That was my first recollection -- after CoreOS' Flannel, I think the next two (or at least two of the earliest) overlay networks available for Kubernetes were Weave Net and Calico (whose core maintainers started Tigera). Flannel is still around and under active development despite CoreOS being long gone; hopefully the tools Weave employees maintained can keep healthy communities going around them.
I think people got turned off from them when it came to light they had invented their own cryptography without doing any vetting that it was actually secure. At least, that’s why we moved away from it as quickly as possible with our reasoning being: “if someone is foolish enough to roll their own crypto, what else are they doing foolishly?”
Despite having been the main maintainer of Weave Net for ~4 years, I have no idea what you are talking about. Weave Net used Google's NaCL library from day 1; later adding optional AES using the in-kernel implementation.
The key exchange was/is totally custom without using anything standard, though it uses standard concepts (DH, though it does some non-standard things with it), which *might* be secure, but as far as I know, never actually put to the test.
We were using the weave CNI on our kubernetes cluster. It started failing, so we called weaveworks to try to buy support. They said no, recommending a different CNI which would necessitate a disruptive cluster replacement. Once that was a necessity, all the other CNIs were on the table and we went with cilium, which has been ok with k8s 1.22 on CentOS 7, but which is now having undiagnosed trouble with k8s 1.24 on Red Hat 8. The messy process of figuring that out is underway.