Modern software engineering is evolving from conventional source-code development toward an integrated discipline combining requirements engineering, architecture, automated testing, cloud-native development, cybersecurity, artificial intelligence, DevOps, observability, and continuous delivery.
The emergence of generative AI and Retrieval-Augmented Generation (RAG) introduces additional opportunities and challenges. AI can generate software, tests, documentation, architecture suggestions, and technical explanations at unprecedented speed. However, generated output must still satisfy explicit requirements, security constraints, quality objectives, and operational requirements.
This research paper proposes an integrated software-engineering framework centered on Behaviour-Driven Development (BDD), Cucumber, executable specifications, automated testing, AI/RAG evaluation, DevSecOps, CI/CD, and continuous observability.
Modern Software Engineering with Cucumber, BDD, AI/RAG-LLM, DevSecOps, and Modern Development Tools
A Research Framework for AI Software, RAG-LLM, Magento/Hyvä E-Commerce, Automotive Diagnostics, Embedded Systems, Industrial IoT, and Smart-Energy Systems
Prepared for:
IAS-Research.com | KeenComputer.com | KeenDirect.com
Research Focus:
Software Engineering • BDD • Cucumber • AI-Assisted Development • RAG-LLM • DevSecOps • Magento • Hyvä • E-Commerce • Automotive Diagnostics • Embedded Systems • Industrial IoT • Smart Inverters • Grid-Edge Energy
Date: September 2026
Abstract
Modern software engineering is evolving from conventional source-code development toward an integrated discipline combining requirements engineering, architecture, automated testing, cloud-native development, cybersecurity, artificial intelligence, DevOps, observability, and continuous delivery.
The emergence of generative AI and Retrieval-Augmented Generation (RAG) introduces additional opportunities and challenges. AI can generate software, tests, documentation, architecture suggestions, and technical explanations at unprecedented speed. However, generated output must still satisfy explicit requirements, security constraints, quality objectives, and operational requirements.
This research paper proposes an integrated software-engineering framework centered on Behaviour-Driven Development (BDD), Cucumber, executable specifications, automated testing, AI/RAG evaluation, DevSecOps, CI/CD, and continuous observability.
The paper also expands the software-engineering toolchain to include modern tools for:
- Requirements management
- Architecture and MBSE
- UI/UX design
- Source-code management
- AI-assisted coding
- BDD
- Unit testing
- API testing
- Browser automation
- Performance testing
- Static analysis
- Dependency management
- Containerization
- CI/CD
- Infrastructure as Code
- Kubernetes
- Security
- Observability
- Monitoring
- AI/RAG
- Documentation
- Collaboration
A major case study is added for KeenDirect Magento e-commerce using the Hyvä frontend and a custom Hyvä child theme.
Hyvä's current documentation describes the Hyvä frontend as a Magento/Adobe Commerce frontend built around Magento templates, Tailwind CSS, and Alpine.js. Hyvä's documentation recommends child themes for customization because they allow store-specific changes while keeping the parent theme and vendor code separate.
The paper demonstrates how a Hyvä child theme can be engineered using:
Figma → Requirements → Design System → Gherkin → Magento/Hyvä templates → Tailwind CSS → Alpine.js → Git → automated tests → CI/CD → security → production monitoring
The framework is also applied to:
- RAG-LLM software engineering
- OBD-AI automotive diagnostics
- KeenDirect Magento/Hyvä e-commerce
- Smart inverter and grid-edge systems
- Embedded and Industrial IoT software
The paper proposes a research-to-engineering-to-commercialization model involving IAS-Research, KeenComputer, and KeenDirect.
1. Introduction
Software engineering is no longer simply the process of writing programs.
Modern systems combine:
- Web applications
- APIs
- Databases
- Cloud platforms
- Containers
- AI models
- RAG pipelines
- Vector databases
- Knowledge graphs
- Embedded processors
- IoT devices
- Automotive networks
- Payment systems
- Cybersecurity
- Power electronics
- Industrial control
Consequently, software engineering must address the entire lifecycle.
A modern lifecycle can be represented as:
Discover → Specify → Design → Implement → Test → Secure → Deploy → Observe → Improve
This paper examines how modern tools can support this lifecycle.
2. Research Objectives
The objectives are to:
- Explain modern software engineering.
- Explain BDD and Cucumber.
- Explain Gherkin as executable requirements.
- Examine AI-assisted software development.
- Develop a RAG-LLM software-testing methodology.
- Integrate modern development tools.
- Develop a DevSecOps architecture.
- Integrate CI/CD and observability.
- Apply the framework to OBD-AI.
- Apply the framework to Magento and Hyvä.
- Develop a Hyvä child-theme engineering use case.
- Apply the framework to smart inverters.
- Apply the framework to embedded and Industrial IoT systems.
- Define an SME-oriented toolchain.
- Explain the roles of IAS-Research, KeenComputer, and KeenDirect.
3. Central Research Proposition
The central proposition is:
Modern software engineering should connect human requirements, executable behaviour, source code, automated verification, security, deployment, and operational feedback into one traceable lifecycle.
AI increases the speed at which software can be produced.
Therefore, verification becomes increasingly important.
The proposed model is:
Business Objective ↓ Requirements ↓ Examples ↓ BDD / Gherkin ↓ Architecture ↓ UI/UX Design ↓ Implementation ↓ Unit Testing ↓ Integration Testing ↓ AI/RAG Evaluation ↓ Security Testing ↓ CI/CD ↓ Deployment ↓ Observability ↓ Production Feedback ↓ New Requirements
4. Modern Software Engineering Toolchain
A modern engineering organization should not depend on one tool.
Different tools solve different engineering problems.
4.1 Requirements and Agile Management
Important tools include:
- Jira
- GitHub Issues
- GitLab Issues
- Linear
- Azure DevOps
- YouTrack
- Jama Connect
These tools can manage:
- Requirements
- Epics
- User stories
- Tasks
- Bugs
- Acceptance criteria
- Sprint planning
- Product roadmaps
5. Architecture and Systems Engineering
For complex projects, software architecture should be explicitly modeled.
Tools and methodologies include:
- Sparx Enterprise Architect
- UML
- SysML
- MBSE
- ArchiMate
- C4 Model
- Mermaid
- PlantUML
- Architecture Decision Records
Enterprise Architect can be particularly useful when software engineering must interact with:
- Embedded systems
- Hardware
- Industrial systems
- Power electronics
- Automotive systems
- Requirements traceability
6. UI/UX and Product Design
Modern software engineering should connect product design with implementation.
Important tools include:
- Figma
- FigJam
- Adobe XD
- Penpot
- Storybook
A typical process is:
Customer Requirement ↓ User Journey ↓ Wireframe ↓ Figma Prototype ↓ Design System ↓ Frontend Components ↓ Implementation ↓ Automated UI Testing
For the KeenDirect Magento/Hyvä project, Figma can define:
- Homepage
- Category pages
- Product cards
- Product detail page
- Shopping cart
- Checkout
- Account pages
- Search
- Navigation
- Mobile layouts
7. Source-Code Management
Git remains the foundation of modern software development.
Common platforms include:
- GitHub
- GitLab
- Bitbucket
- Azure Repos
Git provides:
- Version control
- Branching
- Merging
- Pull requests
- Code review
- Release history
- Change traceability
For an engineering project, source control should include more than application code.
It can also contain:
- Tests
- Gherkin scenarios
- Infrastructure
- Docker configurations
- CI/CD workflows
- Documentation
- Architecture definitions
- Configuration templates
8. Modern AI-Assisted Development Tools
AI-assisted development is becoming an important part of the software-engineering workflow.
Examples include:
- GitHub Copilot
- Claude Code
- Cursor
- JetBrains AI tools
- OpenAI-based coding workflows
- Continue
- Aider
- Amazon Q Developer
AI can assist with:
- Code generation
- Refactoring
- Debugging
- Documentation
- Test generation
- Code explanation
- Migration
- Repository analysis
- Requirements transformation
However:
AI-generated code remains engineering output that requires verification.
9. BDD and Cucumber
Cucumber supports Behaviour-Driven Development through executable specifications written using Gherkin.
BDD focuses on collaboration, examples, shared understanding, and continuously checked specifications.
A simple example is:
Feature: Customer checkout Scenario: Customer purchases an available product Given the product is available And the customer has added it to the cart When the customer completes checkout Then the order should be created And inventory should be updated
The scenario can become part of an automated acceptance-testing system.
10. Gherkin as an Engineering Artifact
Gherkin should not be treated merely as a testing script.
It can serve as:
- Acceptance criteria
- Executable documentation
- Collaboration artifact
- Regression test
- Requirements evidence
- Customer-facing behaviour specification
The traceability relationship becomes:
Requirement ↓ Acceptance Criterion ↓ Gherkin Scenario ↓ Automated Test ↓ Build Evidence
11. Unit Testing
Unit testing validates individual software components.
Examples include:
Java
- JUnit
- Mockito
Python
- pytest
- unittest
JavaScript/TypeScript
- Vitest
- Jest
C/C++
- GoogleTest
- Catch2
Embedded
- Unity
- Ceedling
- GoogleTest
Cucumber should not replace these frameworks.
12. Integration Testing
Integration testing verifies communication between components.
Examples include:
- Application → Database
- Magento → Payment
- API → Backend
- RAG application → Vector database
- OBD-AI → CAN interface
- Embedded controller → Sensor
- Inverter controller → Grid interface
Tools can include:
- pytest
- JUnit
- Testcontainers
- REST Assured
- Newman
- Docker Compose
13. API Testing
Modern software is heavily API-driven.
Important tools include:
- Postman
- Newman
- Insomnia
- REST Assured
- Bruno
- Swagger/OpenAPI
An API pipeline can be:
OpenAPI Specification ↓ API Implementation ↓ API Unit Tests ↓ Postman / Newman ↓ Integration Testing ↓ CI/CD
14. Browser and End-to-End Testing
Modern web applications require browser testing.
Important tools include:
- Playwright
- Selenium
- Cypress
Playwright is particularly useful for testing:
- Chromium
- Firefox
- WebKit
- Desktop browsers
- Responsive workflows
For KeenDirect, browser tests can verify:
- Product search
- Product filtering
- Add-to-cart
- Checkout
- Customer registration
- Login
- Payment workflow
- Order confirmation
15. Performance Testing
Performance engineering is another important layer.
Tools include:
- k6
- Apache JMeter
- Gatling
- Locust
Performance testing can examine:
- Response time
- Throughput
- Concurrent users
- API performance
- Database performance
- Checkout performance
For Magento, testing should consider:
- Catalog size
- Search
- Cart
- Checkout
- Customer login
- Payment
- Cache behaviour
- Database load
16. Code Quality
Modern software teams can use:
- SonarQube
- SonarCloud
- ESLint
- PHPStan
- Psalm
- Ruff
- Black
- Pylint
- Prettier
- Checkstyle
These tools can detect:
- Bugs
- Code smells
- Complexity
- Security weaknesses
- Formatting problems
- Type problems
- Maintainability issues
17. Software Composition Analysis
Modern applications depend heavily on third-party libraries.
Tools include:
- Dependabot
- Renovate
- Snyk
- Trivy
- OWASP Dependency-Check
These tools help identify vulnerable or outdated dependencies.
For Magento, Composer dependencies are particularly important.
For JavaScript/Tailwind/Alpine projects, npm dependencies also require management.
18. Containerization
Docker has become an important development technology.
A containerized environment can package:
- Application
- Runtime
- Libraries
- Dependencies
- Configuration
Example:
Developer ↓ Git ↓ Docker ↓ Application ↓ Test ↓ CI ↓ Production
Docker Compose is particularly useful for local development involving:
- PHP
- MySQL/MariaDB
- Redis
- OpenSearch
- Nginx
- Mail services
- RAG services
19. Magento/Warden Development
For KeenDirect, Warden and Docker provide a useful local Magento development environment.
A conceptual stack is:
Kubuntu / Ubuntu ↓ Warden ↓ Docker Compose ↓ Magento ┌──────┼────────┐ ↓ ↓ ↓ PHP MySQL OpenSearch ↓ Redis / Varnish / Nginx
This environment can be integrated with:
- Git
- Composer
- npm
- Cucumber
- Playwright
- PHPUnit
- Static analysis
- CI/CD
20. Infrastructure as Code
Modern engineering increasingly treats infrastructure as code.
Important tools include:
- Terraform
- OpenTofu
- Ansible
- Pulumi
- Packer
Infrastructure can therefore become version-controlled engineering artifacts.
Example:
Infrastructure Requirement ↓ Terraform / OpenTofu ↓ Cloud / VPS ↓ Docker / Kubernetes ↓ Application
21. Kubernetes and Cloud-Native Engineering
For larger systems, Kubernetes can provide container orchestration.
Important technologies include:
- Kubernetes
- Helm
- Argo CD
- Flux
- Kustomize
- Istio
- Cilium
Not every SME requires Kubernetes.
For a smaller Magento deployment, Docker Compose/Warden may be more appropriate.
The engineering principle is:
Use the simplest infrastructure that satisfies the requirements.
22. CI/CD
Modern CI/CD tools include:
- GitHub Actions
- GitLab CI/CD
- Jenkins
- Azure Pipelines
- CircleCI
- Buildkite
- Argo CD
A pipeline can be:
Git Commit ↓ Build ↓ Unit Tests ↓ Code Quality ↓ Dependency Scan ↓ Integration Tests ↓ RAG Evaluation ↓ Cucumber ↓ Browser Tests ↓ Security Tests ↓ Container Build ↓ Staging ↓ Production
23. DevSecOps
Security must be integrated into software engineering.
Important tools include:
SAST
- Semgrep
- SonarQube
- CodeQL
DAST
- OWASP ZAP
- Burp Suite
Dependency Security
- Dependabot
- Renovate
- Snyk
- OWASP Dependency-Check
Container Security
- Trivy
- Grype
Infrastructure Security
- Checkov
- tfsec/OpenTofu-compatible scanning
Runtime Security
- Wazuh
- Falco
- SIEM platforms
NIST's Secure Software Development Framework provides a structured set of secure-development practices that can be integrated into different SDLC models.
24. Observability
Modern software engineering must extend into production.
Three important observability areas are:
Logs
What happened?
Metrics
How much/how often?
Traces
Where did the request spend time?
Important technologies include:
- OpenTelemetry
- Prometheus
- Grafana
- Loki
- Elasticsearch/OpenSearch
- Jaeger
- Tempo
- Sentry
A modern architecture can therefore be:
Application │ ├── Logs ├── Metrics └── Traces ↓ Observability ↓ Analysis ↓ Engineering
25. Monitoring and Security Operations
For SME infrastructure, tools such as:
- Nagios
- Wazuh
- Prometheus
- Grafana
can provide complementary visibility.
Nagios can monitor infrastructure and services.
Wazuh can provide security monitoring and event analysis.
Together with application observability, they create a broader operational feedback system.
26. RAG-LLM Software Engineering
RAG systems introduce an additional engineering layer.
A typical architecture is:
Documents ↓ Parsing ↓ Chunking ↓ Embedding ↓ Vector Database ↓ Retriever ↓ LLM ↓ Grounded Answer ↓ Citation
Potential technologies include:
- RAGFlow
- Hugging Face
- Ollama
- OpenAI models
- LlamaIndex
- LangChain
- LangGraph
- Haystack
- LightRAG
- Neo4j
- Qdrant
- Milvus
- Weaviate
- PostgreSQL/pgvector
27. RAG Testing
RAG testing must examine more than software functionality.
Important dimensions include:
- Retrieval relevance
- Retrieval recall
- Context precision
- Grounding
- Citation correctness
- Hallucination
- Latency
- Access control
- Prompt injection resistance
- Data leakage
A useful model is:
Software Test + Retrieval Evaluation + Generation Evaluation + Security Testing + Human Review
28. Cucumber for RAG
Example:
Feature: Technical knowledge assistant Scenario: Answer a question from authorized documentation Given authorized technical documents are indexed And the user asks a question covered by those documents When the question is submitted Then relevant evidence should be retrieved And the answer should be based on that evidence And supporting sources should be identified
Another important scenario:
Scenario: Insufficient evidence Given the indexed documents do not contain sufficient evidence When the user asks the question Then the system should indicate that sufficient evidence was not found And should not present an unsupported answer as established fact
29. Hyvä as a Modern Software Engineering Use Case
29.1 Why Hyvä?
Hyvä is a modern Magento/Adobe Commerce frontend architecture based on Magento templates, Tailwind CSS, and Alpine.js. It replaces several parts of the traditional Luma frontend stack with a different frontend approach focused on reduced complexity and performance.
This makes Hyvä particularly useful as a software-engineering case study because it combines:
- PHP
- Magento
- PHTML templates
- XML layout
- Tailwind CSS
- Alpine.js
- JavaScript
- Composer
- npm/Node.js
- Git
- CI/CD
- UI/UX design
- Browser testing
30. Hyvä Child Theme Architecture
Hyvä recommends using child themes to customize the storefront.
The child theme inherits templates, layouts, and styles from the parent while allowing specific components to be customized separately. Hyvä documents this as the recommended customization approach because it keeps store-specific modifications separated from vendor code and supports upgradeability.
Conceptually:
Hyvä Default Theme │ │ inheritance ▼ KeenDirect Hyvä Child Theme │ ├── Custom Header ├── Custom Footer ├── Product Cards ├── Category Pages ├── Product Pages ├── Navigation ├── Cart └── Branding
This is an excellent example of software engineering through controlled customization rather than vendor-code modification.
31. Hyvä Child Theme Engineering Workflow
A recommended workflow is:
Business Requirements ↓ Customer Personas ↓ User Journeys ↓ Figma Design ↓ Design System ↓ Gherkin Scenarios ↓ Hyvä Child Theme ↓ PHTML / Layout XML ↓ Tailwind CSS ↓ Alpine.js ↓ Automated Testing ↓ CI/CD ↓ Magento Staging ↓ Production
32. Hyvä Child Theme Directory
A typical Magento child theme is created under:
app/design/frontend/Vendor/ThemeName/
Hyvä documentation specifies that a child theme can set its parent to Hyva/default or the CSP-compatible parent where applicable.
A conceptual structure is:
app/design/frontend/KeenDirect/Custom/ ├── registration.php ├── theme.xml ├── composer.json │ ├── Magento_Catalog/ │ └── templates/ │ ├── Magento_Checkout/ │ └── templates/ │ └── web/ ├── tailwind/ │ ├── hyva.config.json │ ├── tailwind-source.css │ ├── base/ │ ├── components/ │ ├── theme/ │ └── utilities/ │ └── images/
The exact structure depends on the Magento and Hyvä versions being used.
33. Tailwind CSS in Hyvä
Hyvä uses Tailwind CSS for its frontend styling.
Tailwind generates CSS based on classes found in relevant source files.
This creates an important engineering requirement:
The Tailwind build must know where the relevant templates and classes are located.
Hyvä documentation explains that parent themes and other modules may need to be included as Tailwind sources. Current Hyvä documentation describes hyva-sources and hyva.config.json for this purpose.
34. Hyvä Child Theme and Tailwind Source Management
A simplified configuration concept is:
{ "tailwind": { "include": [ { "src": "vendor/hyva-themes/magento2-default-theme" } ] } }
This allows the child theme's Tailwind build to account for classes used in the parent theme. Hyvä's documentation specifically describes this approach for child themes.
This illustrates an important software-engineering principle:
Inheritance in application architecture does not automatically mean that every build system automatically discovers inherited resources.
The build process must be explicitly engineered.
35. Hyvä Design System
A KeenDirect child theme should ideally define a design system before extensive template customization.
The design system can define:
Brand
- Logo
- Typography
- Colors
- Icons
Layout
- Containers
- Grid
- Spacing
- Breakpoints
Components
- Buttons
- Cards
- Forms
- Alerts
- Navigation
- Product cards
- Price displays
Commerce
- Add-to-cart
- Product options
- Quantity selectors
- Checkout
- Shipping
- Payment
A Figma design can become the visual source of truth while the Hyvä child theme becomes the implementation source.
36. Hyvä Component Development
A component workflow can be:
Figma Component ↓ Component Requirement ↓ Gherkin Behaviour ↓ PHTML Template ↓ Tailwind CSS ↓ Alpine.js Interaction ↓ Browser Test ↓ CI/CD
For example, a product card:
Product Card ├── Image ├── Product Name ├── Price ├── Availability ├── Rating └── Add to Cart
The visual appearance is defined by the design system.
The behaviour is defined by requirements and tests.
37. Hyvä Child Theme BDD Example
Feature: Product card Scenario: Customer adds an available product to cart Given the customer is viewing an available product When the customer selects "Add to Cart" Then the product should be added to the cart And the cart quantity should increase And the cart total should be updated
This can be implemented using:
- Magento
- PHTML
- Alpine.js
- Tailwind CSS
and verified with:
- PHPUnit
- Integration tests
- Playwright
- Cucumber
38. Hyvä UI Testing
A complete Hyvä testing strategy can include:
|
Layer |
Testing |
|---|---|
|
PHP |
PHPUnit |
|
Magento |
Integration tests |
|
JavaScript |
JavaScript unit tests where appropriate |
|
API |
Postman/Newman |
|
BDD |
Cucumber |
|
Browser |
Playwright |
|
Performance |
k6 |
|
Security |
OWASP ZAP |
|
Code quality |
PHPStan/SonarQube |
|
Dependencies |
Composer audit/Dependabot/Renovate |
|
Production |
OpenTelemetry/Sentry/Nagios/Wazuh |
39. Hyvä and AI-Assisted Development
AI can assist with:
- PHTML generation
- Tailwind class suggestions
- Alpine.js components
- Magento layout XML
- Test generation
- Refactoring
- Documentation
- Code review
However, AI-generated Hyvä code should be validated against:
- Magento architecture
- Hyvä conventions
- Tailwind build configuration
- Alpine.js behaviour
- Accessibility
- Responsive design
- Security
- Browser compatibility
- Upgradeability
A useful principle is:
Never allow AI to bypass the child-theme architecture or modify vendor code simply because it is faster.
40. Hyvä and Figma
The Figma → Hyvä workflow can be:
Figma │ ├── Design Tokens ├── Components ├── Responsive Layout └── User Flows ↓ Hyvä Child Theme │ ├── Tailwind ├── PHTML └── Alpine.js ↓ Playwright ↓ Cucumber ↓ CI/CD
Hyvä also provides a UI Library with ready-to-use components and a matching Figma file, according to its current documentation.
41. Hyvä CMS and Software Engineering
Magento content introduces another testing challenge.
Content editors can create:
- CMS pages
- CMS blocks
- Product descriptions
- Category descriptions
Hyvä documentation describes mechanisms for making Tailwind classes work with CMS-managed content, including a CMS Tailwind JIT module supporting Tailwind v3 and v4.
This creates an additional engineering requirement:
CMS-generated content must be included in the visual and functional testing strategy.
42. Hyvä Performance Engineering
A modern Magento frontend should be evaluated using:
- Page-load performance
- Core Web Vitals
- JavaScript execution
- CSS size
- Image optimization
- Cache effectiveness
- API response time
- Checkout performance
Performance testing can use:
- Lighthouse
- PageSpeed Insights
- WebPageTest
- Chrome DevTools
- k6
- RUM/observability tools
Performance should be tested continuously rather than only before launch.
43. Hyvä Security Engineering
Security testing should include:
- Magento security patches
- Composer dependencies
- JavaScript dependencies
- Authentication
- Authorization
- XSS
- CSRF
- Content Security Policy
- API security
- Payment security
- Admin security
The Hyvä CSP-compatible theme option should be considered where appropriate to the Magento environment. Hyvä's documentation identifies CSP support requirements and theme variants.
44. Complete KeenDirect Hyvä DevOps Pipeline
A practical pipeline is:
Figma ↓ Requirements ↓ Gherkin ↓ Git ↓ Warden / Docker ↓ Magento + Hyvä ↓ PHPUnit ↓ PHPStan ↓ Composer Dependency Checks ↓ Tailwind Build ↓ Playwright ↓ Cucumber ↓ OWASP ZAP ↓ Container / Deployment Checks ↓ Staging ↓ Performance Testing ↓ Production ↓ OpenTelemetry / Monitoring
This transforms Hyvä theme development from "frontend customization" into a complete software-engineering process.
45. OBD-AI Use Case
OBD-AI demonstrates the same engineering methodology in automotive diagnostics.
Architecture:
Vehicle ↓ OBD-II / CAN ↓ Diagnostic Data ↓ OBD-AI ↓ RAG ↓ Service Manuals ↓ Vector / Knowledge Database ↓ LLM ↓ Diagnostic Explanation ↓ Technician
BDD can specify the technician's expected workflow.
46. OBD-AI Gherkin
Feature: Automotive diagnostic assistance Scenario: Diagnose a known trouble code Given the vehicle profile is available And the diagnostic trouble code has been captured And relevant service manuals are indexed When the technician requests diagnostic assistance Then relevant technical information should be retrieved And the response should provide supporting sources
Testing can include:
- CAN parser unit tests
- Integration tests
- API tests
- RAG evaluation
- Cucumber
- Security
- Performance
- Hardware integration
47. Smart Inverter Use Case
A smart inverter combines:
- Power electronics
- Embedded software
- Control
- Communication
- Protection
- Simulation
- AI
- Grid interaction
A system-level requirement could be:
The inverter shall detect an overvoltage condition and enter the specified protection state.
Gherkin:
Feature: Inverter protection Scenario: Detect overvoltage Given the inverter is operating normally When the measured voltage exceeds the protection threshold Then the inverter should enter the specified protection state And the event should be recorded And the monitoring system should receive an alert
Detailed electrical validation can be performed using simulation and HIL.
48. Embedded Systems
Embedded software requires additional tools:
- STM32
- FreeRTOS
- Zephyr
- Yocto
- QEMU
- SystemC/TLM
- C/C++
- CMake
- Ninja
- GoogleTest
- Unity
- Ceedling
A CI pipeline can compile firmware for multiple targets and run automated tests before hardware deployment.
49. Industrial IoT
Industrial IoT can combine:
Sensors ↓ Embedded Controller ↓ MQTT ↓ Edge Gateway ↓ Backend ↓ Database ↓ RAG / AI ↓ Dashboard ↓ Operator
Testing should cover:
- Device communication
- MQTT
- API
- Database
- AI
- Security
- Monitoring
50. Requirements Traceability
Modern software engineering should maintain a traceability chain:
Business Objective ↓ Requirement ↓ User Story ↓ Figma / Design ↓ Gherkin ↓ Architecture ↓ Code ↓ Unit Test ↓ Integration Test ↓ Security Test ↓ CI/CD ↓ Deployment ↓ Monitoring
This is particularly valuable for complex engineering projects.
51. The Modern Software Engineering Stack
The entire tool ecosystem can be summarized as follows.
|
Layer |
Modern tools |
|---|---|
|
Strategy |
Product roadmap, OKRs |
|
Requirements |
Jira, Linear, Jama |
|
UX |
Figma, Penpot |
|
Architecture |
Enterprise Architect, PlantUML, Mermaid |
|
AI Coding |
Copilot, Claude Code, Cursor, JetBrains AI |
|
Source Control |
GitHub, GitLab, Bitbucket |
|
Backend |
PHP, Python, Java, Node.js, Go |
|
Frontend |
React, Vue, TypeScript, Tailwind |
|
Magento |
Magento, Hyvä |
|
BDD |
Cucumber |
|
Unit Tests |
PHPUnit, pytest, JUnit, GoogleTest |
|
API Tests |
Postman, Bruno, REST Assured |
|
Browser Tests |
Playwright, Selenium, Cypress |
|
Performance |
k6, JMeter, Gatling |
|
Code Quality |
SonarQube, PHPStan, ESLint, Ruff |
|
Dependencies |
Dependabot, Renovate, Snyk |
|
Containers |
Docker, Podman |
|
Orchestration |
Kubernetes |
|
IaC |
Terraform, OpenTofu, Ansible |
|
CI/CD |
GitHub Actions, GitLab CI, Jenkins |
|
Security |
Semgrep, CodeQL, OWASP ZAP, Trivy |
|
Observability |
OpenTelemetry, Prometheus, Grafana |
|
Error Monitoring |
Sentry |
|
Infrastructure Monitoring |
Nagios |
|
Security Monitoring |
Wazuh |
|
RAG |
RAGFlow, LlamaIndex, LangChain, Haystack |
|
AI Models |
Hugging Face, Ollama, OpenAI and other LLM platforms |
|
Vector DB |
Qdrant, Milvus, Weaviate, pgvector |
|
Graph DB |
Neo4j |
|
Documentation |
Markdown, Docusaurus, Confluence |
|
Collaboration |
Slack, Teams, GitHub |
|
Design System |
Figma, Storybook |
The list is intended as a representative modern toolchain, not a requirement to deploy every tool.
52. Avoiding Tool Proliferation
The existence of many tools creates another engineering problem.
An organization can easily end up with:
20+ tools ↓ 20+ configurations ↓ 20+ integrations ↓ High maintenance cost
The better model is:
Engineering Requirement ↓ Required Capability ↓ Smallest Suitable Tool ↓ Integration ↓ Automation
The objective should be engineering effectiveness, not maximum tool count.
53. Recommended SME Stack
For a small engineering organization, a practical baseline can be:
Core
- Git
- GitHub/GitLab
- VS Code
- Docker
- Python/PHP
- pytest/PHPUnit
Requirements
- Jira or GitHub Issues
BDD
- Cucumber
Web Testing
- Playwright
API
- Postman/Bruno
Quality
- SonarQube
- PHPStan
- ESLint
Security
- OWASP ZAP
- Semgrep
- Trivy
- Dependabot/Renovate
CI/CD
- GitHub Actions or GitLab CI
Monitoring
- OpenTelemetry
- Prometheus
- Grafana
- Nagios
- Wazuh
AI
- RAGFlow
- Hugging Face
- Ollama
- Appropriate LLM platform
This provides a strong foundation without requiring a large enterprise platform.
54. Engineering Maturity Model
Level 1 — Manual Development
- Manual testing
- Limited documentation
- No systematic CI
Level 2 — Version Control
- Git
- Code review
- Automated builds
Level 3 — Automated Testing
- Unit
- Integration
- API
- BDD
- Browser testing
Level 4 — DevSecOps
- SAST
- Dependency scanning
- DAST
- Container security
Level 5 — Continuous Delivery
- CI/CD
- Automated deployment
- Infrastructure as Code
Level 6 — Observability
- Logs
- Metrics
- Traces
- Production feedback
Level 7 — AI-Assisted Engineering
- AI coding
- AI test generation
- RAG
- AI documentation
- AI-assisted operations
Level 8 — Continuous Engineering
Customer ↓ Requirements ↓ Design ↓ Development ↓ Verification ↓ Deployment ↓ Operations ↓ Data ↓ AI / Analytics ↓ Engineering Improvement
55. Role of IAS-Research
IAS-Research can provide:
Research
- AI/RAG
- Embedded AI
- Automotive diagnostics
- Industrial IoT
- Grid-edge energy
- Smart inverter technology
Architecture
- Software architecture
- MBSE
- UML/SysML
- AI architecture
- RAG architecture
- Hardware/software co-design
Research engineering
- Proof of concept
- Feasibility studies
- Simulation
- Technology evaluation
- Technical publications
IAS-Research therefore represents the research, architecture, and innovation layer.
56. Role of KeenComputer
KeenComputer can provide:
- Software development
- Web development
- Magento
- Hyvä
- Joomla
- WordPress
- PHP
- Python
- APIs
- Docker
- Warden
- DevOps
- CI/CD
- VPS deployment
- Security
- Monitoring
- IT modernization
KeenComputer therefore represents the implementation, deployment, and operational engineering layer.
57. Role of KeenDirect
KeenDirect can provide:
- E-commerce
- Computer hardware
- Components
- Magento
- Hyvä
- Payment integration
- Shipping
- Inventory
- Supply-chain management
- AI-assisted product discovery
- Customer-facing commerce
KeenDirect provides a real-world commercialization environment in which software engineering methodologies can be validated.
58. Research-to-Commercialization Model
The three organizations can be represented as:
IAS-RESEARCH │ │ Research / Architecture │ ▼ KEENCOMPUTER │ │ Software Engineering / DevOps │ ▼ KEENDIRECT │ │ Commercial Applications │ ▼ CUSTOMERS │ ▼ Operational Feedback │ └──────────────► IAS-RESEARCH
This creates a continuous innovation cycle.
59. Integrated Engineering Architecture
The complete framework can be summarized as:
BUSINESS │ ▼ REQUIREMENTS │ ▼ USER STORIES │ ▼ FIGMA / DESIGN │ ▼ GHERKIN │ ▼ ARCHITECTURE │ ┌────────────────┼─────────────────┐ │ │ │ ▼ ▼ ▼ WEB/E-COMMERCE AI/RAG EMBEDDED │ │ │ └────────────────┼─────────────────┘ ▼ DEVELOPMENT │ ▼ UNIT TESTING │ ▼ INTEGRATION TESTING │ ┌─────────────┼─────────────┐ │ │ │ ▼ ▼ ▼ API Cucumber Security │ │ │ └─────────────┼─────────────┘ ▼ CI/CD │ ▼ DEPLOYMENT │ ▼ OBSERVABILITY │ ▼ PRODUCTION FEEDBACK │ ▼ NEW REQUIREMENTS
60. Key Engineering Principles
Principle 1
Requirements should be understandable.
Principle 2
Requirements should be testable.
Principle 3
Gherkin should describe behaviour rather than implementation.
Principle 4
Cucumber should complement unit and integration testing.
Principle 5
AI-generated code requires independent verification.
Principle 6
RAG systems require AI-specific evaluation.
Principle 7
Security belongs throughout the SDLC.
Principle 8
Vendor code should not be modified when a supported extension mechanism exists.
This is especially relevant to Magento/Hyvä child-theme development.
Principle 9
Design systems should connect UI design with frontend implementation.
Principle 10
Production monitoring is part of software engineering.
Principle 11
Use the simplest toolchain that satisfies the engineering requirements.
61. Recommended KeenDirect Hyvä Engineering Project
A practical research and implementation project can be established as:
Project
AI-Assisted Magento/Hyvä Child Theme Engineering Using BDD, Cucumber, Figma, Tailwind CSS, Alpine.js, and DevSecOps
Objective
Develop a reusable engineering methodology for building and maintaining KeenDirect's Magento storefront.
Technology
- Magento
- Hyvä
- PHP
- PHTML
- Tailwind CSS
- Alpine.js
- Figma
- Git
- Docker/Warden
- PHPUnit
- Cucumber
- Playwright
- PHPStan
- SonarQube
- OWASP ZAP
- GitHub Actions
- OpenTelemetry
Process
Figma ↓ Requirements ↓ Gherkin ↓ Hyvä Child Theme ↓ Tailwind / Alpine ↓ Unit Tests ↓ Playwright ↓ Cucumber ↓ Security ↓ CI/CD ↓ Staging ↓ Production
This can become a dedicated KeenDirect software-engineering reference architecture.
62. Future Research Opportunities
The framework supports several additional research papers.
Paper 1
Cucumber and BDD for AI/RAG-LLM Software Engineering
Paper 2
Cucumber-Based Testing Framework for OBD-AI Automotive Diagnostics
Paper 3
AI-Assisted Magento/Hyvä Child Theme Engineering
Paper 4
Figma-to-Hyvä Design-System Engineering for E-Commerce
Paper 5
DevSecOps for Magento and Hyvä
Paper 6
RAGFlow and RAG-LLM Quality Engineering
Paper 7
BDD and MBSE for Smart Inverter Systems
Paper 8
AI-Assisted Software Engineering for SMEs
Paper 9
Wazuh, Nagios, and RAG-LLM for Continuous IT Operations
Paper 10
Research-to-Commercialization Using IAS-Research, KeenComputer, and KeenDirect
63. Conclusion
Modern software engineering is becoming an integrated discipline involving:
Requirements + Design + Architecture + Coding + AI + Testing + Security + DevOps + Observability + Continuous Improvement
Cucumber and BDD provide an important bridge between requirements and executable software behaviour.
AI introduces another major opportunity.
AI can accelerate:
- Coding
- Testing
- Documentation
- Architecture analysis
- Debugging
- RAG development
But increased generation speed makes verification more important.
The proposed engineering framework therefore connects:
Human requirements
→ Figma/design
→ BDD/Gherkin
→ Architecture
→ AI-assisted implementation
→ Unit testing
→ Integration testing
→ RAG evaluation
→ Cucumber
→ Security
→ CI/CD
→ Deployment
→ Observability
→ Production feedback
The Hyvä child-theme use case demonstrates how this methodology can be applied to a real modern e-commerce frontend. Hyvä's architecture allows Magento developers to use familiar Magento concepts such as layout XML, blocks, view models, and PHTML while using Tailwind CSS and Alpine.js for the frontend.
Hyvä's child-theme model is particularly relevant to software engineering because store-specific changes can be isolated from the parent theme and vendor code, improving maintainability and upgrade management.
The KeenDirect use case further demonstrates that a frontend theme is not merely a visual artifact. It is a software component requiring:
- Requirements
- UX design
- Architecture
- Source control
- Component design
- CSS
- JavaScript
- Automated tests
- Security
- Performance
- CI/CD
- Monitoring
The same engineering principles apply to OBD-AI, RAGFlow-based systems, embedded systems, smart inverters, and Industrial IoT.
The resulting model is:
Research → Requirements → Design → Architecture → Implementation → Verification → Security → Deployment → Operations → Feedback → Research
IAS-Research can provide research, architecture, feasibility, and innovation.
KeenComputer can provide software engineering, DevOps, security, deployment, and operational implementation.
KeenDirect can provide the commercial e-commerce and hardware/software integration environment.
Together, these capabilities create a practical research-to-engineering-to-commercialization software lifecycle.
References
- Cucumber, Documentation, Cucumber.
https://cucumber.io/docs/ - Cucumber, Behaviour-Driven Development, Cucumber.
https://cucumber.io/docs/bdd/ - Cucumber, Gherkin Reference, Cucumber.
https://cucumber.io/docs/gherkin/reference/ - NIST, Secure Software Development Framework (SSDF) Version 1.1, NIST SP 800-218.
https://csrc.nist.gov/pubs/sp/800/218/final - NIST, Secure Software Development Framework, National Institute of Standards and Technology.
https://csrc.nist.gov/projects/ssdf - OWASP, DevSecOps Guideline, OWASP Developer Guide.
https://devguide.owasp.org/en/09-operations/01-devsecops/ - ISO/IEC, ISO/IEC 25010:2023 — Systems and Software Engineering — Product Quality Model, International Organization for Standardization.
https://committee.iso.org/standard/78176.html - Hyvä Themes, Hyvä Documentation — What is Hyvä? Hyvä Themes.
- Hyvä Themes, Building a Hyvä Child Theme, Hyvä Documentation.
- Hyvä Themes, Getting Started with Hyvä Theme, Hyvä Documentation.
- Hyvä Themes, Working with Tailwind CSS and Hyvä Sources, Hyvä Documentation.
- Hyvä Themes, Tailwind Content Settings, Hyvä Documentation.
- Hyvä Themes, Sharing Common CSS Between Themes, Hyvä Documentation.
- Hyvä Themes, CMS Tailwind JIT, Hyvä Documentation.
- Hyvä Themes, Hyvä Compatibility Modules, Hyvä Documentation.
Final Research Model
The central model proposed by this paper is:
HUMAN / BUSINESS NEED │ ▼ REQUIREMENTS │ ▼ USER JOURNEYS │ ▼ FIGMA / DESIGN │ ▼ BDD / GHERKIN │ ▼ ARCHITECTURE │ ┌─────────────────┼──────────────────┐ │ │ │ ▼ ▼ ▼ MAGENTO/HYVÄ RAG-LLM EMBEDDED │ │ │ ▼ ▼ ▼ Tailwind RAGFlow RTOS Alpine Vector DB Firmware PHP LLM Hardware │ │ │ └─────────────────┼──────────────────┘ ▼ IMPLEMENTATION │ ▼ UNIT TESTS │ ▼ INTEGRATION TESTS │ ▼ CUCUMBER / ACCEPTANCE │ ▼ SECURITY TESTING │ ▼ CI/CD │ ▼ DEPLOYMENT │ ▼ OBSERVABILITY / SOC │ ▼ PRODUCTION FEEDBACK │ ▼ NEW RESEARCH
This is the proposed IAS-Research software-engineering framework: from requirements and design through AI-assisted implementation, automated verification, secure deployment, and continuous engineering improvement.