# Raspberry Pi from scratch

From a Pi still in its box to an SSH session from anywhere, in about fifteen
minutes. No monitor, no keyboard — you will never plug the Pi into a screen.

## What you need

Any Raspberry Pi with Wi-Fi or Ethernet — a Pi Zero 2 W, a Pi 4, a Pi 5,
or anything in between. A microSD card of 8 GB or more, a power
supply, and a computer to flash the card from. And
[a RelaySSH account](https://relayssh.com/auth/signup/), which is free
during the beta.

## Flash Raspberry Pi OS

Install [Raspberry Pi
Imager](https://www.raspberrypi.com/software/) and run it. Choose your Pi model, pick **Raspberry Pi OS
Lite (64-bit)** — there is no desktop to see — and select your
microSD card.

Before writing, open the settings screen. This is the step that saves you
a monitor, so fill it in completely:

- **Hostname** — the name you will SSH to, for example `pi-desk`.
- **Username and password** — the account you will log in as.
- **Wi-Fi SSID, password, and country** — the Pi joins your network on first boot.
- **Enable SSH** — use password authentication, or paste a public key if you have one.

Write the card, then eject it.

> **Note:** Skip the settings screen and the Pi boots with no network and no SSH — the only fix is a monitor and keyboard. Fill it in now.

## First boot and a local SSH session

Put the card in the Pi and power it on. First boot takes a minute or two
while it resizes the filesystem and joins Wi-Fi. Then, from a computer on
the same network:

```sh
ssh pi-desk@pi-desk.local
```

Substitute your username and the hostname you set. Accept the host key
fingerprint when asked, and enter your password. You now have a shell on
the Pi.

> **Tip:** If .local does not resolve, your network has no mDNS. Find the Pi's address in your router's client list and ssh to that IP instead.

## Install RelaySSH

Still in that SSH session, copy your install command from the dashboard
(**Add device**) and run it on the Pi. It installs the agent,
registers the Pi to your account, and starts the connection.

```sh
curl -fsSL https://relayssh.com/install/YOUR-INSTALL-KEY/ | sudo sh
```

The Pi appears in your dashboard within a few seconds. On its detail page,
add a tunnel to port 22. The relay assigns that tunnel its own public port.
[Getting started](https://relayssh.com/docs/getting-started/)
covers what the agent is doing in more detail.

> **Warning:** Change the password you set in Imager if you reused one, and prefer key authentication. The Pi is about to be reachable from any network.

## Connect from anywhere

Leave your home network — a phone hotspot is enough to prove it — and SSH
to the port the dashboard assigned:

```sh
ssh -p 20001 pi-desk@relayssh.com
```

Same shell, from any network, with no public IP and no port forwarding.
Authentication still happens on the Pi against the account you created in
Imager; the relay only moves bytes.

## Where to next

If you are weighing RelaySSH against other Raspberry Pi remote-access tools,
[RelaySSH compared with
PiTunnel](https://relayssh.com/docs/relayssh-vs-pitunnel/) lays out the differences.
