The TPM combined with secure boot will only unlock the disk if nothings been tampered with, meaning your OS security is intact. If you switch off secure boot or mess with the kernel or boot loader it’ll just refuse to unlock.
I would guess extracting the keys from the tpm in other ways is not impossible, but probably sufficiently hard to be not worth it in most situations.