0.17.0-rc.3

First release carrying the connection inversion: a monitoring instance asks the
platform for work, runs it against its own metric store, and posts the result
back. The platform opens no connection to the instance to collect.

- instance-jobs: the box-side agent (poll, claim, run, submit, sweep), shipped as
  a new postgresai/instance-jobs image. Behind the `instance-jobs` compose
  profile, which nothing enables automatically.
- pgai promql: run a PromQL query on an instance through the platform. Requires
  platform-all's v1.instance_query_enqueue / v1.instance_query_result, which are
  deployed as of api/1.2.51; the channel itself stays off until both
  app.settings.instance_jobs_enabled and app.settings.instance_queries_enabled
  are turned on.
- cli: issues list shows open issues by default and renders status as
  open/closed (#367).

Nothing changes for an existing instance on upgrade: the compose profile is off,
and an instance is only job-backed when the platform flag is on AND it is
actually polling.

Refs #366, #378