Skip to content

Raspberry Pi 5 Headless Setup: First Boot and SSH Checklist

To set up a Raspberry Pi 5 without a monitor, configure a user, network, hostname, and SSH key in Raspberry Pi Imager before writing the card. For the first boot, Ethernet is the easiest way to separate a boot problem from a Wi-Fi problem. Connect the Pi 5 to a suitable USB-C power supply, wait for provisioning, then SSH to the hostname or the address shown by your router.

This Pi 5 checklist focuses on the first connection and the failures that are easy to confuse. For all models and longer-term remote-access choices, use the general headless setup guide.

Pi 5 first-boot checklist

Check What to do
Boot media Write and verify a current Raspberry Pi OS image with Imager. Start with microSD if you have not yet confirmed another boot device.
Power Prefer the official 27 W USB-C supply. The Pi 5 is specified for 5 V at 5 A; a 5 V at 3 A supply limits power available to USB peripherals.
Network Connect Ethernet before power-up for the first test, or configure Wi-Fi SSID, password, and country in Imager.
Account Create your own username and password in Imager. There is no universal pi / raspberry login.
Remote access Enable SSH in Imager and supply your public key. Keep the private key on your computer.
First connection Try ssh your-user@pi5-lab.local; if name lookup fails, use the router's DHCP address.

The official getting-started guide documents Imager customisation, the Pi 5 power recommendation, and headless first boot.

1. Prepare Imager before connecting power

Install Raspberry Pi Imager on another computer. Select Raspberry Pi 5, Raspberry Pi OS 64-bit (Lite for terminal-only use, Desktop if you need a graphical session), and the intended storage device. Check its name and capacity before writing; Imager will erase it.

In Imager's customisation screens:

  1. Set a unique hostname, for example pi5-lab.
  2. Create a username and strong password.
  3. Set locale, time zone, and keyboard layout.
  4. If using Wi-Fi, enter the exact SSID and password and select the correct Wi-Fi country.
  5. Enable SSH with public-key authentication. Paste the contents of your .pub file, never the private-key file.
  6. Write the image and allow Imager to verify it.

If you need a new key on a Linux or macOS client, run ssh-keygen -t ed25519 and show ~/.ssh/id_ed25519.pub. Windows OpenSSH users can do the same in PowerShell. Imager's official remote-access instructions describe the SSH setting.

2. Boot with a simple network path

Insert the verified microSD card, attach Ethernet to your router if available, and connect the Pi 5 power supply last. Leave USB drives and other high-draw peripherals disconnected for this first test. Initial setup can take longer than a normal reboot; the official first-boot guidance recommends checking the status LED if the Pi has not booted within five minutes.

Pi 5 status LEDs are integrated with the power button. A red light can indicate low-power standby, while green flashing indicates storage activity; a repeating flash pattern can indicate a boot fault. Read the model-specific LED and warning-code table before diagnosing a pattern by colour alone.

3. Find the Pi and connect

On another computer on the same LAN, try the hostname you set in Imager:

ssh your-user@pi5-lab.local

If .local fails, inspect your router's DHCP client list for pi5-lab, then connect to the assigned address:

ssh your-user@192.168.1.42

Replace the example address with the real lease. A working IP connection with a failing .local name points to mDNS discovery, not necessarily a Pi boot problem. Check your client's mDNS support and whether both devices are on the same LAN.

If SSH fails, identify the layer first

Symptom First check Next action
No DHCP lease and no storage activity Power, card seating, image verification, LED pattern Test the verified microSD image with Ethernet and minimal peripherals.
Lease exists, hostname fails Name resolution SSH to the numeric IP; fix mDNS separately.
Connection times out Address, LAN isolation, Wi-Fi credentials Confirm the client and Pi are on the same reachable network.
Connection refused SSH service setting Recheck that SSH was enabled in Imager.
Permission denied Imager username and public key Use the created username and the matching client private key.
Host key changed Device identity If you reimaged the Pi, verify the new fingerprint before removing an old known-hosts entry.

Use the interactive headless troubleshooter for a more detailed path. If you used Wi-Fi, repeat the first-boot test over Ethernet before changing several settings at once.

Verify the first login

After SSH works, check the board, OS, connection, and power history:

1
2
3
4
5
6
tr -d '\0' </proc/device-tree/model
cat /etc/os-release
nmcli device status
ip route
vcgencmd get_throttled
systemctl --failed

Update the OS through APT, then reconnect after reboot:

1
2
3
sudo apt update
sudo apt full-upgrade
sudo reboot

If a new Trixie installation requests your account password for sudo, use the password you created in Imager. SSH-key login and administrator authentication are separate. For Wi-Fi profiles and static addresses after first boot, follow the NetworkManager guide.

FAQ

Can I use Raspberry Pi OS Lite and connect with SSH?

Yes. Lite is appropriate when you only need a terminal. VNC requires a graphical desktop; add one deliberately if you need screen sharing.

Does the Pi 5 need 5 V at 5 A just to boot?

The Raspberry Pi hardware documentation says a good 5 V at 3 A supply can boot the Pi 5, but the available USB peripheral current is limited. The official 27 W supply is the recommended baseline for this checklist.

Should I put ssh or wpa_supplicant.conf on the boot partition?

For a new current Raspberry Pi OS image, use Imager customisation for the account, SSH, and network. It keeps the steps together and avoids mixing old boot-file recipes with the current OS.

Continue from here