A Pi in a cabinet, on a wall or in a vehicle will lose power unexpectedly. Any write in progress at that moment can corrupt the filesystem, and flash cards also wear out from constant writes. Layer the mitigations:
1. Power first
Undervoltage alone can corrupt storage. Use the correct supply for the model and check vcgencmd get_throttled (see the power and throttling items).
2. Write less
- Log to RAM or to a remote system instead of the card; keep verbose debug logging off in production.
- Don't write sensor samples to local files every second; batch them, or send them over MQTT to a server.
- Databases (e.g. Home Assistant's recorder) are the biggest writers. Reduce what they record, or move them to an SSD.
3. Read-only root with overlayfs
Raspberry Pi OS has a raspi-config option to enable an overlay filesystem: the ext4 root becomes the read-only lower layer, and all writes go to a RAM-based (tmpfs) upper layer.
- Power loss can no longer damage the root filesystem.
- Everything written is lost on reboot. Put data that must persist on a separate writable partition or send it off the device.
- To update the system, disable the overlay, update, re-enable.
Well suited for kiosks, data collectors and gateways whose configuration rarely changes.
4. Better storage
- SSD or NVMe instead of SD. Raspberry Pi 5 can boot from an NVMe SSD on an M.2 HAT+: update, then set a boot order that includes NVMe under Advanced Options > Boot Order in
raspi-config. Check the drive first withls -l /dev/nvme*. - If you stay on SD: use quality cards. Home Assistant, for example, asks for ≥ 32 GB, A2 cards for Home Assistant OS, because A2 cards handle small random writes better.
5. Keep power up long enough to shut down
A UPS or UPS HAT that signals imminent power loss lets the system shut down cleanly. The Raspberry Pi white paper lists this as a well-understood mitigation.
6. Recover quickly
Keep a tested image (or automated provisioning) so a failed card can be replaced in minutes, and keep configuration in version control or on a server rather than only on the device.