What was the problem exactly? I have been using a yubikey for years for this exact purpose without too much hassle. That being said I do use it through GPG agent. I'm not really sure why TFA dislikes this method, I didn't encounter any significant issues setting it up and it means I can use my yubikey for everything that can use GnuPG (signing git commits, encrypting emails, pass...).
Actually there is one pain point: every time I install a new system I have to remember to install the right packages and udev rules to be able to communicate with my yubikey from gnupg as a non-priviledged user.
But once it works it just works and it's a significant quality of life and security improvement.