Problem with `ujust setup-luks-tpm-unlock`

Hey, I just installed AuroraOS from Universal Bleu and it works great! I just have the encryptions in the wrong layout and the ujust setup-luks-tpm-unlock command gives me this error that I don’t really understand. since TPM is enabled in the BIOS.

What is the output of rpm-ostree kargs and what’s in /proc/cmdline

I’ve been curious, what is the use case of a TPM-unlocking disk? Doesn’t that enable anyone with physical possession can unlock without a pw? If so, what use is the encryption at rest?