server {
    server_name webradio.TLD;

    add_header Strict-Transport-Security "max-age=7200";

    location / {
        proxy_pass http://icecast;
        include    proxy_params;
        add_header 'Access-Control-Allow-Origin' '*' always;
        proxy_ignore_client_abort on;
    }
    include /etc/nginx/snippets/letsencrypt-acme-challenge.conf;

    listen 80; # managed by Certbot
}

upstream icecast {
   server 10.0.3.IP:8080;
}

server {
    listen 8080;

    location / {
        proxy_pass http://icecast;
        include    proxy_params;
        add_header 'Access-Control-Allow-Origin' '*' always;
        proxy_ignore_client_abort on;
    }
}