTDIRS='./pkg/term' hack/test/unit
 set -eu -o pipefail
-TESTFLAGS+=" -test.timeout=${TIMEOUT:-5m}"
-BUILDFLAGS=( -tags "netgo seccomp libdm_no_deferred_remove" )
+BUILDFLAGS=( -tags 'netgo seccomp libdm_no_deferred_remove' )
 pkg_list=$(go list $TESTDIRS | grep -vE "($exclude_paths)")
-for pkg in $pkg_list; do
-    go test "${BUILDFLAGS[@]}" \
-        -cover \
-        -coverprofile=profile.out \
-        -covermode=atomic \
-        $TESTFLAGS \
-        "${pkg}"
-    if test -f profile.out; then
-        cat profile.out >> coverage.txt
-        rm profile.out
-    fi
+mkdir -p bundles
+gotestsum --format=standard-quiet --jsonfile=bundles/go-test-report.json --junitfile=bundles/junit-report.xml -- \
+	"${BUILDFLAGS[@]}" \
+	-cover \
+	-coverprofile=bundles/profile.out \
+	-covermode=atomic \
+	${pkg_list}
diff --git a/hack/validate/all b/hack/validate/all
index 9d95c2d..8e3cbfc 100755
--- a/hack/validate/all
+++ b/hack/validate/all
@@ -4,5 +4,5 @@
 export SCRIPTDIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
-. $SCRIPTDIR/default
-. $SCRIPTDIR/vendor
+. ${SCRIPTDIR}/default
+. ${SCRIPTDIR}/vendor
diff --git a/hack/validate/changelog-date-descending b/hack/validate/changelog-date-descending
index b9c3368..301f9ba 100755
--- a/hack/validate/changelog-date-descending
+++ b/hack/validate/changelog-date-descending
@@ -3,8 +3,8 @@
 if [ ! -r "$changelogFile" ]; then
-  echo "Unable to read file $changelogFile" >&2
-  exit 1
+	echo "Unable to read file $changelogFile" >&2
+	exit 1
 grep -e '^## ' "$changelogFile" | awk '{print$3}' | sort -c -r || exit 2
diff --git a/hack/validate/changelog-well-formed b/hack/validate/changelog-well-formed
index 6c7ce1a..ea7ef0f 100755
--- a/hack/validate/changelog-well-formed
+++ b/hack/validate/changelog-well-formed
@@ -3,8 +3,8 @@
 if [ ! -r "$changelogFile" ]; then
-  echo "Unable to read file $changelogFile" >&2
-  exit 1
+	echo "Unable to read file $changelogFile" >&2
+	exit 1
@@ -12,14 +12,14 @@
 # e.g. "## 1.12.3 (2016-10-26)"
 VER_LINE_REGEX='^## [0-9]+\.[0-9]+\.[0-9]+(-ce)? \([0-9]+-[0-9]+-[0-9]+\)$'
 while read -r line; do
-  if ! [[ "$line" =~ $VER_LINE_REGEX ]]; then
-    echo "Malformed changelog $changelogFile line \"$line\"" >&2
-    changelogWellFormed=0
-  fi
+	if ! [[ "$line" =~ $VER_LINE_REGEX ]]; then
+		echo "Malformed changelog $changelogFile line \"$line\"" >&2
+		changelogWellFormed=0
+	fi
 done < <(grep '^## ' $changelogFile)
 if [[ "$changelogWellFormed" == "1" ]]; then
-  echo "Congratulations!  Changelog $changelogFile is well-formed."
+	echo "Congratulations!  Changelog $changelogFile is well-formed."
-  exit 2
+	exit 2
diff --git a/hack/validate/dco b/hack/validate/dco
index f391001..9e1ed80 100755
--- a/hack/validate/dco
+++ b/hack/validate/dco
@@ -21,7 +21,7 @@
 	grep -qE "$dcoRegex"
-if [ $adds -eq 0 -a $dels -eq 0 ]; then
+if [ ${adds} -eq 0 -a ${dels} -eq 0 ]; then
 	echo '0 adds, 0 deletions; nothing to validate! :)'
 	commits=( $(validate_log --format='format:%H%n') )
diff --git a/hack/validate/default b/hack/validate/default
index 8ec9788..4ca7e91 100755
--- a/hack/validate/default
+++ b/hack/validate/default
@@ -4,14 +4,14 @@
 export SCRIPTDIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
-. $SCRIPTDIR/default-seccomp
-. $SCRIPTDIR/gometalinter
-. $SCRIPTDIR/pkg-imports
-. $SCRIPTDIR/swagger
-. $SCRIPTDIR/swagger-gen
-. $SCRIPTDIR/test-imports
-. $SCRIPTDIR/toml
-. $SCRIPTDIR/changelog-well-formed
-. $SCRIPTDIR/changelog-date-descending
-. $SCRIPTDIR/deprecate-integration-cli
+. ${SCRIPTDIR}/dco
+. ${SCRIPTDIR}/default-seccomp
+. ${SCRIPTDIR}/gometalinter
+. ${SCRIPTDIR}/pkg-imports
+. ${SCRIPTDIR}/swagger
+. ${SCRIPTDIR}/swagger-gen
+. ${SCRIPTDIR}/test-imports
+. ${SCRIPTDIR}/toml
+. ${SCRIPTDIR}/changelog-well-formed
+. ${SCRIPTDIR}/changelog-date-descending
+. ${SCRIPTDIR}/deprecate-integration-cli
diff --git a/hack/validate/deprecate-integration-cli b/hack/validate/deprecate-integration-cli
index da6f831..bc20bf9 100755
--- a/hack/validate/deprecate-integration-cli
+++ b/hack/validate/deprecate-integration-cli
@@ -5,13 +5,13 @@
 source "${SCRIPTDIR}/.validate"
-    validate_diff --diff-filter=ACMR --unified=0 -- 'integration-cli/*_cli_*.go' |
-    grep -E '^\+func (.*) Test' || true
+	validate_diff --diff-filter=ACMR --unified=0 -- 'integration-cli/*_cli_*.go' |
+	grep -E '^\+func (.*) Test' || true
 if [ -z "$new_tests" ]; then
 	echo 'Congratulations!  No new tests added to integration-cli.'
-    exit
+	exit
 echo "The following new tests were added to integration-cli:"
diff --git a/hack/validate/gometalinter b/hack/validate/gometalinter
index 8f42597..0c0ae0d 100755
--- a/hack/validate/gometalinter
+++ b/hack/validate/gometalinter
@@ -10,4 +10,4 @@
 gometalinter \
-	--config $SCRIPTDIR/gometalinter.json ./...
+	--config ${SCRIPTDIR}/gometalinter.json ./...
diff --git a/hack/validate/swagger b/hack/validate/swagger
index 0b3c271..58c032a 100755
--- a/hack/validate/swagger
+++ b/hack/validate/swagger
@@ -8,6 +8,6 @@
 unset IFS
 if [ ${#files[@]} -gt 0 ]; then
-  yamllint -c ${SCRIPTDIR}/.swagger-yamllint api/swagger.yaml
-  swagger validate api/swagger.yaml
+	LANG=C.UTF-8 yamllint -c ${SCRIPTDIR}/.swagger-yamllint api/swagger.yaml
+	swagger validate api/swagger.yaml
diff --git a/hack/validate/swagger-gen b/hack/validate/swagger-gen
index 07c22b5..744f627 100755
--- a/hack/validate/swagger-gen
+++ b/hack/validate/swagger-gen
@@ -25,5 +25,5 @@
 		echo 'Congratulations! All api changes are done the right way.'
-    echo 'No api/types/ or api/swagger.yaml changes in diff.'
+	echo 'No api/types/ or api/swagger.yaml changes in diff.'
diff --git a/internal/test/daemon/daemon.go b/internal/test/daemon/daemon.go
index 61fbdb4..b81da18 100644
--- a/internal/test/daemon/daemon.go
+++ b/internal/test/daemon/daemon.go
@@ -33,6 +33,13 @@
 	Fatalf(string, ...interface{})
+type namer interface {
+	Name() string
+type testNamer interface {
+	TestName() string
 type logT interface {
 	Logf(string, ...interface{})
@@ -91,6 +98,13 @@
 	if dest == "" {
 		dest = os.Getenv("DEST")
+	switch v := t.(type) {
+	case namer:
+		dest = filepath.Join(dest, v.Name())
+	case testNamer:
+		dest = filepath.Join(dest, v.TestName())
+	}
+	t.Logf("Creating a new daemon at: %s", dest)
 	assert.Check(t, dest != "", "Please set the DOCKER_INTEGRATION_DAEMON_DEST or the DEST environment variable")
 	storageDriver := os.Getenv("DOCKER_GRAPHDRIVER")
@@ -607,7 +621,9 @@
 		return nil, err
 	transport.DisableKeepAlives = true
+	if proto == "unix" {
+		addr = filepath.Base(addr)
+	}
 	return &clientConfig{
 		transport: transport,
 		scheme:    scheme,