How good/bad of an idea is a kernel-level VPN?
In terms of whether that's good or bad, it depends on your requirements and what's optimal to you. If you think about the problems in OpenSSL, which backs OpenVPN, then that's been a fairly large attack surface vector. Compare that to ipsec/ike2 kernel related vectors and weigh up the setup/learning/deployment costs of both.
Putting control planes in the kernel is the worrying part IMHO.
Performance wise? If you want it to be usable it's pretty necessary.