Most (but not all) overlay networks are implemented in kernel. If you compromise one node in a cluster, you can fairly trivially snoop traffic, bias other nodes to send traffic through you, or listen via various mechanisms such that you can intercept traffic flowing between workloads not actually located on the compromised node.
So always encrypt everything unless you’re in a very rare environment with central network control that cannot be compromised or intercepted from a given machine.