01
HTTP/3-first ingress
Spooky terminates QUIC and TLS 1.3 at the edge while still supporting bootstrap HTTP/1.1 and HTTP/2 paths for clients that have not moved yet.
Learn more →02
Deterministic routing
Host, path-prefix, and method matching resolve through a clear route model so request placement remains explainable during deployments and incidents.
Learn more →03
Per-upstream traffic control
Each upstream can choose balancing and execution behavior that fits its own shape rather than inheriting one blunt global policy.
Learn more →04
Layered resilience
Brownout, adaptive admission, inflight controls, retries, hedging, and circuit behavior work together so pressure stays local instead of cascading.
Learn more →05
Quota and policy separation
Contract-driven quota decisions remain distinct from overload protection, so policy failures are not confused with system-preservation behavior.
Learn more →06
Runtime activation and rollback
Validation, preview, activation, rollback, and runtime history move operational changes away from ad hoc reload habits toward a safer control-plane workflow.
Learn more →07
TLS and listener operations
Live certificate reload, SNI-based selection, and listener policy controls make transport operations part of the runtime instead of external glue.
Learn more →08
Operator-grade observability
Prometheus metrics, structured logs, OTLP tracing, audit events, dashboards, alerts, and SLO definitions ship as one operational package.
Learn more →09
Existing backends stay in place
Spooky forwards to HTTP/1.1 and HTTP/2 services so teams can improve ingress and operator control without turning the backend estate into a prerequisite migration project.
Learn more →