A Pi in a shed or on a pole that hangs (kernel lock-up, runaway memory, a wedged driver) stays hung until someone power-cycles it. The SoC has a hardware watchdog: if nobody "pets" it within the timeout, it resets the board. systemd can do the petting, and no extra watchdog daemon is needed.
Procedure
-
Check the watchdog device exists (if it doesn't, add
dtparam=watchdog=ontoconfig.txtand reboot):ls -l /dev/watchdog* sudo wdctl # shows the device, current and maximum timeout -
Edit
/etc/systemd/system.conf:[Manager] RuntimeWatchdogSec=14 RebootWatchdogSec=2minRuntimeWatchdogSec: reboot if systemd stops pinging within this time. systemd pings at least every half interval.RebootWatchdogSec: separate timeout while the system is rebooting, in case shutdown hangs.
-
Apply and reboot:
sudo systemctl daemon-reexec sudo reboot
Keep the timeout at or below 15 seconds
The Raspberry Pi watchdog driver (bcm2835_wdt) supports a maximum of 15 seconds. Community answers report reboot loops when larger values were configured on some kernels. Check the maximum with wdctl on your board and stay at or below it.
Limits
- The watchdog catches a frozen system, not a hung application. For your own service, use systemd's per-service
WatchdogSec=withsd_notifypings, plusRestart=on-failure(see the systemd service item). - It reboots; it doesn't fix the cause. Log
journalctl -b -1after an unexpected reboot, and check power (vcgencmd get_throttled) first: undervoltage is a common cause of hangs. - Test it once:
echo c | sudo tee /proc/sysrq-triggercrashes the kernel on purpose. The Pi should come back within the timeout.
Sources: Stack Exchange (CC BY-SA 4.0) — see links.