Are docker layer caching volumes encrypted?

I would like to know if the docker layer caching volumes (which are EBS volumes, right?) are encrypted at rest.

For example, if a base docker image intentionally contains credentials in order to store the configuration with the application, then when using docker layer caching, are the cached layers encrypted?

My response is not entirely an answer to your question, but it is relevant: in general Docker images should not contain credentials. They are better injected into the app as environment variables. That has the additional benefit that you can change the credentials without having to rebuild or redeploy.