Modern software engineering is evolving from conventional source-code development toward an integrated discipline combining requirements engineering, architecture, automated testing, cloud-native development, cybersecurity, artificial intelligence, DevOps, observability, and continuous delivery.

The emergence of generative AI and Retrieval-Augmented Generation (RAG) introduces additional opportunities and challenges. AI can generate software, tests, documentation, architecture suggestions, and technical explanations at unprecedented speed. However, generated output must still satisfy explicit requirements, security constraints, quality objectives, and operational requirements.

This research paper proposes an integrated software-engineering framework centered on Behaviour-Driven Development (BDD), Cucumber, executable specifications, automated testing, AI/RAG evaluation, DevSecOps, CI/CD, and continuous observability.

Modern Software Engineering with Cucumber, BDD, AI/RAG-LLM, DevSecOps, and Modern Development Tools

A Research Framework for AI Software, RAG-LLM, Magento/Hyvä E-Commerce, Automotive Diagnostics, Embedded Systems, Industrial IoT, and Smart-Energy Systems

Prepared for:
IAS-Research.com | KeenComputer.com | KeenDirect.com

Research Focus:
Software Engineering • BDD • Cucumber • AI-Assisted Development • RAG-LLM • DevSecOps • Magento • Hyvä • E-Commerce • Automotive Diagnostics • Embedded Systems • Industrial IoT • Smart Inverters • Grid-Edge Energy

Date: September 2026

Abstract

Modern software engineering is evolving from conventional source-code development toward an integrated discipline combining requirements engineering, architecture, automated testing, cloud-native development, cybersecurity, artificial intelligence, DevOps, observability, and continuous delivery.

The emergence of generative AI and Retrieval-Augmented Generation (RAG) introduces additional opportunities and challenges. AI can generate software, tests, documentation, architecture suggestions, and technical explanations at unprecedented speed. However, generated output must still satisfy explicit requirements, security constraints, quality objectives, and operational requirements.

This research paper proposes an integrated software-engineering framework centered on Behaviour-Driven Development (BDD), Cucumber, executable specifications, automated testing, AI/RAG evaluation, DevSecOps, CI/CD, and continuous observability.

The paper also expands the software-engineering toolchain to include modern tools for:

  • Requirements management
  • Architecture and MBSE
  • UI/UX design
  • Source-code management
  • AI-assisted coding
  • BDD
  • Unit testing
  • API testing
  • Browser automation
  • Performance testing
  • Static analysis
  • Dependency management
  • Containerization
  • CI/CD
  • Infrastructure as Code
  • Kubernetes
  • Security
  • Observability
  • Monitoring
  • AI/RAG
  • Documentation
  • Collaboration

A major case study is added for KeenDirect Magento e-commerce using the Hyvä frontend and a custom Hyvä child theme.

Hyvä's current documentation describes the Hyvä frontend as a Magento/Adobe Commerce frontend built around Magento templates, Tailwind CSS, and Alpine.js. Hyvä's documentation recommends child themes for customization because they allow store-specific changes while keeping the parent theme and vendor code separate.

The paper demonstrates how a Hyvä child theme can be engineered using:

Figma → Requirements → Design System → Gherkin → Magento/Hyvä templates → Tailwind CSS → Alpine.js → Git → automated tests → CI/CD → security → production monitoring

The framework is also applied to:

  1. RAG-LLM software engineering
  2. OBD-AI automotive diagnostics
  3. KeenDirect Magento/Hyvä e-commerce
  4. Smart inverter and grid-edge systems
  5. Embedded and Industrial IoT software

The paper proposes a research-to-engineering-to-commercialization model involving IAS-Research, KeenComputer, and KeenDirect.

1. Introduction

Software engineering is no longer simply the process of writing programs.

Modern systems combine:

  • Web applications
  • APIs
  • Databases
  • Cloud platforms
  • Containers
  • AI models
  • RAG pipelines
  • Vector databases
  • Knowledge graphs
  • Embedded processors
  • IoT devices
  • Automotive networks
  • Payment systems
  • Cybersecurity
  • Power electronics
  • Industrial control

Consequently, software engineering must address the entire lifecycle.

A modern lifecycle can be represented as:

Discover → Specify → Design → Implement → Test → Secure → Deploy → Observe → Improve

This paper examines how modern tools can support this lifecycle.

2. Research Objectives

The objectives are to:

  1. Explain modern software engineering.
  2. Explain BDD and Cucumber.
  3. Explain Gherkin as executable requirements.
  4. Examine AI-assisted software development.
  5. Develop a RAG-LLM software-testing methodology.
  6. Integrate modern development tools.
  7. Develop a DevSecOps architecture.
  8. Integrate CI/CD and observability.
  9. Apply the framework to OBD-AI.
  10. Apply the framework to Magento and Hyvä.
  11. Develop a Hyvä child-theme engineering use case.
  12. Apply the framework to smart inverters.
  13. Apply the framework to embedded and Industrial IoT systems.
  14. Define an SME-oriented toolchain.
  15. Explain the roles of IAS-Research, KeenComputer, and KeenDirect.

3. Central Research Proposition

The central proposition is:

Modern software engineering should connect human requirements, executable behaviour, source code, automated verification, security, deployment, and operational feedback into one traceable lifecycle.

AI increases the speed at which software can be produced.

Therefore, verification becomes increasingly important.

The proposed model is:

Business Objective ↓ Requirements ↓ Examples ↓ BDD / Gherkin ↓ Architecture ↓ UI/UX Design ↓ Implementation ↓ Unit Testing ↓ Integration Testing ↓ AI/RAG Evaluation ↓ Security Testing ↓ CI/CD ↓ Deployment ↓ Observability ↓ Production Feedback ↓ New Requirements

4. Modern Software Engineering Toolchain

A modern engineering organization should not depend on one tool.

Different tools solve different engineering problems.

4.1 Requirements and Agile Management

Important tools include:

  • Jira
  • GitHub Issues
  • GitLab Issues
  • Linear
  • Azure DevOps
  • YouTrack
  • Jama Connect

These tools can manage:

  • Requirements
  • Epics
  • User stories
  • Tasks
  • Bugs
  • Acceptance criteria
  • Sprint planning
  • Product roadmaps

5. Architecture and Systems Engineering

For complex projects, software architecture should be explicitly modeled.

Tools and methodologies include:

  • Sparx Enterprise Architect
  • UML
  • SysML
  • MBSE
  • ArchiMate
  • C4 Model
  • Mermaid
  • PlantUML
  • Architecture Decision Records

Enterprise Architect can be particularly useful when software engineering must interact with:

  • Embedded systems
  • Hardware
  • Industrial systems
  • Power electronics
  • Automotive systems
  • Requirements traceability

6. UI/UX and Product Design

Modern software engineering should connect product design with implementation.

Important tools include:

  • Figma
  • FigJam
  • Adobe XD
  • Penpot
  • Storybook

A typical process is:

Customer Requirement ↓ User Journey ↓ Wireframe ↓ Figma Prototype ↓ Design System ↓ Frontend Components ↓ Implementation ↓ Automated UI Testing

For the KeenDirect Magento/Hyvä project, Figma can define:

  • Homepage
  • Category pages
  • Product cards
  • Product detail page
  • Shopping cart
  • Checkout
  • Account pages
  • Search
  • Navigation
  • Mobile layouts

7. Source-Code Management

Git remains the foundation of modern software development.

Common platforms include:

  • GitHub
  • GitLab
  • Bitbucket
  • Azure Repos

Git provides:

  • Version control
  • Branching
  • Merging
  • Pull requests
  • Code review
  • Release history
  • Change traceability

For an engineering project, source control should include more than application code.

It can also contain:

  • Tests
  • Gherkin scenarios
  • Infrastructure
  • Docker configurations
  • CI/CD workflows
  • Documentation
  • Architecture definitions
  • Configuration templates

8. Modern AI-Assisted Development Tools

AI-assisted development is becoming an important part of the software-engineering workflow.

Examples include:

  • GitHub Copilot
  • Claude Code
  • Cursor
  • JetBrains AI tools
  • OpenAI-based coding workflows
  • Continue
  • Aider
  • Amazon Q Developer

AI can assist with:

  • Code generation
  • Refactoring
  • Debugging
  • Documentation
  • Test generation
  • Code explanation
  • Migration
  • Repository analysis
  • Requirements transformation

However:

AI-generated code remains engineering output that requires verification.

9. BDD and Cucumber

Cucumber supports Behaviour-Driven Development through executable specifications written using Gherkin.

BDD focuses on collaboration, examples, shared understanding, and continuously checked specifications.

A simple example is:

Feature: Customer checkout Scenario: Customer purchases an available product Given the product is available And the customer has added it to the cart When the customer completes checkout Then the order should be created And inventory should be updated

The scenario can become part of an automated acceptance-testing system.

10. Gherkin as an Engineering Artifact

Gherkin should not be treated merely as a testing script.

It can serve as:

  • Acceptance criteria
  • Executable documentation
  • Collaboration artifact
  • Regression test
  • Requirements evidence
  • Customer-facing behaviour specification

The traceability relationship becomes:

Requirement ↓ Acceptance Criterion ↓ Gherkin Scenario ↓ Automated Test ↓ Build Evidence

11. Unit Testing

Unit testing validates individual software components.

Examples include:

Java

  • JUnit
  • Mockito

Python

  • pytest
  • unittest

JavaScript/TypeScript

  • Vitest
  • Jest

C/C++

  • GoogleTest
  • Catch2

Embedded

  • Unity
  • Ceedling
  • GoogleTest

Cucumber should not replace these frameworks.

12. Integration Testing

Integration testing verifies communication between components.

Examples include:

  • Application → Database
  • Magento → Payment
  • API → Backend
  • RAG application → Vector database
  • OBD-AI → CAN interface
  • Embedded controller → Sensor
  • Inverter controller → Grid interface

Tools can include:

  • pytest
  • JUnit
  • Testcontainers
  • REST Assured
  • Newman
  • Docker Compose

13. API Testing

Modern software is heavily API-driven.

Important tools include:

  • Postman
  • Newman
  • Insomnia
  • REST Assured
  • Bruno
  • Swagger/OpenAPI

An API pipeline can be:

OpenAPI Specification ↓ API Implementation ↓ API Unit Tests ↓ Postman / Newman ↓ Integration Testing ↓ CI/CD

14. Browser and End-to-End Testing

Modern web applications require browser testing.

Important tools include:

  • Playwright
  • Selenium
  • Cypress

Playwright is particularly useful for testing:

  • Chromium
  • Firefox
  • WebKit
  • Desktop browsers
  • Responsive workflows

For KeenDirect, browser tests can verify:

  • Product search
  • Product filtering
  • Add-to-cart
  • Checkout
  • Customer registration
  • Login
  • Payment workflow
  • Order confirmation

15. Performance Testing

Performance engineering is another important layer.

Tools include:

  • k6
  • Apache JMeter
  • Gatling
  • Locust

Performance testing can examine:

  • Response time
  • Throughput
  • Concurrent users
  • API performance
  • Database performance
  • Checkout performance

For Magento, testing should consider:

  • Catalog size
  • Search
  • Cart
  • Checkout
  • Customer login
  • Payment
  • Cache behaviour
  • Database load

16. Code Quality

Modern software teams can use:

  • SonarQube
  • SonarCloud
  • ESLint
  • PHPStan
  • Psalm
  • Ruff
  • Black
  • Pylint
  • Prettier
  • Checkstyle

These tools can detect:

  • Bugs
  • Code smells
  • Complexity
  • Security weaknesses
  • Formatting problems
  • Type problems
  • Maintainability issues

17. Software Composition Analysis

Modern applications depend heavily on third-party libraries.

Tools include:

  • Dependabot
  • Renovate
  • Snyk
  • Trivy
  • OWASP Dependency-Check

These tools help identify vulnerable or outdated dependencies.

For Magento, Composer dependencies are particularly important.

For JavaScript/Tailwind/Alpine projects, npm dependencies also require management.

18. Containerization

Docker has become an important development technology.

A containerized environment can package:

  • Application
  • Runtime
  • Libraries
  • Dependencies
  • Configuration

Example:

Developer ↓ Git ↓ Docker ↓ Application ↓ Test ↓ CI ↓ Production

Docker Compose is particularly useful for local development involving:

  • PHP
  • MySQL/MariaDB
  • Redis
  • OpenSearch
  • Nginx
  • Mail services
  • RAG services

19. Magento/Warden Development

For KeenDirect, Warden and Docker provide a useful local Magento development environment.

A conceptual stack is:

Kubuntu / Ubuntu ↓ Warden ↓ Docker Compose ↓ Magento ┌──────┼────────┐ ↓ ↓ ↓ PHP MySQL OpenSearch ↓ Redis / Varnish / Nginx

This environment can be integrated with:

  • Git
  • Composer
  • npm
  • Cucumber
  • Playwright
  • PHPUnit
  • Static analysis
  • CI/CD

20. Infrastructure as Code

Modern engineering increasingly treats infrastructure as code.

Important tools include:

  • Terraform
  • OpenTofu
  • Ansible
  • Pulumi
  • Packer

Infrastructure can therefore become version-controlled engineering artifacts.

Example:

Infrastructure Requirement ↓ Terraform / OpenTofu ↓ Cloud / VPS ↓ Docker / Kubernetes ↓ Application

21. Kubernetes and Cloud-Native Engineering

For larger systems, Kubernetes can provide container orchestration.

Important technologies include:

  • Kubernetes
  • Helm
  • Argo CD
  • Flux
  • Kustomize
  • Istio
  • Cilium

Not every SME requires Kubernetes.

For a smaller Magento deployment, Docker Compose/Warden may be more appropriate.

The engineering principle is:

Use the simplest infrastructure that satisfies the requirements.

22. CI/CD

Modern CI/CD tools include:

  • GitHub Actions
  • GitLab CI/CD
  • Jenkins
  • Azure Pipelines
  • CircleCI
  • Buildkite
  • Argo CD

A pipeline can be:

Git Commit ↓ Build ↓ Unit Tests ↓ Code Quality ↓ Dependency Scan ↓ Integration Tests ↓ RAG Evaluation ↓ Cucumber ↓ Browser Tests ↓ Security Tests ↓ Container Build ↓ Staging ↓ Production

23. DevSecOps

Security must be integrated into software engineering.

Important tools include:

SAST

  • Semgrep
  • SonarQube
  • CodeQL

DAST

  • OWASP ZAP
  • Burp Suite

Dependency Security

  • Dependabot
  • Renovate
  • Snyk
  • OWASP Dependency-Check

Container Security

  • Trivy
  • Grype

Infrastructure Security

  • Checkov
  • tfsec/OpenTofu-compatible scanning

Runtime Security

  • Wazuh
  • Falco
  • SIEM platforms

NIST's Secure Software Development Framework provides a structured set of secure-development practices that can be integrated into different SDLC models.

24. Observability

Modern software engineering must extend into production.

Three important observability areas are:

Logs

What happened?

Metrics

How much/how often?

Traces

Where did the request spend time?

Important technologies include:

  • OpenTelemetry
  • Prometheus
  • Grafana
  • Loki
  • Elasticsearch/OpenSearch
  • Jaeger
  • Tempo
  • Sentry

A modern architecture can therefore be:

Application │ ├── Logs ├── Metrics └── Traces ↓ Observability ↓ Analysis ↓ Engineering

25. Monitoring and Security Operations

For SME infrastructure, tools such as:

  • Nagios
  • Wazuh
  • Prometheus
  • Grafana

can provide complementary visibility.

Nagios can monitor infrastructure and services.

Wazuh can provide security monitoring and event analysis.

Together with application observability, they create a broader operational feedback system.

26. RAG-LLM Software Engineering

RAG systems introduce an additional engineering layer.

A typical architecture is:

Documents ↓ Parsing ↓ Chunking ↓ Embedding ↓ Vector Database ↓ Retriever ↓ LLM ↓ Grounded Answer ↓ Citation

Potential technologies include:

  • RAGFlow
  • Hugging Face
  • Ollama
  • OpenAI models
  • LlamaIndex
  • LangChain
  • LangGraph
  • Haystack
  • LightRAG
  • Neo4j
  • Qdrant
  • Milvus
  • Weaviate
  • PostgreSQL/pgvector

27. RAG Testing

RAG testing must examine more than software functionality.

Important dimensions include:

  • Retrieval relevance
  • Retrieval recall
  • Context precision
  • Grounding
  • Citation correctness
  • Hallucination
  • Latency
  • Access control
  • Prompt injection resistance
  • Data leakage

A useful model is:

Software Test + Retrieval Evaluation + Generation Evaluation + Security Testing + Human Review

28. Cucumber for RAG

Example:

Feature: Technical knowledge assistant Scenario: Answer a question from authorized documentation Given authorized technical documents are indexed And the user asks a question covered by those documents When the question is submitted Then relevant evidence should be retrieved And the answer should be based on that evidence And supporting sources should be identified

Another important scenario:

Scenario: Insufficient evidence Given the indexed documents do not contain sufficient evidence When the user asks the question Then the system should indicate that sufficient evidence was not found And should not present an unsupported answer as established fact

29. Hyvä as a Modern Software Engineering Use Case

29.1 Why Hyvä?

Hyvä is a modern Magento/Adobe Commerce frontend architecture based on Magento templates, Tailwind CSS, and Alpine.js. It replaces several parts of the traditional Luma frontend stack with a different frontend approach focused on reduced complexity and performance.

This makes Hyvä particularly useful as a software-engineering case study because it combines:

  • PHP
  • Magento
  • PHTML templates
  • XML layout
  • Tailwind CSS
  • Alpine.js
  • JavaScript
  • Composer
  • npm/Node.js
  • Git
  • CI/CD
  • UI/UX design
  • Browser testing

30. Hyvä Child Theme Architecture

Hyvä recommends using child themes to customize the storefront.

The child theme inherits templates, layouts, and styles from the parent while allowing specific components to be customized separately. Hyvä documents this as the recommended customization approach because it keeps store-specific modifications separated from vendor code and supports upgradeability.

Conceptually:

Hyvä Default Theme │ │ inheritance ▼ KeenDirect Hyvä Child Theme │ ├── Custom Header ├── Custom Footer ├── Product Cards ├── Category Pages ├── Product Pages ├── Navigation ├── Cart └── Branding

This is an excellent example of software engineering through controlled customization rather than vendor-code modification.

31. Hyvä Child Theme Engineering Workflow

A recommended workflow is:

Business Requirements ↓ Customer Personas ↓ User Journeys ↓ Figma Design ↓ Design System ↓ Gherkin Scenarios ↓ Hyvä Child Theme ↓ PHTML / Layout XML ↓ Tailwind CSS ↓ Alpine.js ↓ Automated Testing ↓ CI/CD ↓ Magento Staging ↓ Production

32. Hyvä Child Theme Directory

A typical Magento child theme is created under:

app/design/frontend/Vendor/ThemeName/

Hyvä documentation specifies that a child theme can set its parent to Hyva/default or the CSP-compatible parent where applicable.

A conceptual structure is:

app/design/frontend/KeenDirect/Custom/ ├── registration.php ├── theme.xml ├── composer.json │ ├── Magento_Catalog/ │ └── templates/ │ ├── Magento_Checkout/ │ └── templates/ │ └── web/ ├── tailwind/ │ ├── hyva.config.json │ ├── tailwind-source.css │ ├── base/ │ ├── components/ │ ├── theme/ │ └── utilities/ │ └── images/

The exact structure depends on the Magento and Hyvä versions being used.

33. Tailwind CSS in Hyvä

Hyvä uses Tailwind CSS for its frontend styling.

Tailwind generates CSS based on classes found in relevant source files.

This creates an important engineering requirement:

The Tailwind build must know where the relevant templates and classes are located.

Hyvä documentation explains that parent themes and other modules may need to be included as Tailwind sources. Current Hyvä documentation describes hyva-sources and hyva.config.json for this purpose.

34. Hyvä Child Theme and Tailwind Source Management

A simplified configuration concept is:

{ "tailwind": { "include": [ { "src": "vendor/hyva-themes/magento2-default-theme" } ] } }

This allows the child theme's Tailwind build to account for classes used in the parent theme. Hyvä's documentation specifically describes this approach for child themes.

This illustrates an important software-engineering principle:

Inheritance in application architecture does not automatically mean that every build system automatically discovers inherited resources.

The build process must be explicitly engineered.

35. Hyvä Design System

A KeenDirect child theme should ideally define a design system before extensive template customization.

The design system can define:

Brand

  • Logo
  • Typography
  • Colors
  • Icons

Layout

  • Containers
  • Grid
  • Spacing
  • Breakpoints

Components

  • Buttons
  • Cards
  • Forms
  • Alerts
  • Navigation
  • Product cards
  • Price displays

Commerce

  • Add-to-cart
  • Product options
  • Quantity selectors
  • Checkout
  • Shipping
  • Payment

A Figma design can become the visual source of truth while the Hyvä child theme becomes the implementation source.

36. Hyvä Component Development

A component workflow can be:

Figma Component ↓ Component Requirement ↓ Gherkin Behaviour ↓ PHTML Template ↓ Tailwind CSS ↓ Alpine.js Interaction ↓ Browser Test ↓ CI/CD

For example, a product card:

Product Card ├── Image ├── Product Name ├── Price ├── Availability ├── Rating └── Add to Cart

The visual appearance is defined by the design system.

The behaviour is defined by requirements and tests.

37. Hyvä Child Theme BDD Example

Feature: Product card Scenario: Customer adds an available product to cart Given the customer is viewing an available product When the customer selects "Add to Cart" Then the product should be added to the cart And the cart quantity should increase And the cart total should be updated

This can be implemented using:

  • Magento
  • PHTML
  • Alpine.js
  • Tailwind CSS

and verified with:

  • PHPUnit
  • Integration tests
  • Playwright
  • Cucumber

38. Hyvä UI Testing

A complete Hyvä testing strategy can include:

Layer

Testing

PHP

PHPUnit

Magento

Integration tests

JavaScript

JavaScript unit tests where appropriate

API

Postman/Newman

BDD

Cucumber

Browser

Playwright

Performance

k6

Security

OWASP ZAP

Code quality

PHPStan/SonarQube

Dependencies

Composer audit/Dependabot/Renovate

Production

OpenTelemetry/Sentry/Nagios/Wazuh

39. Hyvä and AI-Assisted Development

AI can assist with:

  • PHTML generation
  • Tailwind class suggestions
  • Alpine.js components
  • Magento layout XML
  • Test generation
  • Refactoring
  • Documentation
  • Code review

However, AI-generated Hyvä code should be validated against:

  • Magento architecture
  • Hyvä conventions
  • Tailwind build configuration
  • Alpine.js behaviour
  • Accessibility
  • Responsive design
  • Security
  • Browser compatibility
  • Upgradeability

A useful principle is:

Never allow AI to bypass the child-theme architecture or modify vendor code simply because it is faster.

40. Hyvä and Figma

The Figma → Hyvä workflow can be:

Figma │ ├── Design Tokens ├── Components ├── Responsive Layout └── User Flows ↓ Hyvä Child Theme │ ├── Tailwind ├── PHTML └── Alpine.js ↓ Playwright ↓ Cucumber ↓ CI/CD

Hyvä also provides a UI Library with ready-to-use components and a matching Figma file, according to its current documentation.

41. Hyvä CMS and Software Engineering

Magento content introduces another testing challenge.

Content editors can create:

  • CMS pages
  • CMS blocks
  • Product descriptions
  • Category descriptions

Hyvä documentation describes mechanisms for making Tailwind classes work with CMS-managed content, including a CMS Tailwind JIT module supporting Tailwind v3 and v4.

This creates an additional engineering requirement:

CMS-generated content must be included in the visual and functional testing strategy.

42. Hyvä Performance Engineering

A modern Magento frontend should be evaluated using:

  • Page-load performance
  • Core Web Vitals
  • JavaScript execution
  • CSS size
  • Image optimization
  • Cache effectiveness
  • API response time
  • Checkout performance

Performance testing can use:

  • Lighthouse
  • PageSpeed Insights
  • WebPageTest
  • Chrome DevTools
  • k6
  • RUM/observability tools

Performance should be tested continuously rather than only before launch.

43. Hyvä Security Engineering

Security testing should include:

  • Magento security patches
  • Composer dependencies
  • JavaScript dependencies
  • Authentication
  • Authorization
  • XSS
  • CSRF
  • Content Security Policy
  • API security
  • Payment security
  • Admin security

The Hyvä CSP-compatible theme option should be considered where appropriate to the Magento environment. Hyvä's documentation identifies CSP support requirements and theme variants.

44. Complete KeenDirect Hyvä DevOps Pipeline

A practical pipeline is:

Figma ↓ Requirements ↓ Gherkin ↓ Git ↓ Warden / Docker ↓ Magento + Hyvä ↓ PHPUnit ↓ PHPStan ↓ Composer Dependency Checks ↓ Tailwind Build ↓ Playwright ↓ Cucumber ↓ OWASP ZAP ↓ Container / Deployment Checks ↓ Staging ↓ Performance Testing ↓ Production ↓ OpenTelemetry / Monitoring

This transforms Hyvä theme development from "frontend customization" into a complete software-engineering process.

45. OBD-AI Use Case

OBD-AI demonstrates the same engineering methodology in automotive diagnostics.

Architecture:

Vehicle ↓ OBD-II / CAN ↓ Diagnostic Data ↓ OBD-AI ↓ RAG ↓ Service Manuals ↓ Vector / Knowledge Database ↓ LLM ↓ Diagnostic Explanation ↓ Technician

BDD can specify the technician's expected workflow.

46. OBD-AI Gherkin

Feature: Automotive diagnostic assistance Scenario: Diagnose a known trouble code Given the vehicle profile is available And the diagnostic trouble code has been captured And relevant service manuals are indexed When the technician requests diagnostic assistance Then relevant technical information should be retrieved And the response should provide supporting sources

Testing can include:

  • CAN parser unit tests
  • Integration tests
  • API tests
  • RAG evaluation
  • Cucumber
  • Security
  • Performance
  • Hardware integration

47. Smart Inverter Use Case

A smart inverter combines:

  • Power electronics
  • Embedded software
  • Control
  • Communication
  • Protection
  • Simulation
  • AI
  • Grid interaction

A system-level requirement could be:

The inverter shall detect an overvoltage condition and enter the specified protection state.

Gherkin:

Feature: Inverter protection Scenario: Detect overvoltage Given the inverter is operating normally When the measured voltage exceeds the protection threshold Then the inverter should enter the specified protection state And the event should be recorded And the monitoring system should receive an alert

Detailed electrical validation can be performed using simulation and HIL.

48. Embedded Systems

Embedded software requires additional tools:

  • STM32
  • FreeRTOS
  • Zephyr
  • Yocto
  • QEMU
  • SystemC/TLM
  • C/C++
  • CMake
  • Ninja
  • GoogleTest
  • Unity
  • Ceedling

A CI pipeline can compile firmware for multiple targets and run automated tests before hardware deployment.

49. Industrial IoT

Industrial IoT can combine:

Sensors ↓ Embedded Controller ↓ MQTT ↓ Edge Gateway ↓ Backend ↓ Database ↓ RAG / AI ↓ Dashboard ↓ Operator

Testing should cover:

  • Device communication
  • MQTT
  • API
  • Database
  • AI
  • Security
  • Monitoring

50. Requirements Traceability

Modern software engineering should maintain a traceability chain:

Business Objective ↓ Requirement ↓ User Story ↓ Figma / Design ↓ Gherkin ↓ Architecture ↓ Code ↓ Unit Test ↓ Integration Test ↓ Security Test ↓ CI/CD ↓ Deployment ↓ Monitoring

This is particularly valuable for complex engineering projects.

51. The Modern Software Engineering Stack

The entire tool ecosystem can be summarized as follows.

Layer

Modern tools

Strategy

Product roadmap, OKRs

Requirements

Jira, Linear, Jama

UX

Figma, Penpot

Architecture

Enterprise Architect, PlantUML, Mermaid

AI Coding

Copilot, Claude Code, Cursor, JetBrains AI

Source Control

GitHub, GitLab, Bitbucket

Backend

PHP, Python, Java, Node.js, Go

Frontend

React, Vue, TypeScript, Tailwind

Magento

Magento, Hyvä

BDD

Cucumber

Unit Tests

PHPUnit, pytest, JUnit, GoogleTest

API Tests

Postman, Bruno, REST Assured

Browser Tests

Playwright, Selenium, Cypress

Performance

k6, JMeter, Gatling

Code Quality

SonarQube, PHPStan, ESLint, Ruff

Dependencies

Dependabot, Renovate, Snyk

Containers

Docker, Podman

Orchestration

Kubernetes

IaC

Terraform, OpenTofu, Ansible

CI/CD

GitHub Actions, GitLab CI, Jenkins

Security

Semgrep, CodeQL, OWASP ZAP, Trivy

Observability

OpenTelemetry, Prometheus, Grafana

Error Monitoring

Sentry

Infrastructure Monitoring

Nagios

Security Monitoring

Wazuh

RAG

RAGFlow, LlamaIndex, LangChain, Haystack

AI Models

Hugging Face, Ollama, OpenAI and other LLM platforms

Vector DB

Qdrant, Milvus, Weaviate, pgvector

Graph DB

Neo4j

Documentation

Markdown, Docusaurus, Confluence

Collaboration

Slack, Teams, GitHub

Design System

Figma, Storybook

The list is intended as a representative modern toolchain, not a requirement to deploy every tool.

52. Avoiding Tool Proliferation

The existence of many tools creates another engineering problem.

An organization can easily end up with:

20+ tools ↓ 20+ configurations ↓ 20+ integrations ↓ High maintenance cost

The better model is:

Engineering Requirement ↓ Required Capability ↓ Smallest Suitable Tool ↓ Integration ↓ Automation

The objective should be engineering effectiveness, not maximum tool count.

53. Recommended SME Stack

For a small engineering organization, a practical baseline can be:

Core

  • Git
  • GitHub/GitLab
  • VS Code
  • Docker
  • Python/PHP
  • pytest/PHPUnit

Requirements

  • Jira or GitHub Issues

BDD

  • Cucumber

Web Testing

  • Playwright

API

  • Postman/Bruno

Quality

  • SonarQube
  • PHPStan
  • ESLint

Security

  • OWASP ZAP
  • Semgrep
  • Trivy
  • Dependabot/Renovate

CI/CD

  • GitHub Actions or GitLab CI

Monitoring

  • OpenTelemetry
  • Prometheus
  • Grafana
  • Nagios
  • Wazuh

AI

  • RAGFlow
  • Hugging Face
  • Ollama
  • Appropriate LLM platform

This provides a strong foundation without requiring a large enterprise platform.

54. Engineering Maturity Model

Level 1 — Manual Development

  • Manual testing
  • Limited documentation
  • No systematic CI

Level 2 — Version Control

  • Git
  • Code review
  • Automated builds

Level 3 — Automated Testing

  • Unit
  • Integration
  • API
  • BDD
  • Browser testing

Level 4 — DevSecOps

  • SAST
  • Dependency scanning
  • DAST
  • Container security

Level 5 — Continuous Delivery

  • CI/CD
  • Automated deployment
  • Infrastructure as Code

Level 6 — Observability

  • Logs
  • Metrics
  • Traces
  • Production feedback

Level 7 — AI-Assisted Engineering

  • AI coding
  • AI test generation
  • RAG
  • AI documentation
  • AI-assisted operations

Level 8 — Continuous Engineering

Customer ↓ Requirements ↓ Design ↓ Development ↓ Verification ↓ Deployment ↓ Operations ↓ Data ↓ AI / Analytics ↓ Engineering Improvement

55. Role of IAS-Research

IAS-Research can provide:

Research

  • AI/RAG
  • Embedded AI
  • Automotive diagnostics
  • Industrial IoT
  • Grid-edge energy
  • Smart inverter technology

Architecture

  • Software architecture
  • MBSE
  • UML/SysML
  • AI architecture
  • RAG architecture
  • Hardware/software co-design

Research engineering

  • Proof of concept
  • Feasibility studies
  • Simulation
  • Technology evaluation
  • Technical publications

IAS-Research therefore represents the research, architecture, and innovation layer.

56. Role of KeenComputer

KeenComputer can provide:

  • Software development
  • Web development
  • Magento
  • Hyvä
  • Joomla
  • WordPress
  • PHP
  • Python
  • APIs
  • Docker
  • Warden
  • DevOps
  • CI/CD
  • VPS deployment
  • Security
  • Monitoring
  • IT modernization

KeenComputer therefore represents the implementation, deployment, and operational engineering layer.

57. Role of KeenDirect

KeenDirect can provide:

  • E-commerce
  • Computer hardware
  • Components
  • Magento
  • Hyvä
  • Payment integration
  • Shipping
  • Inventory
  • Supply-chain management
  • AI-assisted product discovery
  • Customer-facing commerce

KeenDirect provides a real-world commercialization environment in which software engineering methodologies can be validated.

58. Research-to-Commercialization Model

The three organizations can be represented as:

IAS-RESEARCH │ │ Research / Architecture │ ▼ KEENCOMPUTER │ │ Software Engineering / DevOps │ ▼ KEENDIRECT │ │ Commercial Applications │ ▼ CUSTOMERS │ ▼ Operational Feedback │ └──────────────► IAS-RESEARCH

This creates a continuous innovation cycle.

59. Integrated Engineering Architecture

The complete framework can be summarized as:

BUSINESS │ ▼ REQUIREMENTS │ ▼ USER STORIES │ ▼ FIGMA / DESIGN │ ▼ GHERKIN │ ▼ ARCHITECTURE │ ┌────────────────┼─────────────────┐ │ │ │ ▼ ▼ ▼ WEB/E-COMMERCE AI/RAG EMBEDDED │ │ │ └────────────────┼─────────────────┘ ▼ DEVELOPMENT │ ▼ UNIT TESTING │ ▼ INTEGRATION TESTING │ ┌─────────────┼─────────────┐ │ │ │ ▼ ▼ ▼ API Cucumber Security │ │ │ └─────────────┼─────────────┘ ▼ CI/CD │ ▼ DEPLOYMENT │ ▼ OBSERVABILITY │ ▼ PRODUCTION FEEDBACK │ ▼ NEW REQUIREMENTS

60. Key Engineering Principles

Principle 1

Requirements should be understandable.

Principle 2

Requirements should be testable.

Principle 3

Gherkin should describe behaviour rather than implementation.

Principle 4

Cucumber should complement unit and integration testing.

Principle 5

AI-generated code requires independent verification.

Principle 6

RAG systems require AI-specific evaluation.

Principle 7

Security belongs throughout the SDLC.

Principle 8

Vendor code should not be modified when a supported extension mechanism exists.

This is especially relevant to Magento/Hyvä child-theme development.

Principle 9

Design systems should connect UI design with frontend implementation.

Principle 10

Production monitoring is part of software engineering.

Principle 11

Use the simplest toolchain that satisfies the engineering requirements.

61. Recommended KeenDirect Hyvä Engineering Project

A practical research and implementation project can be established as:

Project

AI-Assisted Magento/Hyvä Child Theme Engineering Using BDD, Cucumber, Figma, Tailwind CSS, Alpine.js, and DevSecOps

Objective

Develop a reusable engineering methodology for building and maintaining KeenDirect's Magento storefront.

Technology

  • Magento
  • Hyvä
  • PHP
  • PHTML
  • Tailwind CSS
  • Alpine.js
  • Figma
  • Git
  • Docker/Warden
  • PHPUnit
  • Cucumber
  • Playwright
  • PHPStan
  • SonarQube
  • OWASP ZAP
  • GitHub Actions
  • OpenTelemetry

Process

Figma ↓ Requirements ↓ Gherkin ↓ Hyvä Child Theme ↓ Tailwind / Alpine ↓ Unit Tests ↓ Playwright ↓ Cucumber ↓ Security ↓ CI/CD ↓ Staging ↓ Production

This can become a dedicated KeenDirect software-engineering reference architecture.

62. Future Research Opportunities

The framework supports several additional research papers.

Paper 1

Cucumber and BDD for AI/RAG-LLM Software Engineering

Paper 2

Cucumber-Based Testing Framework for OBD-AI Automotive Diagnostics

Paper 3

AI-Assisted Magento/Hyvä Child Theme Engineering

Paper 4

Figma-to-Hyvä Design-System Engineering for E-Commerce

Paper 5

DevSecOps for Magento and Hyvä

Paper 6

RAGFlow and RAG-LLM Quality Engineering

Paper 7

BDD and MBSE for Smart Inverter Systems

Paper 8

AI-Assisted Software Engineering for SMEs

Paper 9

Wazuh, Nagios, and RAG-LLM for Continuous IT Operations

Paper 10

Research-to-Commercialization Using IAS-Research, KeenComputer, and KeenDirect

63. Conclusion

Modern software engineering is becoming an integrated discipline involving:

Requirements + Design + Architecture + Coding + AI + Testing + Security + DevOps + Observability + Continuous Improvement

Cucumber and BDD provide an important bridge between requirements and executable software behaviour.

AI introduces another major opportunity.

AI can accelerate:

  • Coding
  • Testing
  • Documentation
  • Architecture analysis
  • Debugging
  • RAG development

But increased generation speed makes verification more important.

The proposed engineering framework therefore connects:

Human requirements

→ Figma/design

→ BDD/Gherkin

→ Architecture

→ AI-assisted implementation

→ Unit testing

→ Integration testing

→ RAG evaluation

→ Cucumber

→ Security

→ CI/CD

→ Deployment

→ Observability

→ Production feedback

The Hyvä child-theme use case demonstrates how this methodology can be applied to a real modern e-commerce frontend. Hyvä's architecture allows Magento developers to use familiar Magento concepts such as layout XML, blocks, view models, and PHTML while using Tailwind CSS and Alpine.js for the frontend.

Hyvä's child-theme model is particularly relevant to software engineering because store-specific changes can be isolated from the parent theme and vendor code, improving maintainability and upgrade management.

The KeenDirect use case further demonstrates that a frontend theme is not merely a visual artifact. It is a software component requiring:

  • Requirements
  • UX design
  • Architecture
  • Source control
  • Component design
  • CSS
  • JavaScript
  • Automated tests
  • Security
  • Performance
  • CI/CD
  • Monitoring

The same engineering principles apply to OBD-AI, RAGFlow-based systems, embedded systems, smart inverters, and Industrial IoT.

The resulting model is:

Research → Requirements → Design → Architecture → Implementation → Verification → Security → Deployment → Operations → Feedback → Research

IAS-Research can provide research, architecture, feasibility, and innovation.

KeenComputer can provide software engineering, DevOps, security, deployment, and operational implementation.

KeenDirect can provide the commercial e-commerce and hardware/software integration environment.

Together, these capabilities create a practical research-to-engineering-to-commercialization software lifecycle.

References

  1. Cucumber, Documentation, Cucumber.
    https://cucumber.io/docs/
  2. Cucumber, Behaviour-Driven Development, Cucumber.
    https://cucumber.io/docs/bdd/
  3. Cucumber, Gherkin Reference, Cucumber.
    https://cucumber.io/docs/gherkin/reference/
  4. NIST, Secure Software Development Framework (SSDF) Version 1.1, NIST SP 800-218.
    https://csrc.nist.gov/pubs/sp/800/218/final
  5. NIST, Secure Software Development Framework, National Institute of Standards and Technology.
    https://csrc.nist.gov/projects/ssdf
  6. OWASP, DevSecOps Guideline, OWASP Developer Guide.
    https://devguide.owasp.org/en/09-operations/01-devsecops/
  7. ISO/IEC, ISO/IEC 25010:2023 — Systems and Software Engineering — Product Quality Model, International Organization for Standardization.
    https://committee.iso.org/standard/78176.html
  8. Hyvä Themes, Hyvä Documentation — What is Hyvä? Hyvä Themes.
  9. Hyvä Themes, Building a Hyvä Child Theme, Hyvä Documentation.
  10. Hyvä Themes, Getting Started with Hyvä Theme, Hyvä Documentation.
  11. Hyvä Themes, Working with Tailwind CSS and Hyvä Sources, Hyvä Documentation.
  12. Hyvä Themes, Tailwind Content Settings, Hyvä Documentation.
  13. Hyvä Themes, Sharing Common CSS Between Themes, Hyvä Documentation.
  14. Hyvä Themes, CMS Tailwind JIT, Hyvä Documentation.
  15. Hyvä Themes, Hyvä Compatibility Modules, Hyvä Documentation.

Final Research Model

The central model proposed by this paper is:

HUMAN / BUSINESS NEED │ ▼ REQUIREMENTS │ ▼ USER JOURNEYS │ ▼ FIGMA / DESIGN │ ▼ BDD / GHERKIN │ ▼ ARCHITECTURE │ ┌─────────────────┼──────────────────┐ │ │ │ ▼ ▼ ▼ MAGENTO/HYVÄ RAG-LLM EMBEDDED │ │ │ ▼ ▼ ▼ Tailwind RAGFlow RTOS Alpine Vector DB Firmware PHP LLM Hardware │ │ │ └─────────────────┼──────────────────┘ ▼ IMPLEMENTATION │ ▼ UNIT TESTS │ ▼ INTEGRATION TESTS │ ▼ CUCUMBER / ACCEPTANCE │ ▼ SECURITY TESTING │ ▼ CI/CD │ ▼ DEPLOYMENT │ ▼ OBSERVABILITY / SOC │ ▼ PRODUCTION FEEDBACK │ ▼ NEW RESEARCH

This is the proposed IAS-Research software-engineering framework: from requirements and design through AI-assisted implementation, automated verification, secure deployment, and continuous engineering improvement.