>> 3. Is it ok to have swap and /boot on an encrypted LVM?

Swap is okay.  Boot depends on your boot loader.  I don't know if grub2 can 
handle this or not.

>Never run encryption on swap.  Doing so merely burdens performance.  I doubt
>even NSA, CIA, MI6 encrypt swap partitions on workstations.

BS.  Encrypting swap is *critical*.  If you do not, an attacker can use 
differential cryptanalysis between what is swapped out and the cyphertext on 

Before even generating the encryption keys for other devices, you should 
change the mount options of your swap partition so that it is encrypted using 
a random key and then remount it.
