My own machine if possible, ask for ThinkPad or Dell XPS Dev. Ed. if client insists on their machine. Worst case, for short periods: anything with a decent keyboard.
Arch Linux on my machine. Kubuntu latest (LTS is acceptable, if not preferred) on client's. Worst case, for short periods: anything close to Linux with an up-to-date stack (say, homebrew on macOS).
ed25519 SSH keys, preferably my own. ssh-agent (GnuPG, when on Linux) with compulsory confirmation on every sign. SSH certificates a must for host authentication, preferred for client authentication.
ZeroTier or Wireguard strongly preferred for VPN access to client networks. OpenVPN et al. begrudgingly accepted, but only for short durations. TeamViewer et al. strict no on own machine.
LXD and/or systemd-nspawn for containerisation. Docker strict no on my machine.
Terminal Emulator: Konsole or Konsole-based if possible. Worst case: anything with decent colours and keybinding support.
Font: Whichever suits the display, resolution etc. the best among: Iosevka (family), Hermit, and Fantasque Sans Mono.
Editor/IDE: At minimum — Vim or Neovim; Preferred — Emacs 26 with own spacemacs-based config.
Version control: Minimum — git; maximum — magit.
Plugins: On vim/neovim — few, if any, in-editor plugins; on Emacs — custom config tuned for specific stacks; Out-of-editor — stack-specific CLI tooling.
Almost every stack I use I try to stick as close to latest vanilla as I can (e.g., C/C++ is just ordinary text editing with compilers in -Wall -Werror etc. modes). Some stacks that are somewhat non-vanilla:
Python: 3.7 strongly preferred; 3.6 begrudgingly accepted; 3.5, 3.4, and 2.7 only for legacy maintenance. flake8, pylint, et. al. with possible Emacs integration. Sphinx (with a tuned config) for documentation, autodoc favoured.
SQL & DB: Emacs's org-mode+org-babel for playing; Sqitch and pg_tap for committing.
Racket: Emacs with Geiser. Org-mode (and thus org-babel) for small scripts/projects.
Common Lisp: SLIME (with small extensions in elisp, primarily for remote editing), sbcl (always built from source and installed with sources), quicklisp (augmented with small, private dist), erudite (+ private extensions) for literate programming (rendered, via Sphinx, to PDF).