I find it hard enough to get vanilla qubes working and stay working without involving libre boot.
But, unless libreboot has some unique approach, the /boot partition cannot be encrypted. To luks unlock you need cryptsetup command or similar. And that is in the kernel. And so that needs to be available unencrypted. Chicken or egg situation.
One approach is heads which informs if your /boot partition has been modified.
Another is to have the /boot on a USB drive (guide below)