Think I may have figured it out, but would appreciate a confirmation if my understanding is correct just as a sanity check for myself.
Under "Manage Authentication", I was previously changing just the "Local primary key" to "mail" as I thought this was the key to match to the Gluu record, and then the "Primary key" (which was left as "uid") would be used from the Gluu record to authenticate against the directory via LDAP. This wasn't working however.
Changing both of these (as opposed to just one of them) to "mail" seems to have got me what I needed and I can now log in with email, change the emails in my directory and not affect the Inum so it stays consistent.
Under the "Manage authentication" area, is the "Primary key" and "Local primary key" effectively a source attribute to destination attribute mapping (like on the cache refresh page)?
Thanks