Ledge is a Markdown editor where code blocks are executable. You write a note, drop in a fenced shell block, hit ⌘↩, and the output streams in beneath it. Each note gets its own persistent shell — cd somewhere, export a variable, activate a virtualenv, and it carries into the next run. This is the core mechanic: your notes aren't documentation about work, they're the work itself. The remote execution model is the sharpest design choice here. Point Ledge at a server over SSH and the notes live there. Shells run there. Close the laptop and they keep going. Your phone, your desktop, and a second window can all attach to one server simultaneously, each with its own tabs. The phone app (iOS and Android beta) is a thin client onto the same server — no local note storage, just a window. This is closer to how ops teams actually work than any notebook product has managed: the runbook lives where the infrastructure lives. Secrets management is handled through profiles — named dotenv files stored outside your notes folder. A note carries only the profile name in its frontmatter, never the credentials. Notes get synced, backed up, read by agents; profile values stay on the machine. It's a clean separation that solves one of the persistent headaches of executable notebooks without inventing a new credential store. The MCP server integration is well-considered. Claude Code or any MCP agent can read, search, create, and edit notes. Notes are addressed by title (which survives renames), a prompt block is runnable with ⌘↩, and agents can read the manual. The guard rails matter: there's no delete tool, and locked notes refuse their bodies to every agent. Locking encrypts the note body on disk behind a passphrase — title and tags stay visible for navigation, but search and backlinks skip locked bodies. Sync is deliberately dumb: notes are plain files in ordinary folders. iCloud, Dropbox, git, Syncthing — whatever you already use. No sidecar database. Push a workspace to a git remote and collaborators clone it. Conflicts are git conflicts. This is a philosophical stance: Ledge refuses to own your data layer, which means it also refuses to solve distributed state for you. That's a trade-off, not a flaw. The multi-host execution model rounds out the picture. Add a host: line to frontmatter and every run in that note happens over SSH on that host. Declare several hosts and Ledge asks which one. Mark a block confirm and it shows the code, names the machine, and asks before running. Your cwd and env travel with the run; profiles and secrets never do. This is the difference between a notebook and a control plane — Ledge is trying to be the latter without the weight of the former. What's missing is what you'd expect from a v1 open-source tool: no collaborative editing, no audit trail beyond git history, no built-in scheduling or cron-like triggers. The Android app is beta. The curl-pipe-sh install pattern will make security teams twitch. But the core proposition — your notes are your terminal, your terminal is your notes, and both live where your servers live — is sound and genuinely useful for the developer who currently maintains this workflow across four different tools.