# Caddy TLS termination for the radio stream. # Caddy auto-issues/renews Let's Encrypt certs. Replace radio.example.com. # # NOTE (learned the hard way on wiki-jokes): the app/origin must not fight # Caddy over headers. Caddy adds security headers; icecast's own are fine. radio.example.com { # Stream + static files: proxy everything to icecast (serves webroot too). reverse_proxy icecast:8000 # Stream-friendly: no buffering weirdness for long-lived connections. header X-Robots-Tag "noindex" }