Raspberry Pi 5 Headless Setup: First Boot and SSH Checklist¶
To set up a Raspberry Pi 5 without a monitor, configure a user, network, hostname, and SSH key in Raspberry Pi Imager before writing the card. For the first boot, Ethernet is the easiest way to separate a boot problem from a Wi-Fi problem. Connect the Pi 5 to a suitable USB-C power supply, wait for provisioning, then SSH to the hostname or the address shown by your router.
This Pi 5 checklist focuses on the first connection and the failures that are easy to confuse. For all models and longer-term remote-access choices, use the general headless setup guide.
Pi 5 first-boot checklist¶
| Check | What to do |
|---|---|
| Boot media | Write and verify a current Raspberry Pi OS image with Imager. Start with microSD if you have not yet confirmed another boot device. |
| Power | Prefer the official 27 W USB-C supply. The Pi 5 is specified for 5 V at 5 A; a 5 V at 3 A supply limits power available to USB peripherals. |
| Network | Connect Ethernet before power-up for the first test, or configure Wi-Fi SSID, password, and country in Imager. |
| Account | Create your own username and password in Imager. There is no universal pi / raspberry login. |
| Remote access | Enable SSH in Imager and supply your public key. Keep the private key on your computer. |
| First connection | Try ssh your-user@pi5-lab.local; if name lookup fails, use the router's DHCP address. |
The official getting-started guide documents Imager customisation, the Pi 5 power recommendation, and headless first boot.
1. Prepare Imager before connecting power¶
Install Raspberry Pi Imager on another computer. Select Raspberry Pi 5, Raspberry Pi OS 64-bit (Lite for terminal-only use, Desktop if you need a graphical session), and the intended storage device. Check its name and capacity before writing; Imager will erase it.
In Imager's customisation screens:
- Set a unique hostname, for example
pi5-lab. - Create a username and strong password.
- Set locale, time zone, and keyboard layout.
- If using Wi-Fi, enter the exact SSID and password and select the correct Wi-Fi country.
- Enable SSH with public-key authentication. Paste the contents of your
.pubfile, never the private-key file. - Write the image and allow Imager to verify it.
If you need a new key on a Linux or macOS client, run ssh-keygen -t ed25519 and show ~/.ssh/id_ed25519.pub. Windows OpenSSH users can do the same in PowerShell. Imager's official remote-access instructions describe the SSH setting.
2. Boot with a simple network path¶
Insert the verified microSD card, attach Ethernet to your router if available, and connect the Pi 5 power supply last. Leave USB drives and other high-draw peripherals disconnected for this first test. Initial setup can take longer than a normal reboot; the official first-boot guidance recommends checking the status LED if the Pi has not booted within five minutes.
Pi 5 status LEDs are integrated with the power button. A red light can indicate low-power standby, while green flashing indicates storage activity; a repeating flash pattern can indicate a boot fault. Read the model-specific LED and warning-code table before diagnosing a pattern by colour alone.
3. Find the Pi and connect¶
On another computer on the same LAN, try the hostname you set in Imager:
If .local fails, inspect your router's DHCP client list for pi5-lab, then connect to the assigned address:
Replace the example address with the real lease. A working IP connection with a failing .local name points to mDNS discovery, not necessarily a Pi boot problem. Check your client's mDNS support and whether both devices are on the same LAN.
If SSH fails, identify the layer first¶
| Symptom | First check | Next action |
|---|---|---|
| No DHCP lease and no storage activity | Power, card seating, image verification, LED pattern | Test the verified microSD image with Ethernet and minimal peripherals. |
| Lease exists, hostname fails | Name resolution | SSH to the numeric IP; fix mDNS separately. |
| Connection times out | Address, LAN isolation, Wi-Fi credentials | Confirm the client and Pi are on the same reachable network. |
| Connection refused | SSH service setting | Recheck that SSH was enabled in Imager. |
| Permission denied | Imager username and public key | Use the created username and the matching client private key. |
| Host key changed | Device identity | If you reimaged the Pi, verify the new fingerprint before removing an old known-hosts entry. |
Use the interactive headless troubleshooter for a more detailed path. If you used Wi-Fi, repeat the first-boot test over Ethernet before changing several settings at once.
Verify the first login¶
After SSH works, check the board, OS, connection, and power history:
Update the OS through APT, then reconnect after reboot:
If a new Trixie installation requests your account password for sudo, use the password you created in Imager. SSH-key login and administrator authentication are separate. For Wi-Fi profiles and static addresses after first boot, follow the NetworkManager guide.
FAQ¶
Can I use Raspberry Pi OS Lite and connect with SSH?¶
Yes. Lite is appropriate when you only need a terminal. VNC requires a graphical desktop; add one deliberately if you need screen sharing.
Does the Pi 5 need 5 V at 5 A just to boot?¶
The Raspberry Pi hardware documentation says a good 5 V at 3 A supply can boot the Pi 5, but the available USB peripheral current is limited. The official 27 W supply is the recommended baseline for this checklist.
Should I put ssh or wpa_supplicant.conf on the boot partition?¶
For a new current Raspberry Pi OS image, use Imager customisation for the account, SSH, and network. It keeps the steps together and avoids mixing old boot-file recipes with the current OS.