@ajmartinez What combination of options finally got you what you wanted? In the past I found I had to go into full manual partitioning in the Qubes installer to be able to have unencrypted /boot with encrypted root, but I haven't tried the most recent versions.
@kyle actually default is now unencrypted boot with encrypted root on an lvm thin provisioned volume. That was the only option that worked. Going manual to do away with the unwanted swap broke it every single time, and I don’t care to waste any more of my vacation messing with it. When I get back to NL with a gigabit pipe I may try again, since restoring from backups is super fast now.