`hack/tf-fmt.sh` doesn't work with selinux in enforcing Also, perhaps we should detect if the `terraform` command is on the path and only use the container if `terraform` is not present.