Thank you for the nice guide! Perhaps it should be moved to Community Guides from General Discussion. (I’ve just moved.)
Qubes can be used with TPM, Heads and a hardware key for verified boot and with /boot and /root verification. Works for me. Restricted boot is possible too. All is FLOSS.