Error on sudo certbot renew --dry-run

This is fine. You only need one of the two.

Nowhere.

That config is just telling nginx to take files from /usr/local/etc/nginx/letsencrypt when someone asks for example.com/.well-known/acme-challenge/

I am not sure it is needed, I think it isn't.